################################################################ # abuse.ch URLhaus IDS ruleset (Suricata only) # # Last updated: 2026-08-26 18:17:07 (UTC) # # # # Terms Of Use: https://urlhaus.abuse.ch/api/ # # For questions please contact urlhaus [at] abuse.ch # ################################################################ # # url alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"171.233.36.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908559/; classtype:trojan-activity;sid:84771659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.243.213.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908558/; classtype:trojan-activity;sid:84771658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"171.233.36.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908557/; classtype:trojan-activity;sid:84771657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.145.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908556/; classtype:trojan-activity;sid:84771656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.80.179"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908555/; classtype:trojan-activity;sid:84771655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.45.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908554/; classtype:trojan-activity;sid:84771654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.145.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908553/; classtype:trojan-activity;sid:84771653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.31.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908552/; classtype:trojan-activity;sid:84771652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.121.1"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908551/; classtype:trojan-activity;sid:84771651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.79.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908550/; classtype:trojan-activity;sid:84771650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.58.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908548/; classtype:trojan-activity;sid:84771648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.79.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908547/; classtype:trojan-activity;sid:84771647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.58.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908546/; classtype:trojan-activity;sid:84771646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_arc"; depth:11; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908545/; classtype:trojan-activity;sid:84771645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_arm4"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908530/; classtype:trojan-activity;sid:84771630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_i686"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908531/; classtype:trojan-activity;sid:84771631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908532/; classtype:trojan-activity;sid:84771632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_x86_64"; depth:14; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908533/; classtype:trojan-activity;sid:84771633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_x86"; depth:11; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908534/; classtype:trojan-activity;sid:84771634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_i486"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908535/; classtype:trojan-activity;sid:84771635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_mpsl"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908536/; classtype:trojan-activity;sid:84771636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_ppc"; depth:11; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908537/; classtype:trojan-activity;sid:84771637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_arm6"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908538/; classtype:trojan-activity;sid:84771638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_arm5"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908539/; classtype:trojan-activity;sid:84771639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_sh4"; depth:11; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908540/; classtype:trojan-activity;sid:84771640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_mips"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908541/; classtype:trojan-activity;sid:84771641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/system_arm7"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908542/; classtype:trojan-activity;sid:84771642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg.sh"; depth:6; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908543/; classtype:trojan-activity;sid:84771643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/running.sh"; depth:11; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908544/; classtype:trojan-activity;sid:84771644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.94.34"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908529/; classtype:trojan-activity;sid:84771629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.44.145.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908528/; classtype:trojan-activity;sid:84771628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.185.199.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908527/; classtype:trojan-activity;sid:84771627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.30.115.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908526/; classtype:trojan-activity;sid:84771626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/agent.exe"; depth:22; endswith; nocase; http.host; content:"medicosantiagomarrero.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908525/; classtype:trojan-activity;sid:84771625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/stego_1lwwbg2gvn.png"; depth:25; endswith; nocase; http.host; content:"vc.tnygbw.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908524/; classtype:trojan-activity;sid:84771624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ginfol/stego_canli0q0np.png"; depth:28; endswith; nocase; http.host; content:"lavos.life"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908523/; classtype:trojan-activity;sid:84771623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/40/bfjihib.txt"; depth:15; endswith; nocase; http.host; content:"216.9.224.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908522/; classtype:trojan-activity;sid:84771622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/rest-api/iwpmqoy/egilhta/qio1pek/kk3crypted.ps1"; depth:60; endswith; nocase; http.host; content:"algi-english.4lima.at"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908521/; classtype:trojan-activity;sid:84771621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/rest-api/iwpmqoy/egilhta/qio1pek/millscrypted.ps1"; depth:62; endswith; nocase; http.host; content:"algi-english.4lima.at"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908520/; classtype:trojan-activity;sid:84771620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/rest-api/iwpmqoy/egilhta/qio1pek/crypted.ps1"; depth:57; endswith; nocase; http.host; content:"algi-english.4lima.at"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908519/; classtype:trojan-activity;sid:84771619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/rest-api/iwpmqoy/egilhta/qio1pek/e3crypted.ps1"; depth:59; endswith; nocase; http.host; content:"algi-english.4lima.at"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908518/; classtype:trojan-activity;sid:84771618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gsew/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"idylliccreations.net"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908516/; classtype:trojan-activity;sid:84771616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bebe/bebeln.exe"; depth:16; endswith; nocase; http.host; content:"tmcksa.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908517/; classtype:trojan-activity;sid:84771617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v0/b/julyendingapama.firebasestorage.app/o/inve%20new.png|3f|alt=media|7c|26|7c|token=15e2a054-9211-4b2f-987c-c1225adf4faa"; depth:123; endswith; nocase; http.host; content:"firebasestorage.googleapis.com"; depth:30; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908515/; classtype:trojan-activity;sid:84771615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.30.115.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908514/; classtype:trojan-activity;sid:84771614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b41995cf38e90365.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908513/; classtype:trojan-activity;sid:84771613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"152.42.202.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908511/; classtype:trojan-activity;sid:84771611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"152.42.202.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908510/; classtype:trojan-activity;sid:84771610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"152.42.202.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908509/; classtype:trojan-activity;sid:84771609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.76.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908508/; classtype:trojan-activity;sid:84771608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.95.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908505/; classtype:trojan-activity;sid:84771605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.56.232.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908504/; classtype:trojan-activity;sid:84771604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.16.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908503/; classtype:trojan-activity;sid:84771603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.191.16.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908501/; classtype:trojan-activity;sid:84771601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.56.232.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908502/; classtype:trojan-activity;sid:84771602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.94.144.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908500/; classtype:trojan-activity;sid:84771600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.26.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908499/; classtype:trojan-activity;sid:84771599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/winword.zip"; depth:12; endswith; nocase; http.host; content:"asdsocial.pt"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908498/; classtype:trojan-activity;sid:84771598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.249.199.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908497/; classtype:trojan-activity;sid:84771597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/plugins/linux.bin"; depth:29; endswith; nocase; http.host; content:"cta.edu.pe"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908495/; classtype:trojan-activity;sid:84771595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/plugins/linux.bin"; depth:29; endswith; nocase; http.host; content:"cta.edu.pe"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908496/; classtype:trojan-activity;sid:84771596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jah.arm7"; depth:9; endswith; nocase; http.host; content:"43.228.157.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908479/; classtype:trojan-activity;sid:84771579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jah.arm4"; depth:9; endswith; nocase; http.host; content:"43.228.157.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908480/; classtype:trojan-activity;sid:84771580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jah.arm6"; depth:9; endswith; nocase; http.host; content:"43.228.157.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908481/; classtype:trojan-activity;sid:84771581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jah.arm5"; depth:9; endswith; nocase; http.host; content:"43.228.157.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908478/; classtype:trojan-activity;sid:84771578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.120.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908477/; classtype:trojan-activity;sid:84771577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.120.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908476/; classtype:trojan-activity;sid:84771576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.194.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908472/; classtype:trojan-activity;sid:84771572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.254.188.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908471/; classtype:trojan-activity;sid:84771571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.194.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908469/; classtype:trojan-activity;sid:84771569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.193.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908468/; classtype:trojan-activity;sid:84771568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.177.20.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908467/; classtype:trojan-activity;sid:84771567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.114.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908456/; classtype:trojan-activity;sid:84771556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.234.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908457/; classtype:trojan-activity;sid:84771557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.236.93.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908458/; classtype:trojan-activity;sid:84771558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.7.113.51"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908461/; classtype:trojan-activity;sid:84771561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.37.242"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908462/; classtype:trojan-activity;sid:84771562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.11.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908463/; classtype:trojan-activity;sid:84771563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.54.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908464/; classtype:trojan-activity;sid:84771564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.43.98"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908465/; classtype:trojan-activity;sid:84771565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/qw1.exe"; depth:20; endswith; nocase; http.host; content:"45.13.186.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908466/; classtype:trojan-activity;sid:84771566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.255.151.24"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908444/; classtype:trojan-activity;sid:84771544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.46.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908446/; classtype:trojan-activity;sid:84771546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.173.158.197"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908447/; classtype:trojan-activity;sid:84771547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.6.33.35"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908448/; classtype:trojan-activity;sid:84771548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.226.26.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908449/; classtype:trojan-activity;sid:84771549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.50.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908451/; classtype:trojan-activity;sid:84771551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.27.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908452/; classtype:trojan-activity;sid:84771552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.222.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908453/; classtype:trojan-activity;sid:84771553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.56.166.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908454/; classtype:trojan-activity;sid:84771554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908455/; classtype:trojan-activity;sid:84771555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.4.163.42"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908443/; classtype:trojan-activity;sid:84771543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.68.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908442/; classtype:trojan-activity;sid:84771542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.5.102"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908439/; classtype:trojan-activity;sid:84771539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.22.111.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908440/; classtype:trojan-activity;sid:84771540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"96.245.232.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908441/; classtype:trojan-activity;sid:84771541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"82.114.178.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908410/; classtype:trojan-activity;sid:84771510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.41.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908411/; classtype:trojan-activity;sid:84771511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.123.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908412/; classtype:trojan-activity;sid:84771512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.88.200.53"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908414/; classtype:trojan-activity;sid:84771514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.188.75.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908416/; classtype:trojan-activity;sid:84771516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.203.187.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908417/; classtype:trojan-activity;sid:84771517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.88.164.98"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908418/; classtype:trojan-activity;sid:84771518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.87.220.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908419/; classtype:trojan-activity;sid:84771519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.9.35.137"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908420/; classtype:trojan-activity;sid:84771520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"177.39.122.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908422/; classtype:trojan-activity;sid:84771522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.199.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908423/; classtype:trojan-activity;sid:84771523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.192.191.125"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908424/; classtype:trojan-activity;sid:84771524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.74.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908425/; classtype:trojan-activity;sid:84771525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.188.79.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908426/; classtype:trojan-activity;sid:84771526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908427/; classtype:trojan-activity;sid:84771527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.175.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908428/; classtype:trojan-activity;sid:84771528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.168.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908429/; classtype:trojan-activity;sid:84771529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.64.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908430/; classtype:trojan-activity;sid:84771530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.1.227.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908431/; classtype:trojan-activity;sid:84771531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.173.76.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908432/; classtype:trojan-activity;sid:84771532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.130.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908433/; classtype:trojan-activity;sid:84771533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.59.236.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908434/; classtype:trojan-activity;sid:84771534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.116.161.23"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908435/; classtype:trojan-activity;sid:84771535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.229.168.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908436/; classtype:trojan-activity;sid:84771536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.173.158.197"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908437/; classtype:trojan-activity;sid:84771537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.185.177.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908407/; classtype:trojan-activity;sid:84771507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.50.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908408/; classtype:trojan-activity;sid:84771508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.222.89.207"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908404/; classtype:trojan-activity;sid:84771504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.152.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908405/; classtype:trojan-activity;sid:84771505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.6.33.35"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908402/; classtype:trojan-activity;sid:84771502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.226.26.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908403/; classtype:trojan-activity;sid:84771503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908398/; classtype:trojan-activity;sid:84771498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.78.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908399/; classtype:trojan-activity;sid:84771499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.236.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908400/; classtype:trojan-activity;sid:84771500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.51"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908401/; classtype:trojan-activity;sid:84771501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.54.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908383/; classtype:trojan-activity;sid:84771483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.151.133.53"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908384/; classtype:trojan-activity;sid:84771484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.87.220.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908385/; classtype:trojan-activity;sid:84771485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv6l"; depth:7; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908386/; classtype:trojan-activity;sid:84771486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.48.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908387/; classtype:trojan-activity;sid:84771487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.114.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908389/; classtype:trojan-activity;sid:84771489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.60.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908390/; classtype:trojan-activity;sid:84771490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.185.177.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908391/; classtype:trojan-activity;sid:84771491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.140.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908392/; classtype:trojan-activity;sid:84771492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.30.220"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908393/; classtype:trojan-activity;sid:84771493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.240.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908394/; classtype:trojan-activity;sid:84771494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"211.75.38.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908395/; classtype:trojan-activity;sid:84771495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.56.166.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908396/; classtype:trojan-activity;sid:84771496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.145.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908397/; classtype:trojan-activity;sid:84771497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908372/; classtype:trojan-activity;sid:84771472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.60.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908374/; classtype:trojan-activity;sid:84771474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.250.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908375/; classtype:trojan-activity;sid:84771475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.182.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908376/; classtype:trojan-activity;sid:84771476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.236.91.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908377/; classtype:trojan-activity;sid:84771477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.112.52"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908378/; classtype:trojan-activity;sid:84771478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.37.212.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908379/; classtype:trojan-activity;sid:84771479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.222.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908380/; classtype:trojan-activity;sid:84771480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.85.15.247"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908381/; classtype:trojan-activity;sid:84771481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.42.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908370/; classtype:trojan-activity;sid:84771470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.209.50"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908371/; classtype:trojan-activity;sid:84771471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.152.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908367/; classtype:trojan-activity;sid:84771467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.27.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908368/; classtype:trojan-activity;sid:84771468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.188.75.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908369/; classtype:trojan-activity;sid:84771469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.88.164.98"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908366/; classtype:trojan-activity;sid:84771466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.133.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908363/; classtype:trojan-activity;sid:84771463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.68.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908365/; classtype:trojan-activity;sid:84771465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.34.109.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908350/; classtype:trojan-activity;sid:84771450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.189.142.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908351/; classtype:trojan-activity;sid:84771451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.140.133.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908352/; classtype:trojan-activity;sid:84771452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.25.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908353/; classtype:trojan-activity;sid:84771453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908354/; classtype:trojan-activity;sid:84771454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908355/; classtype:trojan-activity;sid:84771455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.89.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908356/; classtype:trojan-activity;sid:84771456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.114.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908357/; classtype:trojan-activity;sid:84771457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.193.141"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908359/; classtype:trojan-activity;sid:84771459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.234.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908360/; classtype:trojan-activity;sid:84771460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.37.212.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908361/; classtype:trojan-activity;sid:84771461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.199.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908362/; classtype:trojan-activity;sid:84771462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.155.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908341/; classtype:trojan-activity;sid:84771441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.31.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908343/; classtype:trojan-activity;sid:84771443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.121.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908344/; classtype:trojan-activity;sid:84771444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.236.91.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908345/; classtype:trojan-activity;sid:84771445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908346/; classtype:trojan-activity;sid:84771446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.239.128.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908347/; classtype:trojan-activity;sid:84771447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.160.130.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908348/; classtype:trojan-activity;sid:84771448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.76.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908349/; classtype:trojan-activity;sid:84771449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.239.102.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908333/; classtype:trojan-activity;sid:84771433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.41.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908335/; classtype:trojan-activity;sid:84771435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.22.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908336/; classtype:trojan-activity;sid:84771436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.132.214"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908338/; classtype:trojan-activity;sid:84771438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.9.204"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908339/; classtype:trojan-activity;sid:84771439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.22.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908330/; classtype:trojan-activity;sid:84771430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.173.117.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908331/; classtype:trojan-activity;sid:84771431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"5.59.107.59"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908332/; classtype:trojan-activity;sid:84771432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.9.204"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908328/; classtype:trojan-activity;sid:84771428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.173.117.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908329/; classtype:trojan-activity;sid:84771429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.88.200.53"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908317/; classtype:trojan-activity;sid:84771417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.87.216.223"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908318/; classtype:trojan-activity;sid:84771418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.228.136.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908319/; classtype:trojan-activity;sid:84771419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.7.220.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908320/; classtype:trojan-activity;sid:84771420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.192.251"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908321/; classtype:trojan-activity;sid:84771421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.125.21.163"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908322/; classtype:trojan-activity;sid:84771422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.48.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908323/; classtype:trojan-activity;sid:84771423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.193.141"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908324/; classtype:trojan-activity;sid:84771424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.118.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908325/; classtype:trojan-activity;sid:84771425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.80.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908326/; classtype:trojan-activity;sid:84771426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.11.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908302/; classtype:trojan-activity;sid:84771402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908303/; classtype:trojan-activity;sid:84771403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908304/; classtype:trojan-activity;sid:84771404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908306/; classtype:trojan-activity;sid:84771406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.26.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908307/; classtype:trojan-activity;sid:84771407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.87.58"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908309/; classtype:trojan-activity;sid:84771409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.134.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908311/; classtype:trojan-activity;sid:84771411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.192.191.125"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908312/; classtype:trojan-activity;sid:84771412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.140.133.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908313/; classtype:trojan-activity;sid:84771413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"66.212.187.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908316/; classtype:trojan-activity;sid:84771416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"84.0.26.48"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908300/; classtype:trojan-activity;sid:84771400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.252.217.7"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908301/; classtype:trojan-activity;sid:84771401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"5.59.107.59"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908299/; classtype:trojan-activity;sid:84771399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.239.128.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908296/; classtype:trojan-activity;sid:84771396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.19.245.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908295/; classtype:trojan-activity;sid:84771395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.94.34"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908294/; classtype:trojan-activity;sid:84771394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.153.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908293/; classtype:trojan-activity;sid:84771393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.193.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908292/; classtype:trojan-activity;sid:84771392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.105.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908291/; classtype:trojan-activity;sid:84771391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.255.151.24"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908290/; classtype:trojan-activity;sid:84771390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.153.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908289/; classtype:trojan-activity;sid:84771389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.19.245.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908288/; classtype:trojan-activity;sid:84771388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.203.187.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908287/; classtype:trojan-activity;sid:84771387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.105.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908286/; classtype:trojan-activity;sid:84771386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.101.187.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908284/; classtype:trojan-activity;sid:84771384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.21.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908282/; classtype:trojan-activity;sid:84771382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908280/; classtype:trojan-activity;sid:84771380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"181.79.85.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908279/; classtype:trojan-activity;sid:84771379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.21.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908277/; classtype:trojan-activity;sid:84771377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harder/binikuku.dat"; depth:20; endswith; nocase; http.host; content:"impectorinternational.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908273/; classtype:trojan-activity;sid:84771373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlc.zip"; depth:8; endswith; nocase; http.host; content:"asdsocial.pt"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908272/; classtype:trojan-activity;sid:84771372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/binyu.exe"; depth:10; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908270/; classtype:trojan-activity;sid:84771370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dad/msi_pro.png"; depth:16; endswith; nocase; http.host; content:"ryanborn.net"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908269/; classtype:trojan-activity;sid:84771369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_6qm9r3qt6m.png"; depth:21; endswith; nocase; http.host; content:"gaiadeqi.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908268/; classtype:trojan-activity;sid:84771368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_178aezpp1v.png"; depth:21; endswith; nocase; http.host; content:"alphapicaficagency.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908267/; classtype:trojan-activity;sid:84771367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t38mt4e0/image/upload/v1787702887/img_200735.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908264/; classtype:trojan-activity;sid:84771364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_175vvr0ken.png"; depth:21; endswith; nocase; http.host; content:"gaiadeqi.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908263/; classtype:trojan-activity;sid:84771363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_qngpc3hmcp.png"; depth:21; endswith; nocase; http.host; content:"fiscalizarais.xyz"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908262/; classtype:trojan-activity;sid:84771362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ler8x39qyi3ff9hn9vgodir/true.zip"; depth:33; endswith; nocase; http.host; content:"filedn.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908261/; classtype:trojan-activity;sid:84771361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.76.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908253/; classtype:trojan-activity;sid:84771353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploader/uploader.cgi|3f|mode=downld|7c|26|7c|no=864"; depth:53; endswith; nocase; http.host; content:"www.nishiwaki.ne.jp"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908252/; classtype:trojan-activity;sid:84771352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"130.12.209.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908251/; classtype:trojan-activity;sid:84771351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rump25th.png"; depth:13; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908250/; classtype:trojan-activity;sid:84771350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.50.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908249/; classtype:trojan-activity;sid:84771349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harveyjuansara/upd2352vhjh/raw/refs/heads/main/uninstall.exe"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908248/; classtype:trojan-activity;sid:84771348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harveyjuansara/upd2352vhjh/raw/refs/heads/main/minecraftpatch.exe"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908247/; classtype:trojan-activity;sid:84771347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harveyjuansara/upd2352vhjh/raw/refs/heads/main/github.exe"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908246/; classtype:trojan-activity;sid:84771346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clpr11.exe"; depth:11; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908244/; classtype:trojan-activity;sid:84771344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asemkiic.exe"; depth:13; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908245/; classtype:trojan-activity;sid:84771345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908243/; classtype:trojan-activity;sid:84771343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.50.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908242/; classtype:trojan-activity;sid:84771342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908241/; classtype:trojan-activity;sid:84771341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notepad.exe"; depth:12; endswith; nocase; http.host; content:"85.203.4.64"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908240/; classtype:trojan-activity;sid:84771340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/almfwb.zip"; depth:11; endswith; nocase; http.host; content:"nw.almfwb.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908233/; classtype:trojan-activity;sid:84771333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.182.97.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908201/; classtype:trojan-activity;sid:84771301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.165.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908200/; classtype:trojan-activity;sid:84771300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.169.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908199/; classtype:trojan-activity;sid:84771299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.169.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908198/; classtype:trojan-activity;sid:84771298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.11.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908197/; classtype:trojan-activity;sid:84771297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.165.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908196/; classtype:trojan-activity;sid:84771296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908195/; classtype:trojan-activity;sid:84771295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv4l"; depth:7; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908194/; classtype:trojan-activity;sid:84771294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/handshakebins.sh"; depth:17; endswith; nocase; http.host; content:"213.232.114.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908193/; classtype:trojan-activity;sid:84771293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"43.228.157.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908190/; classtype:trojan-activity;sid:84771290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"43.228.157.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908191/; classtype:trojan-activity;sid:84771291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"43.228.157.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908192/; classtype:trojan-activity;sid:84771292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"146.158.4.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908189/; classtype:trojan-activity;sid:84771289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"27.44.145.195"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908178/; classtype:trojan-activity;sid:84771278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a3f8d2/kaizen.mips"; depth:19; endswith; nocase; http.host; content:"196.251.121.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908176/; classtype:trojan-activity;sid:84771276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a3f8d2/kaizen.mpsl"; depth:19; endswith; nocase; http.host; content:"196.251.121.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908175/; classtype:trojan-activity;sid:84771275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/min.t.1787698800.js"; depth:20; endswith; nocase; http.host; content:"crazy2cdn.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908174/; classtype:trojan-activity;sid:84771274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ses.bin"; depth:8; endswith; nocase; http.host; content:"193.221.200.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908167/; classtype:trojan-activity;sid:84771267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.115.102.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908161/; classtype:trojan-activity;sid:84771261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.20.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908159/; classtype:trojan-activity;sid:84771259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.202.161.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908158/; classtype:trojan-activity;sid:84771258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"220.158.234.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908154/; classtype:trojan-activity;sid:84771254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"220.158.234.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908155/; classtype:trojan-activity;sid:84771255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"220.158.234.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908156/; classtype:trojan-activity;sid:84771256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"220.158.234.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908150/; classtype:trojan-activity;sid:84771250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"220.158.234.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908151/; classtype:trojan-activity;sid:84771251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"220.158.234.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908152/; classtype:trojan-activity;sid:84771252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"220.158.234.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908153/; classtype:trojan-activity;sid:84771253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.244.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908147/; classtype:trojan-activity;sid:84771247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.244.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908146/; classtype:trojan-activity;sid:84771246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.76.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908144/; classtype:trojan-activity;sid:84771244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.100.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908143/; classtype:trojan-activity;sid:84771243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.100.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908142/; classtype:trojan-activity;sid:84771242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.224.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908141/; classtype:trojan-activity;sid:84771241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.70.54"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908140/; classtype:trojan-activity;sid:84771240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.231.76"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908139/; classtype:trojan-activity;sid:84771239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.236.207"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908138/; classtype:trojan-activity;sid:84771238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_124c8c2143039ea5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908137/; classtype:trojan-activity;sid:84771237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.238.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908136/; classtype:trojan-activity;sid:84771236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.236.207"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908135/; classtype:trojan-activity;sid:84771235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.70.54"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908134/; classtype:trojan-activity;sid:84771234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.214.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908133/; classtype:trojan-activity;sid:84771233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.238.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908132/; classtype:trojan-activity;sid:84771232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venv/lib/python3.12/site-packages/bcrypt/_bcrypt.abi3.so"; depth:57; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908131/; classtype:trojan-activity;sid:84771231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"200.115.102.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908130/; classtype:trojan-activity;sid:84771230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.5.177"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908129/; classtype:trojan-activity;sid:84771229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.219.44.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908128/; classtype:trojan-activity;sid:84771228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.60.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908126/; classtype:trojan-activity;sid:84771226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.39.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908127/; classtype:trojan-activity;sid:84771227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.249.199.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908125/; classtype:trojan-activity;sid:84771225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venv/lib/python3.12/site-packages/_cffi_backend.cpython-312-x86_64-linux-gnu.so"; depth:80; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908124/; classtype:trojan-activity;sid:84771224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venv/bin/python3"; depth:17; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908123/; classtype:trojan-activity;sid:84771223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.72.222"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908122/; classtype:trojan-activity;sid:84771222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.186.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908121/; classtype:trojan-activity;sid:84771221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.23.135.203"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908120/; classtype:trojan-activity;sid:84771220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.186.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908119/; classtype:trojan-activity;sid:84771219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.115.74.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908118/; classtype:trojan-activity;sid:84771218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.219.44.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908117/; classtype:trojan-activity;sid:84771217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.135.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908116/; classtype:trojan-activity;sid:84771216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.67.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908115/; classtype:trojan-activity;sid:84771215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.84.112.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908114/; classtype:trojan-activity;sid:84771214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.223.141.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908113/; classtype:trojan-activity;sid:84771213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.18.207"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908112/; classtype:trojan-activity;sid:84771212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.23.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908111/; classtype:trojan-activity;sid:84771211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.67.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908110/; classtype:trojan-activity;sid:84771210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.223.141.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908109/; classtype:trojan-activity;sid:84771209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.18.207"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908108/; classtype:trojan-activity;sid:84771208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.188.197"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908107/; classtype:trojan-activity;sid:84771207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.138.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908106/; classtype:trojan-activity;sid:84771206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.35.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908105/; classtype:trojan-activity;sid:84771205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_2dedd67a4922be21.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908104/; classtype:trojan-activity;sid:84771204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908103/; classtype:trojan-activity;sid:84771203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.250.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908102/; classtype:trojan-activity;sid:84771202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest|7c|26|7c|c=eye%20clinic|7c|26|7c|c=|7c|26|7c|c=surgery|7c|26|7c|c=personal|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c="; depth:186; endswith; nocase; http.host; content:"paretandassociates.screenconnect.com"; depth:36; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908101/; classtype:trojan-activity;sid:84771201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.109.205.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908100/; classtype:trojan-activity;sid:84771200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venv/lib64/python3.12/site-packages/cryptography/hazmat/bindings/_rust.abi3.so"; depth:79; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908099/; classtype:trojan-activity;sid:84771199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_6d132da8983cd728.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908098/; classtype:trojan-activity;sid:84771198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.109.205.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908097/; classtype:trojan-activity;sid:84771197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.241.8.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908096/; classtype:trojan-activity;sid:84771196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.107.198"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908095/; classtype:trojan-activity;sid:84771195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.138.107.198"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908094/; classtype:trojan-activity;sid:84771194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.138.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908093/; classtype:trojan-activity;sid:84771193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.8.60"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908092/; classtype:trojan-activity;sid:84771192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.64.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908091/; classtype:trojan-activity;sid:84771191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.60.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908090/; classtype:trojan-activity;sid:84771190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.54.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908089/; classtype:trojan-activity;sid:84771189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.64.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908088/; classtype:trojan-activity;sid:84771188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.141.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908087/; classtype:trojan-activity;sid:84771187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.76.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908086/; classtype:trojan-activity;sid:84771186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/fb2232aa883b4a33ac3877a402c0126c"; depth:35; endswith; nocase; http.host; content:"kolpa.lol"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908085/; classtype:trojan-activity;sid:84771185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/odens.exe"; depth:10; endswith; nocase; http.host; content:"193.221.200.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908084/; classtype:trojan-activity;sid:84771184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venv/lib64/python3.12/site-packages/pip/_vendor/urllib3/__pycache__/fields.cpython-312.pyc"; depth:91; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908083/; classtype:trojan-activity;sid:84771183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/3c547dbeb28c4b8d937a771d0debff39"; depth:35; endswith; nocase; http.host; content:"kolpa.lol"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908082/; classtype:trojan-activity;sid:84771182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/9077ca9a63a44186add67faed923847e"; depth:35; endswith; nocase; http.host; content:"kolpa.lol"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908081/; classtype:trojan-activity;sid:84771181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/049e625ea690455ba545c97cf546fd8d"; depth:35; endswith; nocase; http.host; content:"kolpa.lol"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908080/; classtype:trojan-activity;sid:84771180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exe/backup_svc-release.exe"; depth:27; endswith; nocase; http.host; content:"plutotvshow.biz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908079/; classtype:trojan-activity;sid:84771179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wepu/cryptedd.ps1"; depth:18; endswith; nocase; http.host; content:"172.86.114.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908078/; classtype:trojan-activity;sid:84771178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wepu/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"172.86.114.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908077/; classtype:trojan-activity;sid:84771177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.209.50"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908076/; classtype:trojan-activity;sid:84771176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modules/mod_login/tocvpyg/aijontc/osefrak/ojcrypted.ps1"; depth:56; endswith; nocase; http.host; content:"architekten-schreiner.de"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908075/; classtype:trojan-activity;sid:84771175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.151.72.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908074/; classtype:trojan-activity;sid:84771174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.164.115.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908073/; classtype:trojan-activity;sid:84771173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"212.164.115.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908072/; classtype:trojan-activity;sid:84771172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908071/; classtype:trojan-activity;sid:84771171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.13.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908070/; classtype:trojan-activity;sid:84771170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/setup.aac"; depth:15; endswith; nocase; http.host; content:"wordtax.ink"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908069/; classtype:trojan-activity;sid:84771169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.13.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908068/; classtype:trojan-activity;sid:84771168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f1"; depth:3; endswith; nocase; http.host; content:"final-aura.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908067/; classtype:trojan-activity;sid:84771167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.151.72.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908066/; classtype:trojan-activity;sid:84771166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908065/; classtype:trojan-activity;sid:84771165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"authowareinc1.screenconnect.com"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908064/; classtype:trojan-activity;sid:84771164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/en/screenconnect.clientsetup.msi"; depth:33; endswith; nocase; http.host; content:"540239621396215402.raymelo.vu"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908063/; classtype:trojan-activity;sid:84771163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908062/; classtype:trojan-activity;sid:84771162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.225.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908061/; classtype:trojan-activity;sid:84771161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_31233e915ca34d9f.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908060/; classtype:trojan-activity;sid:84771160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/screenconnect.clientsetup"; depth:26; endswith; nocase; http.host; content:"pub-5188043a98ed4134bdbf1227691455ca.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908059/; classtype:trojan-activity;sid:84771159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"106.58.114.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908058/; classtype:trojan-activity;sid:84771158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.225.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908057/; classtype:trojan-activity;sid:84771157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_c28beab8f1eb5a16.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908056/; classtype:trojan-activity;sid:84771156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.232.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908055/; classtype:trojan-activity;sid:84771155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venv/bin/python3.12"; depth:20; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908054/; classtype:trojan-activity;sid:84771154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.247.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908053/; classtype:trojan-activity;sid:84771153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.5.250"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908052/; classtype:trojan-activity;sid:84771152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venv/lib/python3.12/site-packages/cffi-2.1.1.dist-info/metadata"; depth:64; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908051/; classtype:trojan-activity;sid:84771151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.45.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908050/; classtype:trojan-activity;sid:84771150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.217.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908048/; classtype:trojan-activity;sid:84771148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.182.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908049/; classtype:trojan-activity;sid:84771149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.48.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908047/; classtype:trojan-activity;sid:84771147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.74.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908046/; classtype:trojan-activity;sid:84771146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.193.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908045/; classtype:trojan-activity;sid:84771145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.42.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908044/; classtype:trojan-activity;sid:84771144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908028/; classtype:trojan-activity;sid:84771128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.116.151.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908029/; classtype:trojan-activity;sid:84771129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.23.136.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908030/; classtype:trojan-activity;sid:84771130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908031/; classtype:trojan-activity;sid:84771131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.252.159.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908032/; classtype:trojan-activity;sid:84771132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.142.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908033/; classtype:trojan-activity;sid:84771133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"106.58.114.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908034/; classtype:trojan-activity;sid:84771134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.202.17.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908035/; classtype:trojan-activity;sid:84771135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.80.236"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908036/; classtype:trojan-activity;sid:84771136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.74.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908037/; classtype:trojan-activity;sid:84771137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908038/; classtype:trojan-activity;sid:84771138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.206.151.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908039/; classtype:trojan-activity;sid:84771139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.122.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908040/; classtype:trojan-activity;sid:84771140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.210.95"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908041/; classtype:trojan-activity;sid:84771141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.189.142.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908042/; classtype:trojan-activity;sid:84771142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcdn"; depth:5; endswith; nocase; http.host; content:"61.184.10.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908043/; classtype:trojan-activity;sid:84771143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"106.40.243.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908027/; classtype:trojan-activity;sid:84771127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.126.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908026/; classtype:trojan-activity;sid:84771126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.36.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908023/; classtype:trojan-activity;sid:84771123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.224.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908024/; classtype:trojan-activity;sid:84771124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.12.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908025/; classtype:trojan-activity;sid:84771125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.159.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908017/; classtype:trojan-activity;sid:84771117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.170.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908018/; classtype:trojan-activity;sid:84771118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.142.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908019/; classtype:trojan-activity;sid:84771119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.122.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908020/; classtype:trojan-activity;sid:84771120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.229.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908021/; classtype:trojan-activity;sid:84771121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.252.217.7"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908022/; classtype:trojan-activity;sid:84771122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.236.116.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907995/; classtype:trojan-activity;sid:84771095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.215.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907996/; classtype:trojan-activity;sid:84771096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.140.187.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907997/; classtype:trojan-activity;sid:84771097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.185.64.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907998/; classtype:trojan-activity;sid:84771098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.189.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907999/; classtype:trojan-activity;sid:84771099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.127.53.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908000/; classtype:trojan-activity;sid:84771100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.193.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908001/; classtype:trojan-activity;sid:84771101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.62.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908002/; classtype:trojan-activity;sid:84771102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.237.104.66"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908003/; classtype:trojan-activity;sid:84771103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.182.229"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908004/; classtype:trojan-activity;sid:84771104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.4.140.241"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908005/; classtype:trojan-activity;sid:84771105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.238.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908006/; classtype:trojan-activity;sid:84771106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.45.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908007/; classtype:trojan-activity;sid:84771107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.185.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908008/; classtype:trojan-activity;sid:84771108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.198.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908009/; classtype:trojan-activity;sid:84771109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"23.242.193.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908010/; classtype:trojan-activity;sid:84771110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.112.52"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908011/; classtype:trojan-activity;sid:84771111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.203.210.102"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908012/; classtype:trojan-activity;sid:84771112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.92.74.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908013/; classtype:trojan-activity;sid:84771113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.108.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908014/; classtype:trojan-activity;sid:84771114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.181.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908015/; classtype:trojan-activity;sid:84771115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.92.74.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908016/; classtype:trojan-activity;sid:84771116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.30.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907992/; classtype:trojan-activity;sid:84771092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.234.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907993/; classtype:trojan-activity;sid:84771093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.78.61"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907994/; classtype:trojan-activity;sid:84771094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.69.73.14"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907991/; classtype:trojan-activity;sid:84771091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.80.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907990/; classtype:trojan-activity;sid:84771090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.123.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907985/; classtype:trojan-activity;sid:84771085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.238.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907986/; classtype:trojan-activity;sid:84771086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"23.242.193.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907987/; classtype:trojan-activity;sid:84771087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.96.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907988/; classtype:trojan-activity;sid:84771088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.206.176.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907989/; classtype:trojan-activity;sid:84771089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907967/; classtype:trojan-activity;sid:84771067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.99.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907968/; classtype:trojan-activity;sid:84771068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.234.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907969/; classtype:trojan-activity;sid:84771069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.79.144.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907970/; classtype:trojan-activity;sid:84771070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.47.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907971/; classtype:trojan-activity;sid:84771071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907972/; classtype:trojan-activity;sid:84771072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.76.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907973/; classtype:trojan-activity;sid:84771073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"87.68.238.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907974/; classtype:trojan-activity;sid:84771074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"81.227.54.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907975/; classtype:trojan-activity;sid:84771075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.226.201"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907976/; classtype:trojan-activity;sid:84771076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.54.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907977/; classtype:trojan-activity;sid:84771077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.185.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907978/; classtype:trojan-activity;sid:84771078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.69.73.14"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907979/; classtype:trojan-activity;sid:84771079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.251.0.100"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907980/; classtype:trojan-activity;sid:84771080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.163.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907981/; classtype:trojan-activity;sid:84771081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.181.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907982/; classtype:trojan-activity;sid:84771082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"24.75.165.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907983/; classtype:trojan-activity;sid:84771083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.193.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907984/; classtype:trojan-activity;sid:84771084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.194.210.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907953/; classtype:trojan-activity;sid:84771053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.88.7.48"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907954/; classtype:trojan-activity;sid:84771054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.175.56.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907955/; classtype:trojan-activity;sid:84771055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.62.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907956/; classtype:trojan-activity;sid:84771056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.90.87"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907957/; classtype:trojan-activity;sid:84771057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.179.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907958/; classtype:trojan-activity;sid:84771058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.107.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907959/; classtype:trojan-activity;sid:84771059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.53.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907960/; classtype:trojan-activity;sid:84771060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.74.116"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907961/; classtype:trojan-activity;sid:84771061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.214.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907962/; classtype:trojan-activity;sid:84771062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.59.228.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907963/; classtype:trojan-activity;sid:84771063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907964/; classtype:trojan-activity;sid:84771064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.152.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907965/; classtype:trojan-activity;sid:84771065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.190.202.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907966/; classtype:trojan-activity;sid:84771066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.188.6.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907951/; classtype:trojan-activity;sid:84771051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.233.12.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907952/; classtype:trojan-activity;sid:84771052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.45.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907950/; classtype:trojan-activity;sid:84771050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.116.151.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907949/; classtype:trojan-activity;sid:84771049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.116.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907941/; classtype:trojan-activity;sid:84771041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.140.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907942/; classtype:trojan-activity;sid:84771042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.107.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907943/; classtype:trojan-activity;sid:84771043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.226.201"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907944/; classtype:trojan-activity;sid:84771044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.23.136.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907945/; classtype:trojan-activity;sid:84771045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.30.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907946/; classtype:trojan-activity;sid:84771046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.18.214.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907947/; classtype:trojan-activity;sid:84771047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.99.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907948/; classtype:trojan-activity;sid:84771048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.97.181"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907914/; classtype:trojan-activity;sid:84771014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907915/; classtype:trojan-activity;sid:84771015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.210.95"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907916/; classtype:trojan-activity;sid:84771016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.188.197"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907917/; classtype:trojan-activity;sid:84771017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.181.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907918/; classtype:trojan-activity;sid:84771018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.228.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907919/; classtype:trojan-activity;sid:84771019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.90.87"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907920/; classtype:trojan-activity;sid:84771020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"41.201.226.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907921/; classtype:trojan-activity;sid:84771021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.25.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907922/; classtype:trojan-activity;sid:84771022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.236.222.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907923/; classtype:trojan-activity;sid:84771023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907924/; classtype:trojan-activity;sid:84771024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.237.104.66"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907925/; classtype:trojan-activity;sid:84771025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907926/; classtype:trojan-activity;sid:84771026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.31.252.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907927/; classtype:trojan-activity;sid:84771027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.236.116.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907928/; classtype:trojan-activity;sid:84771028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.104.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907929/; classtype:trojan-activity;sid:84771029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.72.222"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907930/; classtype:trojan-activity;sid:84771030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.165.89.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907931/; classtype:trojan-activity;sid:84771031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.146.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907932/; classtype:trojan-activity;sid:84771032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.202.17.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907933/; classtype:trojan-activity;sid:84771033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.31.252.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907934/; classtype:trojan-activity;sid:84771034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.233.12.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907935/; classtype:trojan-activity;sid:84771035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.152.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907936/; classtype:trojan-activity;sid:84771036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.20.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907937/; classtype:trojan-activity;sid:84771037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.48.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907938/; classtype:trojan-activity;sid:84771038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.179.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907939/; classtype:trojan-activity;sid:84771039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.214.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907940/; classtype:trojan-activity;sid:84771040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.82.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907913/; classtype:trojan-activity;sid:84771013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.45.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907912/; classtype:trojan-activity;sid:84771012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.5.250"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907911/; classtype:trojan-activity;sid:84771011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_6bbb893ae4adfb7c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907910/; classtype:trojan-activity;sid:84771010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_79fd211d67412b88.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907909/; classtype:trojan-activity;sid:84771009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ss/screenconnect.clientsetup.msi"; depth:33; endswith; nocase; http.host; content:"smileshiplogistics.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907908/; classtype:trojan-activity;sid:84771008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.223.141.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907907/; classtype:trojan-activity;sid:84771007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.223.141.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907906/; classtype:trojan-activity;sid:84771006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.79.22.252"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907905/; classtype:trojan-activity;sid:84771005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/folder/2wdv0rl5p8k6d/murdermysteryscript"; depth:41; endswith; nocase; http.host; content:"www.mediafire.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907904/; classtype:trojan-activity;sid:84771004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.79.22.252"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907903/; classtype:trojan-activity;sid:84771003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.78.61"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907902/; classtype:trojan-activity;sid:84771002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.232.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907901/; classtype:trojan-activity;sid:84771001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.106.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907900/; classtype:trojan-activity;sid:84771000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot"; depth:4; endswith; nocase; http.host; content:"146.190.156.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907899/; classtype:trojan-activity;sid:84770999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"146.190.156.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907898/; classtype:trojan-activity;sid:84770998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.191.137.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907897/; classtype:trojan-activity;sid:84770997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.2.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907896/; classtype:trojan-activity;sid:84770996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.167.76"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907895/; classtype:trojan-activity;sid:84770995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venv/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust.abi3.so"; depth:77; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907894/; classtype:trojan-activity;sid:84770994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.212.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907893/; classtype:trojan-activity;sid:84770993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"1.171.9.127"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907892/; classtype:trojan-activity;sid:84770992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"66.212.186.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907891/; classtype:trojan-activity;sid:84770991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"1.171.9.127"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907890/; classtype:trojan-activity;sid:84770990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.97.181"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907889/; classtype:trojan-activity;sid:84770989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.82.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907888/; classtype:trojan-activity;sid:84770988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adobe/rem.exe"; depth:14; endswith; nocase; http.host; content:"91.92.47.41"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907887/; classtype:trojan-activity;sid:84770987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adobe/adobe.exe"; depth:16; endswith; nocase; http.host; content:"91.92.47.41"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907886/; classtype:trojan-activity;sid:84770986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.69.95.117"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907884/; classtype:trojan-activity;sid:84770984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.212.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907885/; classtype:trojan-activity;sid:84770985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adobe/oke.vbs"; depth:14; endswith; nocase; http.host; content:"91.92.47.41"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907883/; classtype:trojan-activity;sid:84770983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adobe/svchost.exe"; depth:18; endswith; nocase; http.host; content:"91.92.47.41"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907882/; classtype:trojan-activity;sid:84770982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.73.242"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907881/; classtype:trojan-activity;sid:84770981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/depend/boost.zip"; depth:17; endswith; nocase; http.host; content:"sxetnavelelaio.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907880/; classtype:trojan-activity;sid:84770980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bk.jpg"; depth:7; endswith; nocase; http.host; content:"ccoffice.site"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907879/; classtype:trojan-activity;sid:84770979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/utodyibg.msi"; depth:13; endswith; nocase; http.host; content:"zcalton.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907878/; classtype:trojan-activity;sid:84770978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pas.jpg"; depth:8; endswith; nocase; http.host; content:"ccoffice.site"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907876/; classtype:trojan-activity;sid:84770976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/driver.jpg"; depth:11; endswith; nocase; http.host; content:"ccoffice.site"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907877/; classtype:trojan-activity;sid:84770977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_7af4a49e477043ca.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907873/; classtype:trojan-activity;sid:84770973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b2.txt"; depth:7; endswith; nocase; http.host; content:"zcalton.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907870/; classtype:trojan-activity;sid:84770970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_9b900d7726fb39b2.ps1"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907869/; classtype:trojan-activity;sid:84770969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/)"; depth:10; endswith; nocase; http.host; content:"da607p7qeops0oicos80fhfkfssk5nopg.oast.pro"; depth:42; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907861/; classtype:trojan-activity;sid:84770961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/)"; depth:10; endswith; nocase; http.host; content:"da607p7qeops0oicos80kb76oz16futjt.oast.pro"; depth:42; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907862/; classtype:trojan-activity;sid:84770962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/)"; depth:10; endswith; nocase; http.host; content:"da607p7qeops0oicos80su3hdjwqh7k7g.oast.pro"; depth:42; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907863/; classtype:trojan-activity;sid:84770963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/)"; depth:10; endswith; nocase; http.host; content:"da607p7qeops0oicos808yaut4niq8oz3.oast.pro"; depth:42; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907865/; classtype:trojan-activity;sid:84770965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/)"; depth:10; endswith; nocase; http.host; content:"da607p7qeops0oicos80bmbjdzbp1qe9s.oast.pro"; depth:42; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907867/; classtype:trojan-activity;sid:84770967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"66.212.186.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907846/; classtype:trojan-activity;sid:84770946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.206.151.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907845/; classtype:trojan-activity;sid:84770945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.73.242"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907844/; classtype:trojan-activity;sid:84770944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.239.102.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907843/; classtype:trojan-activity;sid:84770943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.194.210.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907842/; classtype:trojan-activity;sid:84770942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.5.110"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907841/; classtype:trojan-activity;sid:84770941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.10.2.194"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907840/; classtype:trojan-activity;sid:84770940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907839/; classtype:trojan-activity;sid:84770939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m-i.p-s.exodus"; depth:15; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907832/; classtype:trojan-activity;sid:84770932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p-p.c-.exodus"; depth:14; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907833/; classtype:trojan-activity;sid:84770933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-r.m-5.exodus"; depth:15; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907834/; classtype:trojan-activity;sid:84770934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x-3.2-.exodus"; depth:14; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907835/; classtype:trojan-activity;sid:84770935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x-8.6-.exodus"; depth:14; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907836/; classtype:trojan-activity;sid:84770936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m-6.8-k.exodus"; depth:15; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907837/; classtype:trojan-activity;sid:84770937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-r.m-6.exodus"; depth:15; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907838/; classtype:trojan-activity;sid:84770938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907827/; classtype:trojan-activity;sid:84770927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m-p.s-l.exodus"; depth:15; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907828/; classtype:trojan-activity;sid:84770928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-r.m-7.exodus"; depth:15; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907829/; classtype:trojan-activity;sid:84770929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s-h.4-.exodus"; depth:14; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907830/; classtype:trojan-activity;sid:84770930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-r.m-4.exodus"; depth:15; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907831/; classtype:trojan-activity;sid:84770931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-5.8-6.exodus"; depth:15; endswith; nocase; http.host; content:"94.154.43.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907826/; classtype:trojan-activity;sid:84770926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.191.137.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907825/; classtype:trojan-activity;sid:84770925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.46.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907824/; classtype:trojan-activity;sid:84770924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.246.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907823/; classtype:trojan-activity;sid:84770923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"177.125.169.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907821/; classtype:trojan-activity;sid:84770921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.27.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907819/; classtype:trojan-activity;sid:84770919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.246.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907820/; classtype:trojan-activity;sid:84770920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"177.125.169.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907818/; classtype:trojan-activity;sid:84770918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.16.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907817/; classtype:trojan-activity;sid:84770917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.16.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907816/; classtype:trojan-activity;sid:84770916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.238.158.171"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907815/; classtype:trojan-activity;sid:84770915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.27.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907814/; classtype:trojan-activity;sid:84770914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.188.81.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907813/; classtype:trojan-activity;sid:84770913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.192.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907812/; classtype:trojan-activity;sid:84770912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.19.113"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907811/; classtype:trojan-activity;sid:84770911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.55.19.113"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907810/; classtype:trojan-activity;sid:84770910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.192.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907809/; classtype:trojan-activity;sid:84770909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.27.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907808/; classtype:trojan-activity;sid:84770908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_47bd5a894059e297.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907807/; classtype:trojan-activity;sid:84770907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.27.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907806/; classtype:trojan-activity;sid:84770906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.115.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907805/; classtype:trojan-activity;sid:84770905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/js/installwizard.exe"; depth:21; endswith; nocase; http.host; content:"muaklekcoop.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907804/; classtype:trojan-activity;sid:84770904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"171.114.230.183"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907803/; classtype:trojan-activity;sid:84770903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/giggappc"; depth:9; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907801/; classtype:trojan-activity;sid:84770901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkk.arm6"; depth:9; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907802/; classtype:trojan-activity;sid:84770902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907796/; classtype:trojan-activity;sid:84770896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkk.arm7"; depth:9; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907797/; classtype:trojan-activity;sid:84770897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chrome"; depth:7; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907798/; classtype:trojan-activity;sid:84770898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkk.arm5"; depth:9; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907799/; classtype:trojan-activity;sid:84770899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dips"; depth:5; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907800/; classtype:trojan-activity;sid:84770900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkk.arm4"; depth:9; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907794/; classtype:trojan-activity;sid:84770894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dipndots"; depth:9; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907795/; classtype:trojan-activity;sid:84770895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.143.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907793/; classtype:trojan-activity;sid:84770893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.115.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907792/; classtype:trojan-activity;sid:84770892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkk.arm7k"; depth:10; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907791/; classtype:trojan-activity;sid:84770891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dipndotsk"; depth:10; endswith; nocase; http.host; content:"104.168.4.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907790/; classtype:trojan-activity;sid:84770890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.42.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907789/; classtype:trojan-activity;sid:84770889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.42.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907788/; classtype:trojan-activity;sid:84770888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.93.137.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907787/; classtype:trojan-activity;sid:84770887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.225.171"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907786/; classtype:trojan-activity;sid:84770886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.186.230.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907785/; classtype:trojan-activity;sid:84770885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.225.171"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907784/; classtype:trojan-activity;sid:84770884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.202.243.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907783/; classtype:trojan-activity;sid:84770883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.202.243.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907782/; classtype:trojan-activity;sid:84770882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.222.48.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907781/; classtype:trojan-activity;sid:84770881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.93.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907780/; classtype:trojan-activity;sid:84770880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.254.228"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907779/; classtype:trojan-activity;sid:84770879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.142.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907778/; classtype:trojan-activity;sid:84770878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.143.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907777/; classtype:trojan-activity;sid:84770877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.109.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907776/; classtype:trojan-activity;sid:84770876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.157.210.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907775/; classtype:trojan-activity;sid:84770875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.254.228"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907774/; classtype:trojan-activity;sid:84770874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.7.150.192"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907773/; classtype:trojan-activity;sid:84770873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.142.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907772/; classtype:trojan-activity;sid:84770872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.0.60.188"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907771/; classtype:trojan-activity;sid:84770871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.34.62.251"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907770/; classtype:trojan-activity;sid:84770870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.4.17.29"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907769/; classtype:trojan-activity;sid:84770869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.82.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907768/; classtype:trojan-activity;sid:84770868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"47.215.224.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907767/; classtype:trojan-activity;sid:84770867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.189.21.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907766/; classtype:trojan-activity;sid:84770866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.105.77"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907765/; classtype:trojan-activity;sid:84770865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"157.66.146.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907764/; classtype:trojan-activity;sid:84770864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.189.21.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907763/; classtype:trojan-activity;sid:84770863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.105.77"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907762/; classtype:trojan-activity;sid:84770862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"157.66.146.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907761/; classtype:trojan-activity;sid:84770861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.222.48.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907760/; classtype:trojan-activity;sid:84770860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.29.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907759/; classtype:trojan-activity;sid:84770859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.35.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907758/; classtype:trojan-activity;sid:84770858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.29.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907757/; classtype:trojan-activity;sid:84770857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payroll_statement.pdf.pdf"; depth:26; endswith; nocase; http.host; content:"84.54.33.215"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907756/; classtype:trojan-activity;sid:84770856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invoice.zip"; depth:12; endswith; nocase; http.host; content:"84.54.33.215"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907754/; classtype:trojan-activity;sid:84770854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invoice.lnk"; depth:12; endswith; nocase; http.host; content:"84.54.33.215"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907755/; classtype:trojan-activity;sid:84770855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invoice.ps1"; depth:12; endswith; nocase; http.host; content:"84.54.33.215"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907753/; classtype:trojan-activity;sid:84770853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.py"; depth:8; endswith; nocase; http.host; content:"84.54.33.215"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907752/; classtype:trojan-activity;sid:84770852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tplinkrouter.sh"; depth:16; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907751/; classtype:trojan-activity;sid:84770851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/totolink.sh"; depth:12; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907750/; classtype:trojan-activity;sid:84770850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.90.186.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907749/; classtype:trojan-activity;sid:84770849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.35.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907748/; classtype:trojan-activity;sid:84770848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.53.200.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907747/; classtype:trojan-activity;sid:84770847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.7.150.192"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907746/; classtype:trojan-activity;sid:84770846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.104.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907744/; classtype:trojan-activity;sid:84770844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.104.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907745/; classtype:trojan-activity;sid:84770845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907741/; classtype:trojan-activity;sid:84770841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907742/; classtype:trojan-activity;sid:84770842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907743/; classtype:trojan-activity;sid:84770843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t.sh"; depth:5; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907740/; classtype:trojan-activity;sid:84770840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss/boss.bat"; depth:14; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907739/; classtype:trojan-activity;sid:84770839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss/pure.dat"; depth:14; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907738/; classtype:trojan-activity;sid:84770838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f9d3a7c2/bot_arm"; depth:17; endswith; nocase; http.host; content:"94.154.43.89"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907737/; classtype:trojan-activity;sid:84770837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/setup.exe"; depth:10; endswith; nocase; http.host; content:"45.88.186.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907736/; classtype:trojan-activity;sid:84770836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.16.71"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907735/; classtype:trojan-activity;sid:84770835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kworker"; depth:8; endswith; nocase; http.host; content:"139.59.240.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907734/; classtype:trojan-activity;sid:84770834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.220.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907733/; classtype:trojan-activity;sid:84770833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.46.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907732/; classtype:trojan-activity;sid:84770832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.16.71"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907731/; classtype:trojan-activity;sid:84770831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.117.252.99"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907730/; classtype:trojan-activity;sid:84770830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.117.252.99"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907729/; classtype:trojan-activity;sid:84770829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.220.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907728/; classtype:trojan-activity;sid:84770828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.46.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907727/; classtype:trojan-activity;sid:84770827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.122.113"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907726/; classtype:trojan-activity;sid:84770826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.34.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907725/; classtype:trojan-activity;sid:84770825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.122.113"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907724/; classtype:trojan-activity;sid:84770824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.96.245"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907723/; classtype:trojan-activity;sid:84770823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.132.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907722/; classtype:trojan-activity;sid:84770822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.220.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907721/; classtype:trojan-activity;sid:84770821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"176.77.51.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907720/; classtype:trojan-activity;sid:84770820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.220.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907719/; classtype:trojan-activity;sid:84770819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.190.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907718/; classtype:trojan-activity;sid:84770818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.150.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907717/; classtype:trojan-activity;sid:84770817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.59.108.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907716/; classtype:trojan-activity;sid:84770816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.254.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907715/; classtype:trojan-activity;sid:84770815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.165.195"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907714/; classtype:trojan-activity;sid:84770814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.190.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907713/; classtype:trojan-activity;sid:84770813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/security/c8ppwoye50"; depth:20; endswith; nocase; http.host; content:"triapfog.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907712/; classtype:trojan-activity;sid:84770812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hex/traffic"; depth:12; endswith; nocase; http.host; content:"imagehopeag.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907710/; classtype:trojan-activity;sid:84770810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_7a330d043d2a8b77.ps1"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907711/; classtype:trojan-activity;sid:84770811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ba3c4b02363471d3.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907709/; classtype:trojan-activity;sid:84770809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.172.186.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907708/; classtype:trojan-activity;sid:84770808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.74.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907707/; classtype:trojan-activity;sid:84770807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.254.154.168"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907706/; classtype:trojan-activity;sid:84770806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.165.195"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907705/; classtype:trojan-activity;sid:84770805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.204.233.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907699/; classtype:trojan-activity;sid:84770799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skjsadfi123uv12/"; depth:17; endswith; nocase; http.host; content:"cloudsenterprise26.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907698/; classtype:trojan-activity;sid:84770798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_d27852ce3dbc58e5.ps1"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907692/; classtype:trojan-activity;sid:84770792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.213.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907691/; classtype:trojan-activity;sid:84770791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.204.233.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907690/; classtype:trojan-activity;sid:84770790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.57.126.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907689/; classtype:trojan-activity;sid:84770789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.11.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907688/; classtype:trojan-activity;sid:84770788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.17.194.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907687/; classtype:trojan-activity;sid:84770787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.118.34.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907686/; classtype:trojan-activity;sid:84770786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.206.185.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907685/; classtype:trojan-activity;sid:84770785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.57.126.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907684/; classtype:trojan-activity;sid:84770784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.17.194.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907683/; classtype:trojan-activity;sid:84770783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"nwlansing.screenconnect.com"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907681/; classtype:trojan-activity;sid:84770781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe|3f|e=access|7c|26|7c|y=guest|7c|26|7c|t=plgghghg"; depth:83; endswith; nocase; http.host; content:"students16.screenconnect.com"; depth:28; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907682/; classtype:trojan-activity;sid:84770782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.188.141.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907680/; classtype:trojan-activity;sid:84770780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_28ae045da50f3847.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907677/; classtype:trojan-activity;sid:84770777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_def37db2c5087baa.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907678/; classtype:trojan-activity;sid:84770778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_83a2a92978b8b2a2.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907672/; classtype:trojan-activity;sid:84770772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clpmem.exe"; depth:11; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907666/; classtype:trojan-activity;sid:84770766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.118.34.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907665/; classtype:trojan-activity;sid:84770765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.206.185.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907664/; classtype:trojan-activity;sid:84770764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907663/; classtype:trojan-activity;sid:84770763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907661/; classtype:trojan-activity;sid:84770761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907662/; classtype:trojan-activity;sid:84770762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907657/; classtype:trojan-activity;sid:84770757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i686"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907658/; classtype:trojan-activity;sid:84770758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/musl"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907659/; classtype:trojan-activity;sid:84770759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907660/; classtype:trojan-activity;sid:84770760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907650/; classtype:trojan-activity;sid:84770750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907651/; classtype:trojan-activity;sid:84770751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907652/; classtype:trojan-activity;sid:84770752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907653/; classtype:trojan-activity;sid:84770753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907654/; classtype:trojan-activity;sid:84770754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907655/; classtype:trojan-activity;sid:84770755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907656/; classtype:trojan-activity;sid:84770756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.150.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907649/; classtype:trojan-activity;sid:84770749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.150.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907648/; classtype:trojan-activity;sid:84770748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a1dd0f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907619/; classtype:trojan-activity;sid:84770719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/695814"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907620/; classtype:trojan-activity;sid:84770720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f81791"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907621/; classtype:trojan-activity;sid:84770721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e37793"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907622/; classtype:trojan-activity;sid:84770722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f95e82"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907623/; classtype:trojan-activity;sid:84770723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/93779b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907624/; classtype:trojan-activity;sid:84770724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0f798b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907625/; classtype:trojan-activity;sid:84770725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/df9369"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907626/; classtype:trojan-activity;sid:84770726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3d923d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907627/; classtype:trojan-activity;sid:84770727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/948e52"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907628/; classtype:trojan-activity;sid:84770728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7616cc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907629/; classtype:trojan-activity;sid:84770729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ece1eb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907630/; classtype:trojan-activity;sid:84770730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70d90a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907631/; classtype:trojan-activity;sid:84770731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/172acf"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907632/; classtype:trojan-activity;sid:84770732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4b4463"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907633/; classtype:trojan-activity;sid:84770733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/80de26"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907634/; classtype:trojan-activity;sid:84770734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dd765c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907635/; classtype:trojan-activity;sid:84770735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/31cc29"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907636/; classtype:trojan-activity;sid:84770736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6d91a8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907637/; classtype:trojan-activity;sid:84770737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0f8788"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907638/; classtype:trojan-activity;sid:84770738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e86d15"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907639/; classtype:trojan-activity;sid:84770739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8d848a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907640/; classtype:trojan-activity;sid:84770740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7e3c43"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907641/; classtype:trojan-activity;sid:84770741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9c9b86"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907642/; classtype:trojan-activity;sid:84770742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c1f86d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907643/; classtype:trojan-activity;sid:84770743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dcf6e6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907644/; classtype:trojan-activity;sid:84770744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0950fc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907645/; classtype:trojan-activity;sid:84770745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7bd475"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907646/; classtype:trojan-activity;sid:84770746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f18be5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907647/; classtype:trojan-activity;sid:84770747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ecdaae"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907586/; classtype:trojan-activity;sid:84770686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/87e848"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907587/; classtype:trojan-activity;sid:84770687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5ba42b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907588/; classtype:trojan-activity;sid:84770688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c17f7f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907589/; classtype:trojan-activity;sid:84770689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cf9fba"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907590/; classtype:trojan-activity;sid:84770690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/55e9c6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907591/; classtype:trojan-activity;sid:84770691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9c9c3f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907592/; classtype:trojan-activity;sid:84770692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d69836"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907593/; classtype:trojan-activity;sid:84770693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d799da"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907594/; classtype:trojan-activity;sid:84770694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01d9da"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907595/; classtype:trojan-activity;sid:84770695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8bb61f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907596/; classtype:trojan-activity;sid:84770696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cb4d97"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907597/; classtype:trojan-activity;sid:84770697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/375de5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907598/; classtype:trojan-activity;sid:84770698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9dc6cf"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907599/; classtype:trojan-activity;sid:84770699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/07c0df"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907600/; classtype:trojan-activity;sid:84770700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/77be00"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907601/; classtype:trojan-activity;sid:84770701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ea884a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907602/; classtype:trojan-activity;sid:84770702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/460081"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907603/; classtype:trojan-activity;sid:84770703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2e95b1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907604/; classtype:trojan-activity;sid:84770704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/973c93"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907605/; classtype:trojan-activity;sid:84770705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f4cf83"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907606/; classtype:trojan-activity;sid:84770706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/98b74b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907607/; classtype:trojan-activity;sid:84770707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/018391"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907608/; classtype:trojan-activity;sid:84770708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8777eb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907609/; classtype:trojan-activity;sid:84770709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3d44b0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907610/; classtype:trojan-activity;sid:84770710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/544c67"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907611/; classtype:trojan-activity;sid:84770711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1f8f91"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907612/; classtype:trojan-activity;sid:84770712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f2a73f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907613/; classtype:trojan-activity;sid:84770713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e9f1be"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907614/; classtype:trojan-activity;sid:84770714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45eaba"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907615/; classtype:trojan-activity;sid:84770715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fd0af6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907616/; classtype:trojan-activity;sid:84770716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eb0dd6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907617/; classtype:trojan-activity;sid:84770717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35d27a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907618/; classtype:trojan-activity;sid:84770718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ce52a6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907577/; classtype:trojan-activity;sid:84770677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efcd2d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907578/; classtype:trojan-activity;sid:84770678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c93345"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907579/; classtype:trojan-activity;sid:84770679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/191fb3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907580/; classtype:trojan-activity;sid:84770680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/88c40a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907581/; classtype:trojan-activity;sid:84770681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2c2aa6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907582/; classtype:trojan-activity;sid:84770682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/71e32a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907583/; classtype:trojan-activity;sid:84770683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b646e0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907584/; classtype:trojan-activity;sid:84770684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fc264e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907585/; classtype:trojan-activity;sid:84770685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.106.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907576/; classtype:trojan-activity;sid:84770676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.42.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907575/; classtype:trojan-activity;sid:84770675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.186.230.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907574/; classtype:trojan-activity;sid:84770674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.26.82.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907573/; classtype:trojan-activity;sid:84770673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.32.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907572/; classtype:trojan-activity;sid:84770672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.11.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907571/; classtype:trojan-activity;sid:84770671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kushnet.mipsel"; depth:15; endswith; nocase; http.host; content:"45.198.224.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907570/; classtype:trojan-activity;sid:84770670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.188.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907569/; classtype:trojan-activity;sid:84770669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.188.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907568/; classtype:trojan-activity;sid:84770668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"49.73.228.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907567/; classtype:trojan-activity;sid:84770667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.236.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907566/; classtype:trojan-activity;sid:84770666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.172.170.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907565/; classtype:trojan-activity;sid:84770665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"85.108.86.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907564/; classtype:trojan-activity;sid:84770664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_c598446d103f1138.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907563/; classtype:trojan-activity;sid:84770663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.172.170.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907562/; classtype:trojan-activity;sid:84770662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.189.151.32"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907561/; classtype:trojan-activity;sid:84770661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.236.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907540/; classtype:trojan-activity;sid:84770640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.9.139.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907539/; classtype:trojan-activity;sid:84770639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.12.60"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907538/; classtype:trojan-activity;sid:84770638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.177.102.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907537/; classtype:trojan-activity;sid:84770637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"176.77.51.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907531/; classtype:trojan-activity;sid:84770631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.53.200.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907532/; classtype:trojan-activity;sid:84770632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.93.136.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907533/; classtype:trojan-activity;sid:84770633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.43.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907534/; classtype:trojan-activity;sid:84770634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.15.188.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907535/; classtype:trojan-activity;sid:84770635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.15.188.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907536/; classtype:trojan-activity;sid:84770636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.67.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907515/; classtype:trojan-activity;sid:84770615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.67.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907516/; classtype:trojan-activity;sid:84770616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"216.249.4.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907517/; classtype:trojan-activity;sid:84770617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.172.9.203"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907518/; classtype:trojan-activity;sid:84770618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.138.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907519/; classtype:trojan-activity;sid:84770619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"89.189.181.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907520/; classtype:trojan-activity;sid:84770620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.58.115.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907521/; classtype:trojan-activity;sid:84770621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"176.106.241.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907522/; classtype:trojan-activity;sid:84770622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.159.144"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907523/; classtype:trojan-activity;sid:84770623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.41.31"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907524/; classtype:trojan-activity;sid:84770624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.188.94.210"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907525/; classtype:trojan-activity;sid:84770625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.180.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907526/; classtype:trojan-activity;sid:84770626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.88.188"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907527/; classtype:trojan-activity;sid:84770627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.34.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907528/; classtype:trojan-activity;sid:84770628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.149.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907529/; classtype:trojan-activity;sid:84770629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.207.231.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907530/; classtype:trojan-activity;sid:84770630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.169.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907514/; classtype:trojan-activity;sid:84770614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907513/; classtype:trojan-activity;sid:84770613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.192.201"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907510/; classtype:trojan-activity;sid:84770610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.46.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907511/; classtype:trojan-activity;sid:84770611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907512/; classtype:trojan-activity;sid:84770612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.242.128.7"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907494/; classtype:trojan-activity;sid:84770594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907495/; classtype:trojan-activity;sid:84770595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.180.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907496/; classtype:trojan-activity;sid:84770596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.169.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907497/; classtype:trojan-activity;sid:84770597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.94.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907498/; classtype:trojan-activity;sid:84770598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.112.103"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907499/; classtype:trojan-activity;sid:84770599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907500/; classtype:trojan-activity;sid:84770600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.200.113.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907501/; classtype:trojan-activity;sid:84770601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.46.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907502/; classtype:trojan-activity;sid:84770602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.175.56.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907503/; classtype:trojan-activity;sid:84770603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.58.115.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907504/; classtype:trojan-activity;sid:84770604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.59.108.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907505/; classtype:trojan-activity;sid:84770605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.219.119.136"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907506/; classtype:trojan-activity;sid:84770606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.220.83.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907507/; classtype:trojan-activity;sid:84770607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.25.157.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907508/; classtype:trojan-activity;sid:84770608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.25.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907509/; classtype:trojan-activity;sid:84770609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.173.152"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907483/; classtype:trojan-activity;sid:84770583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"216.249.4.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907484/; classtype:trojan-activity;sid:84770584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.232.254.209"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907485/; classtype:trojan-activity;sid:84770585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"89.189.181.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907486/; classtype:trojan-activity;sid:84770586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.138.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907487/; classtype:trojan-activity;sid:84770587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.182.229"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907488/; classtype:trojan-activity;sid:84770588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.87.22.232"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907489/; classtype:trojan-activity;sid:84770589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.173.60.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907490/; classtype:trojan-activity;sid:84770590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.161.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907491/; classtype:trojan-activity;sid:84770591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.88.188"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907492/; classtype:trojan-activity;sid:84770592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907493/; classtype:trojan-activity;sid:84770593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"188.16.85.54"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907478/; classtype:trojan-activity;sid:84770578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"188.16.85.54"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907479/; classtype:trojan-activity;sid:84770579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.53.55.170"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907480/; classtype:trojan-activity;sid:84770580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.77.48.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907481/; classtype:trojan-activity;sid:84770581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.220.83.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907482/; classtype:trojan-activity;sid:84770582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"65.99.181.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907477/; classtype:trojan-activity;sid:84770577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.57.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907476/; classtype:trojan-activity;sid:84770576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.88.222"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907474/; classtype:trojan-activity;sid:84770574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.7.207"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907475/; classtype:trojan-activity;sid:84770575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.189.151.32"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907473/; classtype:trojan-activity;sid:84770573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.243.195"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907472/; classtype:trojan-activity;sid:84770572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.88.136.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907471/; classtype:trojan-activity;sid:84770571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.243.195"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907470/; classtype:trojan-activity;sid:84770570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.91.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907469/; classtype:trojan-activity;sid:84770569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.244.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907468/; classtype:trojan-activity;sid:84770568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.151.113.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907467/; classtype:trojan-activity;sid:84770567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.40.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907466/; classtype:trojan-activity;sid:84770566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.244.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907465/; classtype:trojan-activity;sid:84770565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.126.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907464/; classtype:trojan-activity;sid:84770564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.40.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907463/; classtype:trojan-activity;sid:84770563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.3.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907462/; classtype:trojan-activity;sid:84770562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"80.83.230.144"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907461/; classtype:trojan-activity;sid:84770561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_44ef7cc8421220d0.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907460/; classtype:trojan-activity;sid:84770560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dp.sh"; depth:6; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907459/; classtype:trojan-activity;sid:84770559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_865d4f3e8fa37c05.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907458/; classtype:trojan-activity;sid:84770558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gh/payphone-blip/gd65h7gfd9834/34jtg8sp7"; depth:41; endswith; nocase; http.host; content:"cdn.jsdelivr.net"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907457/; classtype:trojan-activity;sid:84770557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atomic/main_arm7"; depth:17; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907456/; classtype:trojan-activity;sid:84770556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.3.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907455/; classtype:trojan-activity;sid:84770555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.32.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907454/; classtype:trojan-activity;sid:84770554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.6.248"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907453/; classtype:trojan-activity;sid:84770553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.140.10"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907452/; classtype:trojan-activity;sid:84770552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.244.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907451/; classtype:trojan-activity;sid:84770551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.69.95.117"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907450/; classtype:trojan-activity;sid:84770550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.236.222.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907449/; classtype:trojan-activity;sid:84770549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.204.195.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907448/; classtype:trojan-activity;sid:84770548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.145.75"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907447/; classtype:trojan-activity;sid:84770547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.115.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907446/; classtype:trojan-activity;sid:84770546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"193.31.201.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907445/; classtype:trojan-activity;sid:84770545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"96.245.232.186"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907444/; classtype:trojan-activity;sid:84770544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.115.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907443/; classtype:trojan-activity;sid:84770543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.32.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907442/; classtype:trojan-activity;sid:84770542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.190.202.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907441/; classtype:trojan-activity;sid:84770541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.245.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907440/; classtype:trojan-activity;sid:84770540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.126.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907439/; classtype:trojan-activity;sid:84770539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.245.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907438/; classtype:trojan-activity;sid:84770538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907437/; classtype:trojan-activity;sid:84770537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.126.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907436/; classtype:trojan-activity;sid:84770536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.156.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907435/; classtype:trojan-activity;sid:84770535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.74.116"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907434/; classtype:trojan-activity;sid:84770534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907433/; classtype:trojan-activity;sid:84770533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.40.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907432/; classtype:trojan-activity;sid:84770532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907431/; classtype:trojan-activity;sid:84770531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.57.123.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907430/; classtype:trojan-activity;sid:84770530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.90.186.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907429/; classtype:trojan-activity;sid:84770529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.x86"; depth:20; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907428/; classtype:trojan-activity;sid:84770528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.armv7l"; depth:12; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907418/; classtype:trojan-activity;sid:84770518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/gg11"; depth:16; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907419/; classtype:trojan-activity;sid:84770519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.arm5"; depth:21; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907423/; classtype:trojan-activity;sid:84770523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.mips"; depth:10; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907424/; classtype:trojan-activity;sid:84770524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dropper"; depth:8; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907417/; classtype:trojan-activity;sid:84770517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.armv6l"; depth:12; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907415/; classtype:trojan-activity;sid:84770515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.bash_history"; depth:14; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907416/; classtype:trojan-activity;sid:84770516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.x64"; depth:20; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907411/; classtype:trojan-activity;sid:84770511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.mipsel"; depth:12; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907412/; classtype:trojan-activity;sid:84770512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.armv4l"; depth:12; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907413/; classtype:trojan-activity;sid:84770513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot"; depth:4; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907414/; classtype:trojan-activity;sid:84770514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.arm7"; depth:21; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907401/; classtype:trojan-activity;sid:84770501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.sh4"; depth:9; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907402/; classtype:trojan-activity;sid:84770502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.sparc"; depth:11; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907403/; classtype:trojan-activity;sid:84770503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.i686"; depth:10; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907404/; classtype:trojan-activity;sid:84770504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.mipsel"; depth:23; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907406/; classtype:trojan-activity;sid:84770506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.arm6"; depth:21; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907407/; classtype:trojan-activity;sid:84770507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.i486"; depth:21; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907408/; classtype:trojan-activity;sid:84770508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.m68k"; depth:10; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907409/; classtype:trojan-activity;sid:84770509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.mips"; depth:21; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907410/; classtype:trojan-activity;sid:84770510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.ppc440"; depth:23; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907395/; classtype:trojan-activity;sid:84770495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.armv5l"; depth:12; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907396/; classtype:trojan-activity;sid:84770496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.powerpc-440fp"; depth:19; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907390/; classtype:trojan-activity;sid:84770490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.sparc"; depth:22; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907391/; classtype:trojan-activity;sid:84770491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/dp.sh"; depth:17; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907392/; classtype:trojan-activity;sid:84770492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.i586"; depth:10; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907393/; classtype:trojan-activity;sid:84770493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.m68k"; depth:21; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907385/; classtype:trojan-activity;sid:84770485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.i686"; depth:21; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907383/; classtype:trojan-activity;sid:84770483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.sh4"; depth:20; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907381/; classtype:trojan-activity;sid:84770481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.40.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907382/; classtype:trojan-activity;sid:84770482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.ppc"; depth:20; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907377/; classtype:trojan-activity;sid:84770477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raul.powerpc"; depth:13; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907378/; classtype:trojan-activity;sid:84770478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http_files/pito.arm4"; depth:21; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907380/; classtype:trojan-activity;sid:84770480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.72.97.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907374/; classtype:trojan-activity;sid:84770474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.173.152"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907373/; classtype:trojan-activity;sid:84770473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.215.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907372/; classtype:trojan-activity;sid:84770472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.78.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907371/; classtype:trojan-activity;sid:84770471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot"; depth:4; endswith; nocase; http.host; content:"94.154.43.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907370/; classtype:trojan-activity;sid:84770470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.177.251.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907369/; classtype:trojan-activity;sid:84770469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.42.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907368/; classtype:trojan-activity;sid:84770468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907367/; classtype:trojan-activity;sid:84770467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.179.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907366/; classtype:trojan-activity;sid:84770466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.242.128.7"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907365/; classtype:trojan-activity;sid:84770465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.35.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907364/; classtype:trojan-activity;sid:84770464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.179.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907363/; classtype:trojan-activity;sid:84770463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.157.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907362/; classtype:trojan-activity;sid:84770462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.247.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907361/; classtype:trojan-activity;sid:84770461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.40.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907360/; classtype:trojan-activity;sid:84770460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.234.246.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907359/; classtype:trojan-activity;sid:84770459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.157.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907358/; classtype:trojan-activity;sid:84770458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.249.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907357/; classtype:trojan-activity;sid:84770457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.249.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907356/; classtype:trojan-activity;sid:84770456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.238.175.117"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907355/; classtype:trojan-activity;sid:84770455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.10.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907354/; classtype:trojan-activity;sid:84770454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.1.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907353/; classtype:trojan-activity;sid:84770453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.10.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907352/; classtype:trojan-activity;sid:84770452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.167.77.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907351/; classtype:trojan-activity;sid:84770451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.241.8.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907350/; classtype:trojan-activity;sid:84770450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.205.226.191"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907349/; classtype:trojan-activity;sid:84770449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.83.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907348/; classtype:trojan-activity;sid:84770448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"72.255.30.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907347/; classtype:trojan-activity;sid:84770447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907346/; classtype:trojan-activity;sid:84770446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"185.205.226.191"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907345/; classtype:trojan-activity;sid:84770445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"72.255.30.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907344/; classtype:trojan-activity;sid:84770444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907343/; classtype:trojan-activity;sid:84770443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.22.248.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907342/; classtype:trojan-activity;sid:84770442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.152.11.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907341/; classtype:trojan-activity;sid:84770441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.205.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907340/; classtype:trojan-activity;sid:84770440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.1.98"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907339/; classtype:trojan-activity;sid:84770439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.1.98"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907338/; classtype:trojan-activity;sid:84770438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.230.83.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907337/; classtype:trojan-activity;sid:84770437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.9.35.137"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907336/; classtype:trojan-activity;sid:84770436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.116.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907335/; classtype:trojan-activity;sid:84770435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.9.35.137"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907334/; classtype:trojan-activity;sid:84770434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.154.188.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907333/; classtype:trojan-activity;sid:84770433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.124.102"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907332/; classtype:trojan-activity;sid:84770432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.116.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907331/; classtype:trojan-activity;sid:84770431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.124.102"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907330/; classtype:trojan-activity;sid:84770430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.202.22.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907329/; classtype:trojan-activity;sid:84770429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.154.188.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907328/; classtype:trojan-activity;sid:84770428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.55.26.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907326/; classtype:trojan-activity;sid:84770426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.202.22.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907325/; classtype:trojan-activity;sid:84770425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.71.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907324/; classtype:trojan-activity;sid:84770424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.186.190"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907323/; classtype:trojan-activity;sid:84770423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.3.162"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907322/; classtype:trojan-activity;sid:84770422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.169.60.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907321/; classtype:trojan-activity;sid:84770421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.169.60.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907320/; classtype:trojan-activity;sid:84770420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.88.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907319/; classtype:trojan-activity;sid:84770419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.96.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907318/; classtype:trojan-activity;sid:84770418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.125.18.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907317/; classtype:trojan-activity;sid:84770417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.59.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907316/; classtype:trojan-activity;sid:84770416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7782139129/d40iw6t.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907315/; classtype:trojan-activity;sid:84770415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.49.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907314/; classtype:trojan-activity;sid:84770414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.59.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907313/; classtype:trojan-activity;sid:84770413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.177.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907312/; classtype:trojan-activity;sid:84770412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_bb11b14604ad9109.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907311/; classtype:trojan-activity;sid:84770411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtm.sparc"; depth:10; endswith; nocase; http.host; content:"91.92.40.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907310/; classtype:trojan-activity;sid:84770410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtm.arm"; depth:8; endswith; nocase; http.host; content:"91.92.40.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907307/; classtype:trojan-activity;sid:84770407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtm.x86"; depth:8; endswith; nocase; http.host; content:"91.92.40.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907308/; classtype:trojan-activity;sid:84770408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"39.165.187.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907309/; classtype:trojan-activity;sid:84770409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtm.arm7"; depth:9; endswith; nocase; http.host; content:"91.92.40.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907302/; classtype:trojan-activity;sid:84770402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtm.arm6"; depth:9; endswith; nocase; http.host; content:"91.92.40.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907303/; classtype:trojan-activity;sid:84770403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtm.mips"; depth:9; endswith; nocase; http.host; content:"91.92.40.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907304/; classtype:trojan-activity;sid:84770404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.py"; depth:7; endswith; nocase; http.host; content:"51.210.44.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907305/; classtype:trojan-activity;sid:84770405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtm.arm5"; depth:9; endswith; nocase; http.host; content:"91.92.40.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907306/; classtype:trojan-activity;sid:84770406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg11"; depth:5; endswith; nocase; http.host; content:"150.241.65.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907301/; classtype:trojan-activity;sid:84770401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a91ac6d4a7389993.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907300/; classtype:trojan-activity;sid:84770400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psdll"; depth:6; endswith; nocase; http.host; content:"verification-process.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907299/; classtype:trojan-activity;sid:84770399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/servicer.apk"; depth:13; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907291/; classtype:trojan-activity;sid:84770391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telnet.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907292/; classtype:trojan-activity;sid:84770392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntb.x64"; depth:8; endswith; nocase; http.host; content:"217.60.102.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907293/; classtype:trojan-activity;sid:84770393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntb.x86"; depth:8; endswith; nocase; http.host; content:"217.60.102.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907294/; classtype:trojan-activity;sid:84770394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntb.armv6"; depth:10; endswith; nocase; http.host; content:"217.60.102.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907295/; classtype:trojan-activity;sid:84770395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntb.armv7"; depth:10; endswith; nocase; http.host; content:"217.60.102.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907296/; classtype:trojan-activity;sid:84770396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntb.armv5"; depth:10; endswith; nocase; http.host; content:"217.60.102.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907297/; classtype:trojan-activity;sid:84770397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntb.mips"; depth:9; endswith; nocase; http.host; content:"217.60.102.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907298/; classtype:trojan-activity;sid:84770398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_dccbce95dc080534.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907290/; classtype:trojan-activity;sid:84770390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_aa509ab4dee7634e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907285/; classtype:trojan-activity;sid:84770385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_273b8dff51cd4015.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907286/; classtype:trojan-activity;sid:84770386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_adad2e4ddbc81c70.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907287/; classtype:trojan-activity;sid:84770387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/services.apk"; depth:13; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907288/; classtype:trojan-activity;sid:84770388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5513ab74e8b43371.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907289/; classtype:trojan-activity;sid:84770389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.167.175.108"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907284/; classtype:trojan-activity;sid:84770384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.x86"; depth:14; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907282/; classtype:trojan-activity;sid:84770382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.x86_64"; depth:17; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907283/; classtype:trojan-activity;sid:84770383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.ppc"; depth:14; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907280/; classtype:trojan-activity;sid:84770380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.mpsl"; depth:15; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907281/; classtype:trojan-activity;sid:84770381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arm6"; depth:15; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907272/; classtype:trojan-activity;sid:84770372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.aarch64"; depth:18; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907273/; classtype:trojan-activity;sid:84770373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arm7"; depth:15; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907274/; classtype:trojan-activity;sid:84770374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arm"; depth:14; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907275/; classtype:trojan-activity;sid:84770375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arc"; depth:14; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907276/; classtype:trojan-activity;sid:84770376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arm5"; depth:15; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907277/; classtype:trojan-activity;sid:84770377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.m68k"; depth:15; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907278/; classtype:trojan-activity;sid:84770378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.mips"; depth:15; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907279/; classtype:trojan-activity;sid:84770379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.i686"; depth:11; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907271/; classtype:trojan-activity;sid:84770371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.i486"; depth:11; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907268/; classtype:trojan-activity;sid:84770368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.x86_64"; depth:13; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907269/; classtype:trojan-activity;sid:84770369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.mips"; depth:11; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907270/; classtype:trojan-activity;sid:84770370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.powerpc"; depth:14; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907261/; classtype:trojan-activity;sid:84770361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.armv4l"; depth:13; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907262/; classtype:trojan-activity;sid:84770362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.i586"; depth:11; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907263/; classtype:trojan-activity;sid:84770363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.mipsel"; depth:13; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907264/; classtype:trojan-activity;sid:84770364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.armv6l"; depth:13; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907265/; classtype:trojan-activity;sid:84770365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.armv7l"; depth:13; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907266/; classtype:trojan-activity;sid:84770366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agbot.armv5l"; depth:13; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907267/; classtype:trojan-activity;sid:84770367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.16.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907260/; classtype:trojan-activity;sid:84770360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i468"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907259/; classtype:trojan-activity;sid:84770359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907257/; classtype:trojan-activity;sid:84770357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907253/; classtype:trojan-activity;sid:84770353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mirai.arm7"; depth:16; endswith; nocase; http.host; content:"193.111.117.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907254/; classtype:trojan-activity;sid:84770354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mirai.x86"; depth:15; endswith; nocase; http.host; content:"193.111.117.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907255/; classtype:trojan-activity;sid:84770355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"185.104.63.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907256/; classtype:trojan-activity;sid:84770356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.sh"; depth:11; endswith; nocase; http.host; content:"2.27.248.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907247/; classtype:trojan-activity;sid:84770347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907248/; classtype:trojan-activity;sid:84770348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907249/; classtype:trojan-activity;sid:84770349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907250/; classtype:trojan-activity;sid:84770350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907251/; classtype:trojan-activity;sid:84770351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s"; depth:2; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907252/; classtype:trojan-activity;sid:84770352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907244/; classtype:trojan-activity;sid:84770344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907245/; classtype:trojan-activity;sid:84770345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907246/; classtype:trojan-activity;sid:84770346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.6.48"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907243/; classtype:trojan-activity;sid:84770343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.16.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907242/; classtype:trojan-activity;sid:84770342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.167.175.108"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907241/; classtype:trojan-activity;sid:84770341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.6.48"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907240/; classtype:trojan-activity;sid:84770340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.42.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907239/; classtype:trojan-activity;sid:84770339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.11.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907238/; classtype:trojan-activity;sid:84770338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.11.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907237/; classtype:trojan-activity;sid:84770337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.125.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907236/; classtype:trojan-activity;sid:84770336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.118.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907235/; classtype:trojan-activity;sid:84770335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.48.131"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907234/; classtype:trojan-activity;sid:84770334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907233/; classtype:trojan-activity;sid:84770333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907232/; classtype:trojan-activity;sid:84770332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.139.68"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907231/; classtype:trojan-activity;sid:84770331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.230.83.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907230/; classtype:trojan-activity;sid:84770330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.57.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907229/; classtype:trojan-activity;sid:84770329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"24.54.95.49"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907228/; classtype:trojan-activity;sid:84770328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.230.168.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907227/; classtype:trojan-activity;sid:84770327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.234.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907226/; classtype:trojan-activity;sid:84770326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.57.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907225/; classtype:trojan-activity;sid:84770325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.109.237.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907224/; classtype:trojan-activity;sid:84770324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.0.60.188"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907223/; classtype:trojan-activity;sid:84770323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.118.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907222/; classtype:trojan-activity;sid:84770322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.130.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907221/; classtype:trojan-activity;sid:84770321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.57.122.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907220/; classtype:trojan-activity;sid:84770320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.3.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907219/; classtype:trojan-activity;sid:84770319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.151.224.238"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907218/; classtype:trojan-activity;sid:84770318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.241.136.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907217/; classtype:trojan-activity;sid:84770317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.3.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907215/; classtype:trojan-activity;sid:84770315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.241.136.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907216/; classtype:trojan-activity;sid:84770316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.98.147.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907214/; classtype:trojan-activity;sid:84770314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.1.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907212/; classtype:trojan-activity;sid:84770312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.234.246.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907213/; classtype:trojan-activity;sid:84770313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.215.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907210/; classtype:trojan-activity;sid:84770310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.151.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907211/; classtype:trojan-activity;sid:84770311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.32.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907204/; classtype:trojan-activity;sid:84770304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.42.7"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907205/; classtype:trojan-activity;sid:84770305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.6.248"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907206/; classtype:trojan-activity;sid:84770306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.42.7"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907207/; classtype:trojan-activity;sid:84770307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.60.223.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907208/; classtype:trojan-activity;sid:84770308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.145.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907209/; classtype:trojan-activity;sid:84770309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.42.71.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907177/; classtype:trojan-activity;sid:84770277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.205.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907178/; classtype:trojan-activity;sid:84770278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.15.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907179/; classtype:trojan-activity;sid:84770279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.38.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907180/; classtype:trojan-activity;sid:84770280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.229.190.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907181/; classtype:trojan-activity;sid:84770281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.136.52.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907182/; classtype:trojan-activity;sid:84770282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.76.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907183/; classtype:trojan-activity;sid:84770283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"66.8.135.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907184/; classtype:trojan-activity;sid:84770284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.227.224.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907185/; classtype:trojan-activity;sid:84770285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.6.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907186/; classtype:trojan-activity;sid:84770286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.205.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907187/; classtype:trojan-activity;sid:84770287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.255.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907188/; classtype:trojan-activity;sid:84770288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.42.71.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907189/; classtype:trojan-activity;sid:84770289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.100.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907190/; classtype:trojan-activity;sid:84770290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.68.95.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907191/; classtype:trojan-activity;sid:84770291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.57.66.51"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907192/; classtype:trojan-activity;sid:84770292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.138.63"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907193/; classtype:trojan-activity;sid:84770293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.160.130.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907194/; classtype:trojan-activity;sid:84770294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.243.238.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907195/; classtype:trojan-activity;sid:84770295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.49.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907196/; classtype:trojan-activity;sid:84770296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.97.30.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907197/; classtype:trojan-activity;sid:84770297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.55.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907198/; classtype:trojan-activity;sid:84770298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.81.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907199/; classtype:trojan-activity;sid:84770299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.55.170"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907200/; classtype:trojan-activity;sid:84770300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.190.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907201/; classtype:trojan-activity;sid:84770301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.98.147.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907202/; classtype:trojan-activity;sid:84770302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"93.88.96.103"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907203/; classtype:trojan-activity;sid:84770303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.227.224.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907171/; classtype:trojan-activity;sid:84770271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.24.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907172/; classtype:trojan-activity;sid:84770272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.226.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907173/; classtype:trojan-activity;sid:84770273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.97.30.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907174/; classtype:trojan-activity;sid:84770274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.6.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907175/; classtype:trojan-activity;sid:84770275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.117.164.177"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907176/; classtype:trojan-activity;sid:84770276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.204.195.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907141/; classtype:trojan-activity;sid:84770241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.24.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907142/; classtype:trojan-activity;sid:84770242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.188.77.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907143/; classtype:trojan-activity;sid:84770243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.233.107"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907144/; classtype:trojan-activity;sid:84770244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.113.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907145/; classtype:trojan-activity;sid:84770245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.86.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907146/; classtype:trojan-activity;sid:84770246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.40.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907147/; classtype:trojan-activity;sid:84770247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.92.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907148/; classtype:trojan-activity;sid:84770248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.35.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907149/; classtype:trojan-activity;sid:84770249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.183.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907150/; classtype:trojan-activity;sid:84770250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.150.176.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907151/; classtype:trojan-activity;sid:84770251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.34.109.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907152/; classtype:trojan-activity;sid:84770252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"66.8.135.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907153/; classtype:trojan-activity;sid:84770253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.34.109.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907154/; classtype:trojan-activity;sid:84770254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.230.30.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907155/; classtype:trojan-activity;sid:84770255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.244.41.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907156/; classtype:trojan-activity;sid:84770256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.255.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907157/; classtype:trojan-activity;sid:84770257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.77.48.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907158/; classtype:trojan-activity;sid:84770258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.230.30.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907159/; classtype:trojan-activity;sid:84770259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"85.108.84.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907160/; classtype:trojan-activity;sid:84770260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.74.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907161/; classtype:trojan-activity;sid:84770261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.38.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907162/; classtype:trojan-activity;sid:84770262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.138.63"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907163/; classtype:trojan-activity;sid:84770263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.24.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907164/; classtype:trojan-activity;sid:84770264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.140.187.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907165/; classtype:trojan-activity;sid:84770265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.9.18"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907166/; classtype:trojan-activity;sid:84770266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.184.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907167/; classtype:trojan-activity;sid:84770267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.55.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907168/; classtype:trojan-activity;sid:84770268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.117.164.177"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907169/; classtype:trojan-activity;sid:84770269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.151.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907170/; classtype:trojan-activity;sid:84770270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.86.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907140/; classtype:trojan-activity;sid:84770240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.57.122.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907139/; classtype:trojan-activity;sid:84770239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.130.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907138/; classtype:trojan-activity;sid:84770238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.188.94.210"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907137/; classtype:trojan-activity;sid:84770237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.109.237.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907136/; classtype:trojan-activity;sid:84770236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.42.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907135/; classtype:trojan-activity;sid:84770235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.184.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907134/; classtype:trojan-activity;sid:84770234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.151.43.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907133/; classtype:trojan-activity;sid:84770233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.13.149.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907132/; classtype:trojan-activity;sid:84770232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.160.130.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907131/; classtype:trojan-activity;sid:84770231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.70.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907130/; classtype:trojan-activity;sid:84770230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"216.196.170.32"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907129/; classtype:trojan-activity;sid:84770229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.237.148.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907128/; classtype:trojan-activity;sid:84770228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.70.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907127/; classtype:trojan-activity;sid:84770227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.237.148.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907126/; classtype:trojan-activity;sid:84770226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907125/; classtype:trojan-activity;sid:84770225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.34.146"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907124/; classtype:trojan-activity;sid:84770224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.34.146"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907123/; classtype:trojan-activity;sid:84770223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.13.149.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907122/; classtype:trojan-activity;sid:84770222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.49.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907121/; classtype:trojan-activity;sid:84770221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.20.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907120/; classtype:trojan-activity;sid:84770220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.213.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907119/; classtype:trojan-activity;sid:84770219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.124.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907118/; classtype:trojan-activity;sid:84770218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.175.210.205"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907117/; classtype:trojan-activity;sid:84770217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.177.11.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907116/; classtype:trojan-activity;sid:84770216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.106.88"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907115/; classtype:trojan-activity;sid:84770215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.137.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907114/; classtype:trojan-activity;sid:84770214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.79.0.238"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907113/; classtype:trojan-activity;sid:84770213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.106.88"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907112/; classtype:trojan-activity;sid:84770212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.189.23.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907111/; classtype:trojan-activity;sid:84770211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.79.0.238"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907110/; classtype:trojan-activity;sid:84770210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.242.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907109/; classtype:trojan-activity;sid:84770209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.39.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907108/; classtype:trojan-activity;sid:84770208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.83.215"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907107/; classtype:trojan-activity;sid:84770207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.177.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907106/; classtype:trojan-activity;sid:84770206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.242.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907105/; classtype:trojan-activity;sid:84770205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.190.223"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907104/; classtype:trojan-activity;sid:84770204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.228.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907103/; classtype:trojan-activity;sid:84770203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.49.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907102/; classtype:trojan-activity;sid:84770202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.139.14.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907101/; classtype:trojan-activity;sid:84770201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.233.107"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907100/; classtype:trojan-activity;sid:84770200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.228.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907099/; classtype:trojan-activity;sid:84770199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.22.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907098/; classtype:trojan-activity;sid:84770198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.124.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907097/; classtype:trojan-activity;sid:84770197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.223.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907096/; classtype:trojan-activity;sid:84770196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.234.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907095/; classtype:trojan-activity;sid:84770195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.150.176.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907094/; classtype:trojan-activity;sid:84770194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.47.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907093/; classtype:trojan-activity;sid:84770193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.22.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907092/; classtype:trojan-activity;sid:84770192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.223.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907091/; classtype:trojan-activity;sid:84770191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.75.99"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907089/; classtype:trojan-activity;sid:84770189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.29.22.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907090/; classtype:trojan-activity;sid:84770190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.10.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907088/; classtype:trojan-activity;sid:84770188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.10.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907087/; classtype:trojan-activity;sid:84770187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.247.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907086/; classtype:trojan-activity;sid:84770186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.23.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907085/; classtype:trojan-activity;sid:84770185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.29.22.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907084/; classtype:trojan-activity;sid:84770184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.175.210.205"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907083/; classtype:trojan-activity;sid:84770183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.23.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907082/; classtype:trojan-activity;sid:84770182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.3.121"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907081/; classtype:trojan-activity;sid:84770181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.3.121"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907080/; classtype:trojan-activity;sid:84770180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.79.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907079/; classtype:trojan-activity;sid:84770179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.246.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907078/; classtype:trojan-activity;sid:84770178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.243.238.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907077/; classtype:trojan-activity;sid:84770177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.35.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907076/; classtype:trojan-activity;sid:84770176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.79.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907075/; classtype:trojan-activity;sid:84770175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.246.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907074/; classtype:trojan-activity;sid:84770174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.68.249.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907073/; classtype:trojan-activity;sid:84770173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.138.47.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907072/; classtype:trojan-activity;sid:84770172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.88.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907071/; classtype:trojan-activity;sid:84770171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.233.94.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907070/; classtype:trojan-activity;sid:84770170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"185.233.94.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907069/; classtype:trojan-activity;sid:84770169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.88.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907068/; classtype:trojan-activity;sid:84770168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.205.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907067/; classtype:trojan-activity;sid:84770167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.213.115.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907066/; classtype:trojan-activity;sid:84770166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.205.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907065/; classtype:trojan-activity;sid:84770165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.85.209.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907064/; classtype:trojan-activity;sid:84770164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.174.198"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907063/; classtype:trojan-activity;sid:84770163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.20.178"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907062/; classtype:trojan-activity;sid:84770162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.85.209.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907061/; classtype:trojan-activity;sid:84770161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.189.172.160"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907060/; classtype:trojan-activity;sid:84770160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.115.67.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907059/; classtype:trojan-activity;sid:84770159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.194.25.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907058/; classtype:trojan-activity;sid:84770158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.174.198"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907057/; classtype:trojan-activity;sid:84770157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.0.179"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907056/; classtype:trojan-activity;sid:84770156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.189.172.160"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907055/; classtype:trojan-activity;sid:84770155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.198.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907054/; classtype:trojan-activity;sid:84770154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.182.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907053/; classtype:trojan-activity;sid:84770153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.0.179"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907052/; classtype:trojan-activity;sid:84770152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.1.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907051/; classtype:trojan-activity;sid:84770151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.62.249"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907050/; classtype:trojan-activity;sid:84770150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.82.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907049/; classtype:trojan-activity;sid:84770149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.142.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907048/; classtype:trojan-activity;sid:84770148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.179.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907047/; classtype:trojan-activity;sid:84770147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.75.99"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907046/; classtype:trojan-activity;sid:84770146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.242.168"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907045/; classtype:trojan-activity;sid:84770145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.149.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907044/; classtype:trojan-activity;sid:84770144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.142.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907043/; classtype:trojan-activity;sid:84770143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"66.212.173.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907042/; classtype:trojan-activity;sid:84770142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.82.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907041/; classtype:trojan-activity;sid:84770141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.86.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907040/; classtype:trojan-activity;sid:84770140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.86.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907039/; classtype:trojan-activity;sid:84770139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.3.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907038/; classtype:trojan-activity;sid:84770138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"217.64.135.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907037/; classtype:trojan-activity;sid:84770137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.210.95"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907036/; classtype:trojan-activity;sid:84770136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.149.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907035/; classtype:trojan-activity;sid:84770135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"66.212.173.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907034/; classtype:trojan-activity;sid:84770134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.183.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907033/; classtype:trojan-activity;sid:84770133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.243.95.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907032/; classtype:trojan-activity;sid:84770132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.14.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907031/; classtype:trojan-activity;sid:84770131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.210.95"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907030/; classtype:trojan-activity;sid:84770130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.242.168"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907029/; classtype:trojan-activity;sid:84770129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.235.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907028/; classtype:trojan-activity;sid:84770128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.161.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907027/; classtype:trojan-activity;sid:84770127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.14.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907026/; classtype:trojan-activity;sid:84770126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.232.254.209"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907025/; classtype:trojan-activity;sid:84770125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.21.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907024/; classtype:trojan-activity;sid:84770124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.82.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907023/; classtype:trojan-activity;sid:84770123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.21.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907022/; classtype:trojan-activity;sid:84770122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.214.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907021/; classtype:trojan-activity;sid:84770121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.82.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907020/; classtype:trojan-activity;sid:84770120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.219.119.136"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907019/; classtype:trojan-activity;sid:84770119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.206.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907018/; classtype:trojan-activity;sid:84770118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.211.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907017/; classtype:trojan-activity;sid:84770117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.144.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907016/; classtype:trojan-activity;sid:84770116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.105.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907015/; classtype:trojan-activity;sid:84770115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.234.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907014/; classtype:trojan-activity;sid:84770114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.235.202"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907013/; classtype:trojan-activity;sid:84770113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.211.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907012/; classtype:trojan-activity;sid:84770112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.105.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907011/; classtype:trojan-activity;sid:84770111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.184.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907010/; classtype:trojan-activity;sid:84770110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.70.235.87"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907009/; classtype:trojan-activity;sid:84770109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.184.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907008/; classtype:trojan-activity;sid:84770108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.230.68.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907007/; classtype:trojan-activity;sid:84770107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.76.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907006/; classtype:trojan-activity;sid:84770106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"174.105.154.212"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907005/; classtype:trojan-activity;sid:84770105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.40.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907004/; classtype:trojan-activity;sid:84770104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.62.249"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907003/; classtype:trojan-activity;sid:84770103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.213.115.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907002/; classtype:trojan-activity;sid:84770102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.81.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907001/; classtype:trojan-activity;sid:84770101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.77.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907000/; classtype:trojan-activity;sid:84770100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.117.140"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906999/; classtype:trojan-activity;sid:84770099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906988/; classtype:trojan-activity;sid:84770088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906989/; classtype:trojan-activity;sid:84770089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906990/; classtype:trojan-activity;sid:84770090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906991/; classtype:trojan-activity;sid:84770091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/persist.arm7"; depth:13; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906992/; classtype:trojan-activity;sid:84770092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906993/; classtype:trojan-activity;sid:84770093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906994/; classtype:trojan-activity;sid:84770094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906995/; classtype:trojan-activity;sid:84770095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906996/; classtype:trojan-activity;sid:84770096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906997/; classtype:trojan-activity;sid:84770097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906998/; classtype:trojan-activity;sid:84770098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.178.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906987/; classtype:trojan-activity;sid:84770087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906986/; classtype:trojan-activity;sid:84770086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906985/; classtype:trojan-activity;sid:84770085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906984/; classtype:trojan-activity;sid:84770084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906983/; classtype:trojan-activity;sid:84770083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.180.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906982/; classtype:trojan-activity;sid:84770082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.24.21.177"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906981/; classtype:trojan-activity;sid:84770081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906980/; classtype:trojan-activity;sid:84770080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906979/; classtype:trojan-activity;sid:84770079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906978/; classtype:trojan-activity;sid:84770078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906977/; classtype:trojan-activity;sid:84770077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.183.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906976/; classtype:trojan-activity;sid:84770076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906974/; classtype:trojan-activity;sid:84770074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906975/; classtype:trojan-activity;sid:84770075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4ba1a9722212abed.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906973/; classtype:trojan-activity;sid:84770073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906971/; classtype:trojan-activity;sid:84770071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906972/; classtype:trojan-activity;sid:84770072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.85.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906970/; classtype:trojan-activity;sid:84770070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.180.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906969/; classtype:trojan-activity;sid:84770069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.117.140"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906968/; classtype:trojan-activity;sid:84770068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.252.216.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906967/; classtype:trojan-activity;sid:84770067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagenes2/msi_pro.png"; depth:22; endswith; nocase; http.host; content:"munihuacho.gob.pe"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906966/; classtype:trojan-activity;sid:84770066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dot/n1.png"; depth:11; endswith; nocase; http.host; content:"eccmice.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906961/; classtype:trojan-activity;sid:84770061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dot/mk4.png"; depth:12; endswith; nocase; http.host; content:"eccmice.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906962/; classtype:trojan-activity;sid:84770062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dot/mb.png"; depth:11; endswith; nocase; http.host; content:"eccmice.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906963/; classtype:trojan-activity;sid:84770063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dot/nd7.png"; depth:12; endswith; nocase; http.host; content:"eccmice.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906964/; classtype:trojan-activity;sid:84770064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dot/a2.png"; depth:11; endswith; nocase; http.host; content:"eccmice.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906965/; classtype:trojan-activity;sid:84770065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dot/a1.png"; depth:11; endswith; nocase; http.host; content:"eccmice.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906960/; classtype:trojan-activity;sid:84770060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dot/x1.png"; depth:11; endswith; nocase; http.host; content:"eccmice.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906959/; classtype:trojan-activity;sid:84770059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.well-known/new/stego_rabit.png"; depth:32; endswith; nocase; http.host; content:"flicargo.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906956/; classtype:trojan-activity;sid:84770056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.well-known/new/stego_bb.png"; depth:29; endswith; nocase; http.host; content:"flicargo.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906957/; classtype:trojan-activity;sid:84770057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.well-known/new/stego_shot.png"; depth:31; endswith; nocase; http.host; content:"flicargo.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906958/; classtype:trojan-activity;sid:84770058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.well-known/new/stego_ukhdu9nsgd.png"; depth:37; endswith; nocase; http.host; content:"flicargo.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906955/; classtype:trojan-activity;sid:84770055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/softbot.mips"; depth:13; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906954/; classtype:trojan-activity;sid:84770054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/stego_anepqnd5rj.png"; depth:25; endswith; nocase; http.host; content:"coconutoficial.com.br"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906953/; classtype:trojan-activity;sid:84770053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.177.102.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906952/; classtype:trojan-activity;sid:84770052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.231.225.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906951/; classtype:trojan-activity;sid:84770051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.30.58"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906950/; classtype:trojan-activity;sid:84770050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.231.225.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906949/; classtype:trojan-activity;sid:84770049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.123.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906948/; classtype:trojan-activity;sid:84770048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.168.179"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906947/; classtype:trojan-activity;sid:84770047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_043051.png"; depth:15; endswith; nocase; http.host; content:"deliverymailreport.co.za"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906946/; classtype:trojan-activity;sid:84770046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_003735.png"; depth:15; endswith; nocase; http.host; content:"deliverymailreport.co.za"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906944/; classtype:trojan-activity;sid:84770044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_003940.png"; depth:15; endswith; nocase; http.host; content:"deliverymailreport.co.za"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906945/; classtype:trojan-activity;sid:84770045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_043509.png"; depth:15; endswith; nocase; http.host; content:"deliverymailreport.co.za"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906943/; classtype:trojan-activity;sid:84770043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_pro.png"; depth:12; endswith; nocase; http.host; content:"deliverymailreport.co.za"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906942/; classtype:trojan-activity;sid:84770042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_043346.png"; depth:15; endswith; nocase; http.host; content:"deliverymailreport.co.za"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906941/; classtype:trojan-activity;sid:84770041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.123.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906940/; classtype:trojan-activity;sid:84770040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/rest-api/bisdaqc/1iqouyb/vsdfptm/nn/crypted.ps1"; depth:60; endswith; nocase; http.host; content:"8.136.138.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906939/; classtype:trojan-activity;sid:84770039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.171.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906938/; classtype:trojan-activity;sid:84770038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.13.235.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906937/; classtype:trojan-activity;sid:84770037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.251.27"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906936/; classtype:trojan-activity;sid:84770036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.171.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906935/; classtype:trojan-activity;sid:84770035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.168.179"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906934/; classtype:trojan-activity;sid:84770034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blog/chrome.exe"; depth:16; endswith; nocase; http.host; content:"bulkdevices.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906933/; classtype:trojan-activity;sid:84770033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aa/setup.rar"; depth:13; endswith; nocase; http.host; content:"winds11.site"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906932/; classtype:trojan-activity;sid:84770032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dollar.exe"; depth:11; endswith; nocase; http.host; content:"mon-blanc-03.cfd"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906931/; classtype:trojan-activity;sid:84770031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8d34d4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906919/; classtype:trojan-activity;sid:84770019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/07c643"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906920/; classtype:trojan-activity;sid:84770020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/14515c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906921/; classtype:trojan-activity;sid:84770021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bb74f6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906922/; classtype:trojan-activity;sid:84770022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44973f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906923/; classtype:trojan-activity;sid:84770023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/330a6e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906924/; classtype:trojan-activity;sid:84770024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c915c0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906925/; classtype:trojan-activity;sid:84770025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0dfd70"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906926/; classtype:trojan-activity;sid:84770026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8c04f2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906927/; classtype:trojan-activity;sid:84770027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8bea3b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906928/; classtype:trojan-activity;sid:84770028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/452bff"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906929/; classtype:trojan-activity;sid:84770029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/feb455"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906930/; classtype:trojan-activity;sid:84770030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ae2072"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906895/; classtype:trojan-activity;sid:84769995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e489b0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906896/; classtype:trojan-activity;sid:84769996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9a923d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906897/; classtype:trojan-activity;sid:84769997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/455b2c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906898/; classtype:trojan-activity;sid:84769998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/119bdc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906899/; classtype:trojan-activity;sid:84769999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6ccdef"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906900/; classtype:trojan-activity;sid:84770000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/106fe5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906901/; classtype:trojan-activity;sid:84770001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f46a9e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906902/; classtype:trojan-activity;sid:84770002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7fbafd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906903/; classtype:trojan-activity;sid:84770003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/074635"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906904/; classtype:trojan-activity;sid:84770004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/449188"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906905/; classtype:trojan-activity;sid:84770005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/373541"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906906/; classtype:trojan-activity;sid:84770006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/889136"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906907/; classtype:trojan-activity;sid:84770007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c08b5a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906908/; classtype:trojan-activity;sid:84770008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e47e49"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906909/; classtype:trojan-activity;sid:84770009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/06f787"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906910/; classtype:trojan-activity;sid:84770010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50b2c0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906911/; classtype:trojan-activity;sid:84770011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0d9f5f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906912/; classtype:trojan-activity;sid:84770012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1cddd2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906913/; classtype:trojan-activity;sid:84770013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/751d98"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906914/; classtype:trojan-activity;sid:84770014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e70ebc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906915/; classtype:trojan-activity;sid:84770015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/14e7a4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906916/; classtype:trojan-activity;sid:84770016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/30494a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906917/; classtype:trojan-activity;sid:84770017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/15c864"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906918/; classtype:trojan-activity;sid:84770018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app_jncfbh.webp"; depth:16; endswith; nocase; http.host; content:"47.129.178.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906894/; classtype:trojan-activity;sid:84769994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"87.68.238.27"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906893/; classtype:trojan-activity;sid:84769993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.105.50.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906892/; classtype:trojan-activity;sid:84769992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.105.50.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906891/; classtype:trojan-activity;sid:84769991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.94.144.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906890/; classtype:trojan-activity;sid:84769990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.24.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906888/; classtype:trojan-activity;sid:84769988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.239.148.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906889/; classtype:trojan-activity;sid:84769989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"174.105.154.212"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906884/; classtype:trojan-activity;sid:84769984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.20.178"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906885/; classtype:trojan-activity;sid:84769985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.147.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906886/; classtype:trojan-activity;sid:84769986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.5.8.190"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906887/; classtype:trojan-activity;sid:84769987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.59.14.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906883/; classtype:trojan-activity;sid:84769983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.162.38.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906866/; classtype:trojan-activity;sid:84769966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.115.33.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906867/; classtype:trojan-activity;sid:84769967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.18.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906868/; classtype:trojan-activity;sid:84769968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.151.74.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906869/; classtype:trojan-activity;sid:84769969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.151.74.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906870/; classtype:trojan-activity;sid:84769970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"87.68.238.27"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906871/; classtype:trojan-activity;sid:84769971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.246.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906872/; classtype:trojan-activity;sid:84769972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.201.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906873/; classtype:trojan-activity;sid:84769973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.39.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906874/; classtype:trojan-activity;sid:84769974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.34.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906875/; classtype:trojan-activity;sid:84769975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.255.43.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906876/; classtype:trojan-activity;sid:84769976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.92.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906877/; classtype:trojan-activity;sid:84769977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.82.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906878/; classtype:trojan-activity;sid:84769978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.73.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906879/; classtype:trojan-activity;sid:84769979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.151.83.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906880/; classtype:trojan-activity;sid:84769980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.73.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906881/; classtype:trojan-activity;sid:84769981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.151.83.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906882/; classtype:trojan-activity;sid:84769982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.79.85.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906847/; classtype:trojan-activity;sid:84769947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.221.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906848/; classtype:trojan-activity;sid:84769948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.35.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906849/; classtype:trojan-activity;sid:84769949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.194.25.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906850/; classtype:trojan-activity;sid:84769950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.105.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906851/; classtype:trojan-activity;sid:84769951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.7.217.91"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906852/; classtype:trojan-activity;sid:84769952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"203.101.187.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906853/; classtype:trojan-activity;sid:84769953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.202.245.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906854/; classtype:trojan-activity;sid:84769954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.79.131"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906855/; classtype:trojan-activity;sid:84769955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.108.82.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906856/; classtype:trojan-activity;sid:84769956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.108.82.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906857/; classtype:trojan-activity;sid:84769957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.107.210.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906858/; classtype:trojan-activity;sid:84769958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.245.39.127"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906859/; classtype:trojan-activity;sid:84769959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.5.254.164"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906860/; classtype:trojan-activity;sid:84769960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.163.131.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906861/; classtype:trojan-activity;sid:84769961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.64.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906862/; classtype:trojan-activity;sid:84769962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"193.163.187.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906863/; classtype:trojan-activity;sid:84769963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.221.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906864/; classtype:trojan-activity;sid:84769964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"193.163.187.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906865/; classtype:trojan-activity;sid:84769965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.177.182.116"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906846/; classtype:trojan-activity;sid:84769946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.101.187.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906845/; classtype:trojan-activity;sid:84769945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.189.106"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906844/; classtype:trojan-activity;sid:84769944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.116.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906843/; classtype:trojan-activity;sid:84769943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/amd64"; depth:8; endswith; nocase; http.host; content:"194.59.30.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906839/; classtype:trojan-activity;sid:84769939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/kswpad"; depth:9; endswith; nocase; http.host; content:"194.59.30.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906840/; classtype:trojan-activity;sid:84769940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/linux"; depth:8; endswith; nocase; http.host; content:"194.59.30.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906841/; classtype:trojan-activity;sid:84769941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/kal64"; depth:8; endswith; nocase; http.host; content:"194.59.30.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906842/; classtype:trojan-activity;sid:84769942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e41ded"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906837/; classtype:trojan-activity;sid:84769937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d67e2e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906838/; classtype:trojan-activity;sid:84769938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f9e3f4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906826/; classtype:trojan-activity;sid:84769926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d70921"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906827/; classtype:trojan-activity;sid:84769927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bf4fde"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906828/; classtype:trojan-activity;sid:84769928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/520230"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906829/; classtype:trojan-activity;sid:84769929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dd08c4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906830/; classtype:trojan-activity;sid:84769930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a10960"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906831/; classtype:trojan-activity;sid:84769931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/21eb07"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906832/; classtype:trojan-activity;sid:84769932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f17409"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906833/; classtype:trojan-activity;sid:84769933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/662744"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906834/; classtype:trojan-activity;sid:84769934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/72ab73"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906835/; classtype:trojan-activity;sid:84769935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b67bf0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906836/; classtype:trojan-activity;sid:84769936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4f3e29"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906822/; classtype:trojan-activity;sid:84769922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f76130"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906823/; classtype:trojan-activity;sid:84769923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b02922"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906824/; classtype:trojan-activity;sid:84769924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b4fcda"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906825/; classtype:trojan-activity;sid:84769925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/84d632"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906802/; classtype:trojan-activity;sid:84769902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2be985"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906803/; classtype:trojan-activity;sid:84769903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0ab716"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906804/; classtype:trojan-activity;sid:84769904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6c8dfb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906805/; classtype:trojan-activity;sid:84769905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/25a617"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906806/; classtype:trojan-activity;sid:84769906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a1a0da"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906807/; classtype:trojan-activity;sid:84769907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b8efbc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906808/; classtype:trojan-activity;sid:84769908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9cd6a1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906809/; classtype:trojan-activity;sid:84769909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/135481"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906810/; classtype:trojan-activity;sid:84769910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5bf116"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906811/; classtype:trojan-activity;sid:84769911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/21dbf2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906812/; classtype:trojan-activity;sid:84769912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ea8c29"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906813/; classtype:trojan-activity;sid:84769913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b2904e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906814/; classtype:trojan-activity;sid:84769914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7cf768"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906815/; classtype:trojan-activity;sid:84769915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/41308f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906816/; classtype:trojan-activity;sid:84769916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/57965a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906817/; classtype:trojan-activity;sid:84769917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/592521"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906818/; classtype:trojan-activity;sid:84769918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/564fd4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906819/; classtype:trojan-activity;sid:84769919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6da58f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906820/; classtype:trojan-activity;sid:84769920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/07809e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906821/; classtype:trojan-activity;sid:84769921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c5d83d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906787/; classtype:trojan-activity;sid:84769887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2509eb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906788/; classtype:trojan-activity;sid:84769888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5d1d11"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906789/; classtype:trojan-activity;sid:84769889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9ab2df"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906790/; classtype:trojan-activity;sid:84769890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/233bc5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906791/; classtype:trojan-activity;sid:84769891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ceeba2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906792/; classtype:trojan-activity;sid:84769892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bd742d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906793/; classtype:trojan-activity;sid:84769893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/766551"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906794/; classtype:trojan-activity;sid:84769894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a84a56"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906795/; classtype:trojan-activity;sid:84769895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/06d0d9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906796/; classtype:trojan-activity;sid:84769896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e8090c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906797/; classtype:trojan-activity;sid:84769897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/810904"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906798/; classtype:trojan-activity;sid:84769898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/140cef"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906799/; classtype:trojan-activity;sid:84769899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/67dfb1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906800/; classtype:trojan-activity;sid:84769900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20c791"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906801/; classtype:trojan-activity;sid:84769901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f3158a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906766/; classtype:trojan-activity;sid:84769866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/805ade"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906767/; classtype:trojan-activity;sid:84769867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7252a4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906768/; classtype:trojan-activity;sid:84769868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b69b69"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906769/; classtype:trojan-activity;sid:84769869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abcfc3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906770/; classtype:trojan-activity;sid:84769870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3d5609"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906771/; classtype:trojan-activity;sid:84769871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/75fa66"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906772/; classtype:trojan-activity;sid:84769872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/69e5eb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906773/; classtype:trojan-activity;sid:84769873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f653ed"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906774/; classtype:trojan-activity;sid:84769874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/40ab6b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906775/; classtype:trojan-activity;sid:84769875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9bf687"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906776/; classtype:trojan-activity;sid:84769876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1f4418"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906777/; classtype:trojan-activity;sid:84769877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/79d8a6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906778/; classtype:trojan-activity;sid:84769878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45d4ef"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906779/; classtype:trojan-activity;sid:84769879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da703f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906780/; classtype:trojan-activity;sid:84769880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1416b6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906781/; classtype:trojan-activity;sid:84769881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c4878f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906782/; classtype:trojan-activity;sid:84769882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.157.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906783/; classtype:trojan-activity;sid:84769883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9f0d8c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906784/; classtype:trojan-activity;sid:84769884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/374166"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906785/; classtype:trojan-activity;sid:84769885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20fbae"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906786/; classtype:trojan-activity;sid:84769886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.183.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906765/; classtype:trojan-activity;sid:84769865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_21aeb275da3bb00b.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906764/; classtype:trojan-activity;sid:84769864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlcc.zip"; depth:9; endswith; nocase; http.host; content:"kee126.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906763/; classtype:trojan-activity;sid:84769863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/installer_91473f.msi"; depth:21; endswith; nocase; http.host; content:"practisingcertificateprotection.com"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906762/; classtype:trojan-activity;sid:84769862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.53.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906761/; classtype:trojan-activity;sid:84769861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.147.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906760/; classtype:trojan-activity;sid:84769860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.173.75.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906759/; classtype:trojan-activity;sid:84769859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/cl1787387436870.exe"; depth:28; endswith; nocase; http.host; content:"threedrows.net"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906758/; classtype:trojan-activity;sid:84769858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.127.53.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906757/; classtype:trojan-activity;sid:84769857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_91273358c1525030.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906756/; classtype:trojan-activity;sid:84769856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4ce19bfafe018ff9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906755/; classtype:trojan-activity;sid:84769855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a34690cc683b0c1a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906754/; classtype:trojan-activity;sid:84769854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.163.131.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906753/; classtype:trojan-activity;sid:84769853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.84.125"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906752/; classtype:trojan-activity;sid:84769852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.87.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906751/; classtype:trojan-activity;sid:84769851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.105.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906750/; classtype:trojan-activity;sid:84769850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.202.245.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906749/; classtype:trojan-activity;sid:84769849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.145.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906748/; classtype:trojan-activity;sid:84769848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.45.140"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906747/; classtype:trojan-activity;sid:84769847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.87.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906746/; classtype:trojan-activity;sid:84769846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.75.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906745/; classtype:trojan-activity;sid:84769845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.130.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906744/; classtype:trojan-activity;sid:84769844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.199.106"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906743/; classtype:trojan-activity;sid:84769843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.45.140"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906742/; classtype:trojan-activity;sid:84769842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.146.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906741/; classtype:trojan-activity;sid:84769841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.75.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906740/; classtype:trojan-activity;sid:84769840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.199.106"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906739/; classtype:trojan-activity;sid:84769839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlc3.zip"; depth:9; endswith; nocase; http.host; content:"gaiadeqi.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906738/; classtype:trojan-activity;sid:84769838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z7/webhook"; depth:11; endswith; nocase; http.host; content:"pawsockenjoyer.site"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906736/; classtype:trojan-activity;sid:84769836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atomic/main_x86_64"; depth:19; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906737/; classtype:trojan-activity;sid:84769837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906721/; classtype:trojan-activity;sid:84769821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9c9b83"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906722/; classtype:trojan-activity;sid:84769822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http"; depth:5; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906723/; classtype:trojan-activity;sid:84769823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9922af"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906724/; classtype:trojan-activity;sid:84769824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da8d2e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906725/; classtype:trojan-activity;sid:84769825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f6f76d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906726/; classtype:trojan-activity;sid:84769826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5adf18"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906727/; classtype:trojan-activity;sid:84769827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7c899f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906728/; classtype:trojan-activity;sid:84769828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/334215"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906729/; classtype:trojan-activity;sid:84769829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d95abb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906730/; classtype:trojan-activity;sid:84769830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2c07b9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906731/; classtype:trojan-activity;sid:84769831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2b85c0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906732/; classtype:trojan-activity;sid:84769832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_43c5f47d5fbe115a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906733/; classtype:trojan-activity;sid:84769833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d9d6f9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906734/; classtype:trojan-activity;sid:84769834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/67eefd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906735/; classtype:trojan-activity;sid:84769835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zxc9vbnm7lkjh3gf"; depth:17; endswith; nocase; http.host; content:"cloudenterprise26.com"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906720/; classtype:trojan-activity;sid:84769820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg11"; depth:5; endswith; nocase; http.host; content:"150.241.65.80"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906719/; classtype:trojan-activity;sid:84769819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/installer/application%20files/drastok_1_0_0_223/drastok.dll.deploy"; depth:67; endswith; nocase; http.host; content:"drastok.xyz"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906717/; classtype:trojan-activity;sid:84769817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/unix49211821"; depth:15; endswith; nocase; http.host; content:"86.54.25.213"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906718/; classtype:trojan-activity;sid:84769818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api_refresh.scpt"; depth:17; endswith; nocase; http.host; content:"auth2api.site"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906715/; classtype:trojan-activity;sid:84769815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/installer/drastok.application"; depth:30; endswith; nocase; http.host; content:"drastok.xyz"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906716/; classtype:trojan-activity;sid:84769816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/get_verify|3f|i=66695"; depth:22; endswith; nocase; http.host; content:"soft-update.dev"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906714/; classtype:trojan-activity;sid:84769814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.25.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906713/; classtype:trojan-activity;sid:84769813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notify.ps1"; depth:11; endswith; nocase; http.host; content:"faceit-anti-cheat.com"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906712/; classtype:trojan-activity;sid:84769812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.bash_history"; depth:14; endswith; nocase; http.host; content:"150.241.65.80"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906711/; classtype:trojan-activity;sid:84769811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.188.77.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906710/; classtype:trojan-activity;sid:84769810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.25.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906709/; classtype:trojan-activity;sid:84769809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.36.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906708/; classtype:trojan-activity;sid:84769808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.96.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906707/; classtype:trojan-activity;sid:84769807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.96.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906706/; classtype:trojan-activity;sid:84769806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.163.128.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906705/; classtype:trojan-activity;sid:84769805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.177.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906704/; classtype:trojan-activity;sid:84769804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.235.239.18"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906703/; classtype:trojan-activity;sid:84769803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.145.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906702/; classtype:trojan-activity;sid:84769802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.89.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906701/; classtype:trojan-activity;sid:84769801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.89.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906700/; classtype:trojan-activity;sid:84769800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.172.221.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906699/; classtype:trojan-activity;sid:84769799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.190.223"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906698/; classtype:trojan-activity;sid:84769798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.189.148.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906697/; classtype:trojan-activity;sid:84769797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.172.221.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906696/; classtype:trojan-activity;sid:84769796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.189.148.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906695/; classtype:trojan-activity;sid:84769795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.93.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906694/; classtype:trojan-activity;sid:84769794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.205.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906693/; classtype:trojan-activity;sid:84769793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.213.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906692/; classtype:trojan-activity;sid:84769792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.205.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906691/; classtype:trojan-activity;sid:84769791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.199.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906690/; classtype:trojan-activity;sid:84769790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906689/; classtype:trojan-activity;sid:84769789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.mipsel"; depth:9; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906688/; classtype:trojan-activity;sid:84769788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.armv5l"; depth:9; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906687/; classtype:trojan-activity;sid:84769787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lilin.sh"; depth:9; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906677/; classtype:trojan-activity;sid:84769777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.mips"; depth:7; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906678/; classtype:trojan-activity;sid:84769778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.i686"; depth:7; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906679/; classtype:trojan-activity;sid:84769779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.x86_64"; depth:9; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906680/; classtype:trojan-activity;sid:84769780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.armv4l"; depth:9; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906681/; classtype:trojan-activity;sid:84769781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.armv7l"; depth:9; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906682/; classtype:trojan-activity;sid:84769782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.armv6l"; depth:9; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906683/; classtype:trojan-activity;sid:84769783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.i486"; depth:7; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906684/; classtype:trojan-activity;sid:84769784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.powerpc"; depth:10; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906685/; classtype:trojan-activity;sid:84769785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m.i586"; depth:7; endswith; nocase; http.host; content:"222.223.152.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906686/; classtype:trojan-activity;sid:84769786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.136.52.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906676/; classtype:trojan-activity;sid:84769776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.4.17.29"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906675/; classtype:trojan-activity;sid:84769775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.210.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906674/; classtype:trojan-activity;sid:84769774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.210.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906673/; classtype:trojan-activity;sid:84769773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.94.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906672/; classtype:trojan-activity;sid:84769772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.128.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906670/; classtype:trojan-activity;sid:84769770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.7.223.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906671/; classtype:trojan-activity;sid:84769771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.7.223.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906669/; classtype:trojan-activity;sid:84769769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.128.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906668/; classtype:trojan-activity;sid:84769768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.108.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906667/; classtype:trojan-activity;sid:84769767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.20.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906666/; classtype:trojan-activity;sid:84769766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.227.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906665/; classtype:trojan-activity;sid:84769765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.15.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906664/; classtype:trojan-activity;sid:84769764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.138.108.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906663/; classtype:trojan-activity;sid:84769763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.132.158.53"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906662/; classtype:trojan-activity;sid:84769762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.228.132.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906661/; classtype:trojan-activity;sid:84769761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.20.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906660/; classtype:trojan-activity;sid:84769760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.132.158.53"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906659/; classtype:trojan-activity;sid:84769759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.183.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906658/; classtype:trojan-activity;sid:84769758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.214.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906657/; classtype:trojan-activity;sid:84769757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.231.127.198"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906656/; classtype:trojan-activity;sid:84769756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"179.108.90.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906655/; classtype:trojan-activity;sid:84769755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.163.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906654/; classtype:trojan-activity;sid:84769754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/6680549914/enkpzg6.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906653/; classtype:trojan-activity;sid:84769753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.30.116"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906652/; classtype:trojan-activity;sid:84769752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"179.108.90.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906651/; classtype:trojan-activity;sid:84769751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.30.116"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906650/; classtype:trojan-activity;sid:84769750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.158.197.238"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906649/; classtype:trojan-activity;sid:84769749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7154708060/echfkbj.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906648/; classtype:trojan-activity;sid:84769748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.60.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906647/; classtype:trojan-activity;sid:84769747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.158.197.238"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906646/; classtype:trojan-activity;sid:84769746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/installer.exe"; depth:14; endswith; nocase; http.host; content:"mon-blanc-04.cfd"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906645/; classtype:trojan-activity;sid:84769745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.150.177.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906643/; classtype:trojan-activity;sid:84769743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.162.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906644/; classtype:trojan-activity;sid:84769744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"85.15.117.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906642/; classtype:trojan-activity;sid:84769742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.117.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906641/; classtype:trojan-activity;sid:84769741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.117.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906640/; classtype:trojan-activity;sid:84769740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"85.15.117.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906639/; classtype:trojan-activity;sid:84769739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/cl1786993325591.exe"; depth:28; endswith; nocase; http.host; content:"threedrows.net"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906638/; classtype:trojan-activity;sid:84769738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.177.103.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906637/; classtype:trojan-activity;sid:84769737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.177.103.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906636/; classtype:trojan-activity;sid:84769736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.192.234.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906635/; classtype:trojan-activity;sid:84769735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.192.234.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906634/; classtype:trojan-activity;sid:84769734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.51.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906632/; classtype:trojan-activity;sid:84769732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.51.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906633/; classtype:trojan-activity;sid:84769733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.147.243.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906631/; classtype:trojan-activity;sid:84769731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.173.60.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906630/; classtype:trojan-activity;sid:84769730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.208.16.203"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906629/; classtype:trojan-activity;sid:84769729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.208.16.203"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906628/; classtype:trojan-activity;sid:84769728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.166.85"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906627/; classtype:trojan-activity;sid:84769727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.166.85"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906626/; classtype:trojan-activity;sid:84769726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_47648acbd9943ebf.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906625/; classtype:trojan-activity;sid:84769725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.25.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906624/; classtype:trojan-activity;sid:84769724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.64.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906623/; classtype:trojan-activity;sid:84769723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.112.59.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906622/; classtype:trojan-activity;sid:84769722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.64.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906621/; classtype:trojan-activity;sid:84769721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f8yluizdceoz"; depth:13; endswith; nocase; http.host; content:"68.168.20.218"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906620/; classtype:trojan-activity;sid:84769720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.251.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906619/; classtype:trojan-activity;sid:84769719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.112.59.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906618/; classtype:trojan-activity;sid:84769718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.251.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906617/; classtype:trojan-activity;sid:84769717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.26.82.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906616/; classtype:trojan-activity;sid:84769716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"31.4.254.241"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906615/; classtype:trojan-activity;sid:84769715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.194.179.106"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906614/; classtype:trojan-activity;sid:84769714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.158.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906613/; classtype:trojan-activity;sid:84769713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.201.178.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906612/; classtype:trojan-activity;sid:84769712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.59.235.202"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906611/; classtype:trojan-activity;sid:84769711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.194.179.106"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906610/; classtype:trojan-activity;sid:84769710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.61.46.143"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906609/; classtype:trojan-activity;sid:84769709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.158.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906608/; classtype:trojan-activity;sid:84769708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906607/; classtype:trojan-activity;sid:84769707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906606/; classtype:trojan-activity;sid:84769706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.87.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906605/; classtype:trojan-activity;sid:84769705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.237.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906604/; classtype:trojan-activity;sid:84769704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.244.196"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906603/; classtype:trojan-activity;sid:84769703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.180.144.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906602/; classtype:trojan-activity;sid:84769702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"113.228.208.46"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906601/; classtype:trojan-activity;sid:84769701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.244.196"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906600/; classtype:trojan-activity;sid:84769700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spamget.exe"; depth:12; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906599/; classtype:trojan-activity;sid:84769699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.20.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906598/; classtype:trojan-activity;sid:84769698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.94.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906597/; classtype:trojan-activity;sid:84769697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.189.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906596/; classtype:trojan-activity;sid:84769696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.55.26.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906595/; classtype:trojan-activity;sid:84769695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.205"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906593/; classtype:trojan-activity;sid:84769693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.205"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906594/; classtype:trojan-activity;sid:84769694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.68"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906592/; classtype:trojan-activity;sid:84769692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.68"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906591/; classtype:trojan-activity;sid:84769691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906590/; classtype:trojan-activity;sid:84769690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906589/; classtype:trojan-activity;sid:84769689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_9a5c49da1d9d1767.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906588/; classtype:trojan-activity;sid:84769688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0eede3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906583/; classtype:trojan-activity;sid:84769683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2cd0c9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906584/; classtype:trojan-activity;sid:84769684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70504f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906585/; classtype:trojan-activity;sid:84769685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/197001"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906586/; classtype:trojan-activity;sid:84769686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vcapcha.ps1"; depth:12; endswith; nocase; http.host; content:"v-k.com.ua"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906587/; classtype:trojan-activity;sid:84769687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/829f73"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906575/; classtype:trojan-activity;sid:84769675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/98fab6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906576/; classtype:trojan-activity;sid:84769676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/005679"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906577/; classtype:trojan-activity;sid:84769677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/61e952"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906578/; classtype:trojan-activity;sid:84769678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c02601"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906579/; classtype:trojan-activity;sid:84769679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/14f97a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906580/; classtype:trojan-activity;sid:84769680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d81575"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906581/; classtype:trojan-activity;sid:84769681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e0207d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906582/; classtype:trojan-activity;sid:84769682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"192.159.99.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906574/; classtype:trojan-activity;sid:84769674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_1319bd61568f04ed.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906572/; classtype:trojan-activity;sid:84769672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"192.159.99.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906573/; classtype:trojan-activity;sid:84769673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"203.159.90.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906571/; classtype:trojan-activity;sid:84769671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"203.159.90.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906570/; classtype:trojan-activity;sid:84769670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"39.61.53.157"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906569/; classtype:trojan-activity;sid:84769669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv5l"; depth:7; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906568/; classtype:trojan-activity;sid:84769668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc64"; depth:6; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906560/; classtype:trojan-activity;sid:84769660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906561/; classtype:trojan-activity;sid:84769661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amd64"; depth:6; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906562/; classtype:trojan-activity;sid:84769662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906563/; classtype:trojan-activity;sid:84769663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906564/; classtype:trojan-activity;sid:84769664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906565/; classtype:trojan-activity;sid:84769665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv6l"; depth:7; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906566/; classtype:trojan-activity;sid:84769666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906567/; classtype:trojan-activity;sid:84769667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906559/; classtype:trojan-activity;sid:84769659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906558/; classtype:trojan-activity;sid:84769658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.70.235.87"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906557/; classtype:trojan-activity;sid:84769657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906556/; classtype:trojan-activity;sid:84769656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906547/; classtype:trojan-activity;sid:84769647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906548/; classtype:trojan-activity;sid:84769648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906549/; classtype:trojan-activity;sid:84769649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906550/; classtype:trojan-activity;sid:84769650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906551/; classtype:trojan-activity;sid:84769651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906552/; classtype:trojan-activity;sid:84769652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906553/; classtype:trojan-activity;sid:84769653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906554/; classtype:trojan-activity;sid:84769654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adbpersist.arm7"; depth:16; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906555/; classtype:trojan-activity;sid:84769655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906538/; classtype:trojan-activity;sid:84769638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906539/; classtype:trojan-activity;sid:84769639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906540/; classtype:trojan-activity;sid:84769640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i686"; depth:9; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906541/; classtype:trojan-activity;sid:84769641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.aarch64"; depth:12; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906542/; classtype:trojan-activity;sid:84769642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc"; depth:8; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906543/; classtype:trojan-activity;sid:84769643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mipsel"; depth:11; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906544/; classtype:trojan-activity;sid:84769644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906545/; classtype:trojan-activity;sid:84769645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.sh4"; depth:8; endswith; nocase; http.host; content:"94.154.43.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906546/; classtype:trojan-activity;sid:84769646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.79.131"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906537/; classtype:trojan-activity;sid:84769637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.132.182.114"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906536/; classtype:trojan-activity;sid:84769636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"nimblenumbers.screenconnect.com"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906535/; classtype:trojan-activity;sid:84769635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.140.10"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906534/; classtype:trojan-activity;sid:84769634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.59.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906533/; classtype:trojan-activity;sid:84769633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.132.182.114"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906532/; classtype:trojan-activity;sid:84769632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.49.187"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906531/; classtype:trojan-activity;sid:84769631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.234.219.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906530/; classtype:trojan-activity;sid:84769630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.59.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906529/; classtype:trojan-activity;sid:84769629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.powerpc"; depth:18; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906528/; classtype:trojan-activity;sid:84769628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv5l"; depth:17; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906527/; classtype:trojan-activity;sid:84769627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.mips"; depth:15; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906526/; classtype:trojan-activity;sid:84769626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv7l"; depth:17; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906525/; classtype:trojan-activity;sid:84769625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.x86_64"; depth:17; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906514/; classtype:trojan-activity;sid:84769614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv6l"; depth:17; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906515/; classtype:trojan-activity;sid:84769615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.mipsrouter"; depth:21; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906516/; classtype:trojan-activity;sid:84769616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.sh4"; depth:14; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906517/; classtype:trojan-activity;sid:84769617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906518/; classtype:trojan-activity;sid:84769618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.arc"; depth:14; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906519/; classtype:trojan-activity;sid:84769619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.i486"; depth:15; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906520/; classtype:trojan-activity;sid:84769620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv4l"; depth:17; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906521/; classtype:trojan-activity;sid:84769621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.mipsel"; depth:17; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906522/; classtype:trojan-activity;sid:84769622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.sparc"; depth:16; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906523/; classtype:trojan-activity;sid:84769623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.m68k"; depth:15; endswith; nocase; http.host; content:"176.65.139.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906524/; classtype:trojan-activity;sid:84769624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.49.187"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906513/; classtype:trojan-activity;sid:84769613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.224.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906512/; classtype:trojan-activity;sid:84769612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.10.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906511/; classtype:trojan-activity;sid:84769611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.244.41.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906510/; classtype:trojan-activity;sid:84769610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.136.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906509/; classtype:trojan-activity;sid:84769609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.21.251.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906508/; classtype:trojan-activity;sid:84769608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.38.16.176"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906507/; classtype:trojan-activity;sid:84769607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.159.187.179"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906505/; classtype:trojan-activity;sid:84769605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.159.187.179"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906506/; classtype:trojan-activity;sid:84769606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.45.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906499/; classtype:trojan-activity;sid:84769599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.148.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906500/; classtype:trojan-activity;sid:84769600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.171.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906501/; classtype:trojan-activity;sid:84769601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.140.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906502/; classtype:trojan-activity;sid:84769602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"211.75.38.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906503/; classtype:trojan-activity;sid:84769603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.140.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906504/; classtype:trojan-activity;sid:84769604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.87.111.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906480/; classtype:trojan-activity;sid:84769580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.130.28"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906481/; classtype:trojan-activity;sid:84769581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.5.26.85"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906482/; classtype:trojan-activity;sid:84769582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.234.61.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906483/; classtype:trojan-activity;sid:84769583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.49.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906484/; classtype:trojan-activity;sid:84769584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.85.28.108"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906485/; classtype:trojan-activity;sid:84769585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"91.234.61.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906486/; classtype:trojan-activity;sid:84769586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.127.49.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906487/; classtype:trojan-activity;sid:84769587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.130.209.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906488/; classtype:trojan-activity;sid:84769588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.15.53"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906489/; classtype:trojan-activity;sid:84769589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.52.206.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906490/; classtype:trojan-activity;sid:84769590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.163.85.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906491/; classtype:trojan-activity;sid:84769591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.188.75.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906492/; classtype:trojan-activity;sid:84769592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.52.206.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906493/; classtype:trojan-activity;sid:84769593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.54.15.53"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906494/; classtype:trojan-activity;sid:84769594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.85.28.108"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906495/; classtype:trojan-activity;sid:84769595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.184.140.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906496/; classtype:trojan-activity;sid:84769596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.171.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906497/; classtype:trojan-activity;sid:84769597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.179.4.180"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906498/; classtype:trojan-activity;sid:84769598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.94.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906477/; classtype:trojan-activity;sid:84769577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"91.157.243.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906478/; classtype:trojan-activity;sid:84769578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.94.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906479/; classtype:trojan-activity;sid:84769579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.240.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906476/; classtype:trojan-activity;sid:84769576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.63.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906475/; classtype:trojan-activity;sid:84769575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.10.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906474/; classtype:trojan-activity;sid:84769574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.240.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906473/; classtype:trojan-activity;sid:84769573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlccz.zip"; depth:10; endswith; nocase; http.host; content:"colibrik.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906472/; classtype:trojan-activity;sid:84769572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xloadfile/bin.exe"; depth:18; endswith; nocase; http.host; content:"195.177.94.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906471/; classtype:trojan-activity;sid:84769571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wxw6reloyfke/msi_pro.png"; depth:25; endswith; nocase; http.host; content:"tmpfiles.org"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906470/; classtype:trojan-activity;sid:84769570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.87.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906469/; classtype:trojan-activity;sid:84769569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.36.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906468/; classtype:trojan-activity;sid:84769568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/699b25"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906456/; classtype:trojan-activity;sid:84769556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/89e244"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906457/; classtype:trojan-activity;sid:84769557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e3530c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906458/; classtype:trojan-activity;sid:84769558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3eaa22"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906459/; classtype:trojan-activity;sid:84769559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7d4dfe"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906460/; classtype:trojan-activity;sid:84769560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efeb39"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906461/; classtype:trojan-activity;sid:84769561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4c7cb5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906462/; classtype:trojan-activity;sid:84769562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bfe63f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906463/; classtype:trojan-activity;sid:84769563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/acaa53"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906464/; classtype:trojan-activity;sid:84769564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/905a41"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906465/; classtype:trojan-activity;sid:84769565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/58e1a8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906466/; classtype:trojan-activity;sid:84769566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/74346a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906467/; classtype:trojan-activity;sid:84769567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zz/crypted.ps1"; depth:15; endswith; nocase; http.host; content:"onlypackaging.grupoinde.com"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906455/; classtype:trojan-activity;sid:84769555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypted.ps1"; depth:12; endswith; nocase; http.host; content:"pulgarinrealtor.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906454/; classtype:trojan-activity;sid:84769554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.36.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906453/; classtype:trojan-activity;sid:84769553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.92.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906452/; classtype:trojan-activity;sid:84769552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.118.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906451/; classtype:trojan-activity;sid:84769551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"130.12.209.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906450/; classtype:trojan-activity;sid:84769550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlc.zip"; depth:8; endswith; nocase; http.host; content:"kee126.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906449/; classtype:trojan-activity;sid:84769549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/1787161037.c81e7dba2550050a/wxw6reloyfke/msi_pro.png"; depth:56; endswith; nocase; http.host; content:"tmpfiles.org"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906448/; classtype:trojan-activity;sid:84769548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.152.10.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906447/; classtype:trojan-activity;sid:84769547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b87566"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906444/; classtype:trojan-activity;sid:84769544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e7b8f7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906445/; classtype:trojan-activity;sid:84769545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b8b233"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906446/; classtype:trojan-activity;sid:84769546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/24dc12"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906411/; classtype:trojan-activity;sid:84769511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b7a381"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906412/; classtype:trojan-activity;sid:84769512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adb88f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906413/; classtype:trojan-activity;sid:84769513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/29ea88"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906414/; classtype:trojan-activity;sid:84769514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b6973a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906415/; classtype:trojan-activity;sid:84769515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/85a4f4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906416/; classtype:trojan-activity;sid:84769516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ba641b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906417/; classtype:trojan-activity;sid:84769517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/846cac"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906418/; classtype:trojan-activity;sid:84769518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50edcc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906419/; classtype:trojan-activity;sid:84769519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5a848f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906420/; classtype:trojan-activity;sid:84769520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ae9a6b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906421/; classtype:trojan-activity;sid:84769521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d19a37"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906422/; classtype:trojan-activity;sid:84769522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d97308"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906423/; classtype:trojan-activity;sid:84769523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6ef423"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906424/; classtype:trojan-activity;sid:84769524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7202b4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906425/; classtype:trojan-activity;sid:84769525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/90e1de"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906426/; classtype:trojan-activity;sid:84769526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b4af73"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906427/; classtype:trojan-activity;sid:84769527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/08040b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906428/; classtype:trojan-activity;sid:84769528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8a90f5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906429/; classtype:trojan-activity;sid:84769529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/79743e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906430/; classtype:trojan-activity;sid:84769530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/74d9f9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906431/; classtype:trojan-activity;sid:84769531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c060bd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906432/; classtype:trojan-activity;sid:84769532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aede8d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906433/; classtype:trojan-activity;sid:84769533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/370ef8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906434/; classtype:trojan-activity;sid:84769534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1294b8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906435/; classtype:trojan-activity;sid:84769535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f82d25"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906436/; classtype:trojan-activity;sid:84769536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/797dff"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906437/; classtype:trojan-activity;sid:84769537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e04f45"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906438/; classtype:trojan-activity;sid:84769538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/597d4b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906439/; classtype:trojan-activity;sid:84769539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a0ec06"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906440/; classtype:trojan-activity;sid:84769540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/14acdf"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906441/; classtype:trojan-activity;sid:84769541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d834af"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906442/; classtype:trojan-activity;sid:84769542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/982cd0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906443/; classtype:trojan-activity;sid:84769543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.4.133"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906410/; classtype:trojan-activity;sid:84769510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.189.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906409/; classtype:trojan-activity;sid:84769509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.152.10.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906408/; classtype:trojan-activity;sid:84769508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906395/; classtype:trojan-activity;sid:84769495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906396/; classtype:trojan-activity;sid:84769496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906397/; classtype:trojan-activity;sid:84769497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906398/; classtype:trojan-activity;sid:84769498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906399/; classtype:trojan-activity;sid:84769499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_32"; depth:7; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906400/; classtype:trojan-activity;sid:84769500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc440"; depth:7; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906401/; classtype:trojan-activity;sid:84769501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906402/; classtype:trojan-activity;sid:84769502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906403/; classtype:trojan-activity;sid:84769503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906404/; classtype:trojan-activity;sid:84769504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906405/; classtype:trojan-activity;sid:84769505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906406/; classtype:trojan-activity;sid:84769506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"91.192.81.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906407/; classtype:trojan-activity;sid:84769507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"159.255.31.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906394/; classtype:trojan-activity;sid:84769494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"202.163.107.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906393/; classtype:trojan-activity;sid:84769493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.233.94.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906392/; classtype:trojan-activity;sid:84769492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.233.94.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906391/; classtype:trojan-activity;sid:84769491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.78.182.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906390/; classtype:trojan-activity;sid:84769490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.81.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906389/; classtype:trojan-activity;sid:84769489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlc.zip"; depth:8; endswith; nocase; http.host; content:"colibrik.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906388/; classtype:trojan-activity;sid:84769488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/modules/nzx44svmy.bin"; depth:29; endswith; nocase; http.host; content:"krem.mesoptik.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906387/; classtype:trojan-activity;sid:84769487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/modules/rh_tmgdpq.bin"; depth:29; endswith; nocase; http.host; content:"krem.mesoptik.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906386/; classtype:trojan-activity;sid:84769486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.44.156.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906385/; classtype:trojan-activity;sid:84769485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.188.75.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906384/; classtype:trojan-activity;sid:84769484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906383/; classtype:trojan-activity;sid:84769483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"112.123.98.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906382/; classtype:trojan-activity;sid:84769482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lin1948wex"; depth:11; endswith; nocase; http.host; content:"86.109.75.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906380/; classtype:trojan-activity;sid:84769480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_542ee73385a72661.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906381/; classtype:trojan-activity;sid:84769481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nezhahq/scripts/main/agent/install.sh"; depth:38; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906379/; classtype:trojan-activity;sid:84769479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3b3bcb0313f73fb0.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906378/; classtype:trojan-activity;sid:84769478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3dd10d441773a7d5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906377/; classtype:trojan-activity;sid:84769477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/3.jpg"; depth:16; endswith; nocase; http.host; content:"45.225.135.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906376/; classtype:trojan-activity;sid:84769476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orukemer/mercy/refs/heads/main/girhnsb.txt"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906375/; classtype:trojan-activity;sid:84769475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orukemer/image/releases/download/image/3.jpg"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906374/; classtype:trojan-activity;sid:84769474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orukemer/success/refs/heads/main/esrdgmg.txt"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906373/; classtype:trojan-activity;sid:84769473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.44.156.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906372/; classtype:trojan-activity;sid:84769472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.219.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906371/; classtype:trojan-activity;sid:84769471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"159.255.31.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906370/; classtype:trojan-activity;sid:84769470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.78.182.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906369/; classtype:trojan-activity;sid:84769469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.177.182.116"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906368/; classtype:trojan-activity;sid:84769468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adobeinstaller.msi"; depth:19; endswith; nocase; http.host; content:"brightwatch.mypi.co"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906367/; classtype:trojan-activity;sid:84769467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adobepdf.bat"; depth:13; endswith; nocase; http.host; content:"brightwatch.mypi.co"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906366/; classtype:trojan-activity;sid:84769466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/image/stego_3d5qe0layt.png"; depth:27; endswith; nocase; http.host; content:"coconutoficial.com.br"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906365/; classtype:trojan-activity;sid:84769465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/weds/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"pulgarinrealtor.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906364/; classtype:trojan-activity;sid:84769464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.151.74.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906363/; classtype:trojan-activity;sid:84769463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlc.zip"; depth:8; endswith; nocase; http.host; content:"gaiadeqi.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906362/; classtype:trojan-activity;sid:84769462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.123.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906361/; classtype:trojan-activity;sid:84769461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.151.74.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906360/; classtype:trojan-activity;sid:84769460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.123.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906359/; classtype:trojan-activity;sid:84769459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.234.219.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906358/; classtype:trojan-activity;sid:84769458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.163.117"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906357/; classtype:trojan-activity;sid:84769457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.163.117"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906356/; classtype:trojan-activity;sid:84769456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.25.157.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906355/; classtype:trojan-activity;sid:84769455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.201.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906354/; classtype:trojan-activity;sid:84769454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.20.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906353/; classtype:trojan-activity;sid:84769453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.162.38.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906352/; classtype:trojan-activity;sid:84769452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.117.108.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906351/; classtype:trojan-activity;sid:84769451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.84.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906350/; classtype:trojan-activity;sid:84769450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.97.100.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906349/; classtype:trojan-activity;sid:84769449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.3.106"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906348/; classtype:trojan-activity;sid:84769448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.84.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906347/; classtype:trojan-activity;sid:84769447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"93.113.166.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906346/; classtype:trojan-activity;sid:84769446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.162.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906345/; classtype:trojan-activity;sid:84769445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lilin.sh"; depth:9; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906344/; classtype:trojan-activity;sid:84769444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.3.106"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906343/; classtype:trojan-activity;sid:84769443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.100.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906342/; classtype:trojan-activity;sid:84769442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.100.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906341/; classtype:trojan-activity;sid:84769441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.154.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906340/; classtype:trojan-activity;sid:84769440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"93.113.166.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906339/; classtype:trojan-activity;sid:84769439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.217.161.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906338/; classtype:trojan-activity;sid:84769438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.107.210.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906337/; classtype:trojan-activity;sid:84769437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.154.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906336/; classtype:trojan-activity;sid:84769436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906323/; classtype:trojan-activity;sid:84769423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i486"; depth:5; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906324/; classtype:trojan-activity;sid:84769424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906325/; classtype:trojan-activity;sid:84769425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906326/; classtype:trojan-activity;sid:84769426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906327/; classtype:trojan-activity;sid:84769427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906328/; classtype:trojan-activity;sid:84769428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906329/; classtype:trojan-activity;sid:84769429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906330/; classtype:trojan-activity;sid:84769430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906331/; classtype:trojan-activity;sid:84769431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906332/; classtype:trojan-activity;sid:84769432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906333/; classtype:trojan-activity;sid:84769433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906334/; classtype:trojan-activity;sid:84769434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906335/; classtype:trojan-activity;sid:84769435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"124.163.212.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906322/; classtype:trojan-activity;sid:84769422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.18.27"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906321/; classtype:trojan-activity;sid:84769421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.5.254.164"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906320/; classtype:trojan-activity;sid:84769420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.103.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906319/; classtype:trojan-activity;sid:84769419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.103.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906318/; classtype:trojan-activity;sid:84769418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.197.57"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906317/; classtype:trojan-activity;sid:84769417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.174.102.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906316/; classtype:trojan-activity;sid:84769416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.213.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906315/; classtype:trojan-activity;sid:84769415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.203.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906314/; classtype:trojan-activity;sid:84769414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.114.63.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906313/; classtype:trojan-activity;sid:84769413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.223.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906312/; classtype:trojan-activity;sid:84769412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.174.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906311/; classtype:trojan-activity;sid:84769411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.120.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906310/; classtype:trojan-activity;sid:84769410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.203.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906309/; classtype:trojan-activity;sid:84769409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.151.74.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906308/; classtype:trojan-activity;sid:84769408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.114.63.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906307/; classtype:trojan-activity;sid:84769407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.52.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906306/; classtype:trojan-activity;sid:84769406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.120.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906305/; classtype:trojan-activity;sid:84769405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.162.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906304/; classtype:trojan-activity;sid:84769404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.223.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906303/; classtype:trojan-activity;sid:84769403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.52.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906301/; classtype:trojan-activity;sid:84769401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.118.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906302/; classtype:trojan-activity;sid:84769402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.162.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906300/; classtype:trojan-activity;sid:84769400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.253.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906299/; classtype:trojan-activity;sid:84769399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.43.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906298/; classtype:trojan-activity;sid:84769398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.195.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906297/; classtype:trojan-activity;sid:84769397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.190.17.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906296/; classtype:trojan-activity;sid:84769396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.177.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906295/; classtype:trojan-activity;sid:84769395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.43.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906294/; classtype:trojan-activity;sid:84769394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.253.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906293/; classtype:trojan-activity;sid:84769393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ea0fdcdde83b1f61.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906292/; classtype:trojan-activity;sid:84769392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.195.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906291/; classtype:trojan-activity;sid:84769391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906290/; classtype:trojan-activity;sid:84769390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.13.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906289/; classtype:trojan-activity;sid:84769389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.212.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906288/; classtype:trojan-activity;sid:84769388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"140.237.7.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906287/; classtype:trojan-activity;sid:84769387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.212.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906286/; classtype:trojan-activity;sid:84769386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.209.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906285/; classtype:trojan-activity;sid:84769385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.209.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906284/; classtype:trojan-activity;sid:84769384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.174.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906283/; classtype:trojan-activity;sid:84769383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.139.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906282/; classtype:trojan-activity;sid:84769382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.207.216.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906281/; classtype:trojan-activity;sid:84769381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"41.201.226.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906280/; classtype:trojan-activity;sid:84769380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.4.93"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906279/; classtype:trojan-activity;sid:84769379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.56.136.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906278/; classtype:trojan-activity;sid:84769378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.236.118.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906277/; classtype:trojan-activity;sid:84769377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"14.107.121.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906276/; classtype:trojan-activity;sid:84769376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906275/; classtype:trojan-activity;sid:84769375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.241.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906274/; classtype:trojan-activity;sid:84769374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"14.107.121.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906273/; classtype:trojan-activity;sid:84769373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.93.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906272/; classtype:trojan-activity;sid:84769372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.135.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906271/; classtype:trojan-activity;sid:84769371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906270/; classtype:trojan-activity;sid:84769370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.7.217.91"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906269/; classtype:trojan-activity;sid:84769369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.254.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906268/; classtype:trojan-activity;sid:84769368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.2.50.30"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906267/; classtype:trojan-activity;sid:84769367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.241.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906266/; classtype:trojan-activity;sid:84769366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.254.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906265/; classtype:trojan-activity;sid:84769365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.2.50.30"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906264/; classtype:trojan-activity;sid:84769364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.105.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906263/; classtype:trojan-activity;sid:84769363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clc.zip"; depth:8; endswith; nocase; http.host; content:"gaiadeqi.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906262/; classtype:trojan-activity;sid:84769362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/stego_jxdqj7fw9j.png"; depth:28; endswith; nocase; http.host; content:"kits.frog.tw"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906261/; classtype:trojan-activity;sid:84769361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvb/eecrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906259/; classtype:trojan-activity;sid:84769359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvb/ugcrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906260/; classtype:trojan-activity;sid:84769360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.89.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906258/; classtype:trojan-activity;sid:84769358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.105.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906257/; classtype:trojan-activity;sid:84769357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.130.209.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906256/; classtype:trojan-activity;sid:84769356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.89.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906255/; classtype:trojan-activity;sid:84769355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_122332.png"; depth:15; endswith; nocase; http.host; content:"www.2goelectricity.cloud"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906254/; classtype:trojan-activity;sid:84769354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pw/prcrypted.ps1"; depth:17; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906253/; classtype:trojan-activity;sid:84769353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pw/pr2crypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906252/; classtype:trojan-activity;sid:84769352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pw/ezcrypted.ps1"; depth:17; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906251/; classtype:trojan-activity;sid:84769351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin001.png"; depth:11; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906250/; classtype:trojan-activity;sid:84769350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app330.png"; depth:11; endswith; nocase; http.host; content:"pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906249/; classtype:trojan-activity;sid:84769349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.177.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906248/; classtype:trojan-activity;sid:84769348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a9eeb4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906236/; classtype:trojan-activity;sid:84769336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/63d2dd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906237/; classtype:trojan-activity;sid:84769337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1e596c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906238/; classtype:trojan-activity;sid:84769338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/59e4b9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906239/; classtype:trojan-activity;sid:84769339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/229db9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906240/; classtype:trojan-activity;sid:84769340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6711b4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906241/; classtype:trojan-activity;sid:84769341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f61d73"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906242/; classtype:trojan-activity;sid:84769342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/833d99"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906243/; classtype:trojan-activity;sid:84769343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/908e60"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906244/; classtype:trojan-activity;sid:84769344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e6a806"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906245/; classtype:trojan-activity;sid:84769345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e27047"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906246/; classtype:trojan-activity;sid:84769346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/646d52"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906247/; classtype:trojan-activity;sid:84769347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bxaigui.png"; depth:12; endswith; nocase; http.host; content:"pub-8f07b712b50246eca5982f64bd695eea.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906235/; classtype:trojan-activity;sid:84769335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vceolaqcvj.png"; depth:15; endswith; nocase; http.host; content:"pub-153d2a9e026942c4aff3b3aca8f80952.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906234/; classtype:trojan-activity;sid:84769334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/candy.png"; depth:10; endswith; nocase; http.host; content:"somostask.co"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906233/; classtype:trojan-activity;sid:84769333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hukl/cp/bin.exe"; depth:16; endswith; nocase; http.host; content:"wylkpznq.xyz"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906232/; classtype:trojan-activity;sid:84769332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.135.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906231/; classtype:trojan-activity;sid:84769331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.exe"; depth:8; endswith; nocase; http.host; content:"flooriscoveringworld.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906230/; classtype:trojan-activity;sid:84769330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.168.114.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906229/; classtype:trojan-activity;sid:84769329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.168.114.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906228/; classtype:trojan-activity;sid:84769328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newpath.sh"; depth:11; endswith; nocase; http.host; content:"45.150.195.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906227/; classtype:trojan-activity;sid:84769327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.147.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906226/; classtype:trojan-activity;sid:84769326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.248.10"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906224/; classtype:trojan-activity;sid:84769324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.44.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906225/; classtype:trojan-activity;sid:84769325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906223/; classtype:trojan-activity;sid:84769323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.5.10.102"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906222/; classtype:trojan-activity;sid:84769322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm64"; depth:12; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906221/; classtype:trojan-activity;sid:84769321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_46acc204d4e52963.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906220/; classtype:trojan-activity;sid:84769320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"85.108.86.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906219/; classtype:trojan-activity;sid:84769319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.248.10"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906218/; classtype:trojan-activity;sid:84769318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atilabyte/golang/raw/refs/heads/master/scripts/install.sh"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906217/; classtype:trojan-activity;sid:84769317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9a3160"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906215/; classtype:trojan-activity;sid:84769315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b97872"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906216/; classtype:trojan-activity;sid:84769316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f287aa"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906205/; classtype:trojan-activity;sid:84769305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/939936"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906206/; classtype:trojan-activity;sid:84769306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/026141"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906207/; classtype:trojan-activity;sid:84769307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b3eb09"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906208/; classtype:trojan-activity;sid:84769308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6a40ae"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906209/; classtype:trojan-activity;sid:84769309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9c9685"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906210/; classtype:trojan-activity;sid:84769310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fc2db6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906211/; classtype:trojan-activity;sid:84769311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3eafe3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906212/; classtype:trojan-activity;sid:84769312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c4a84f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906213/; classtype:trojan-activity;sid:84769313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ad61ec"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906214/; classtype:trojan-activity;sid:84769314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.220.84.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906204/; classtype:trojan-activity;sid:84769304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"multiculturalbridge.screenconnect.com"; depth:37; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906203/; classtype:trojan-activity;sid:84769303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/access"; depth:7; endswith; nocase; http.host; content:"azlvaka.vu"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906202/; classtype:trojan-activity;sid:84769302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reference/"; depth:11; endswith; nocase; http.host; content:"docuuumennnntonline.top"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906201/; classtype:trojan-activity;sid:84769301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/finalcd"; depth:8; endswith; nocase; http.host; content:"helnivo.vu"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906200/; classtype:trojan-activity;sid:84769300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/windows/"; depth:9; endswith; nocase; http.host; content:"robinhoodwallet.dervano.vu"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906196/; classtype:trojan-activity;sid:84769296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reference/"; depth:11; endswith; nocase; http.host; content:"docuslutmentadoonline.top"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906197/; classtype:trojan-activity;sid:84769297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"shortsouth.screenconnect.com"; depth:28; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906198/; classtype:trojan-activity;sid:84769298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.5.10.102"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906194/; classtype:trojan-activity;sid:84769294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.220.84.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906192/; classtype:trojan-activity;sid:84769292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.183.51.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906191/; classtype:trojan-activity;sid:84769291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.220.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906190/; classtype:trojan-activity;sid:84769290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_2pu3tp48pp.png"; depth:21; endswith; nocase; http.host; content:"somostask.co"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906189/; classtype:trojan-activity;sid:84769289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/text/jzoctxl/u1jifzw/jnmpdkg/ug1crypted.ps1"; depth:56; endswith; nocase; http.host; content:"art-jewels.de"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906186/; classtype:trojan-activity;sid:84769286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/softwaretech"; depth:13; endswith; nocase; http.host; content:"vibecoders.vip"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906187/; classtype:trojan-activity;sid:84769287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/3.jpg"; depth:10; endswith; nocase; http.host; content:"107.174.251.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906188/; classtype:trojan-activity;sid:84769288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"profitable-pink-0y9btnew-dpk6vqe6eheo.edgeone.dev"; depth:49; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906183/; classtype:trojan-activity;sid:84769283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"balanced-red-emhnkdfj-dp7g2kvqxx8n.edgeone.dev"; depth:46; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906184/; classtype:trojan-activity;sid:84769284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_e646a62aa048cacd.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906185/; classtype:trojan-activity;sid:84769285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fdcsdwrqass/microsoft/main/microsoft.exe"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906181/; classtype:trojan-activity;sid:84769281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlc1.zip"; depth:9; endswith; nocase; http.host; content:"gaiadeqi.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906182/; classtype:trojan-activity;sid:84769282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/weareinthebestplaceforbetterfuturecomingforme.hta"; depth:53; endswith; nocase; http.host; content:"23.94.148.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906177/; classtype:trojan-activity;sid:84769277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download.php/complete_package_inspection_and_damage_verification_mp4|3f|f=66898a522ebd09a431f48ede0d3df5e8"; depth:107; endswith; nocase; http.host; content:"fdrv.beeyuskincare.co.nz"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906178/; classtype:trojan-activity;sid:84769278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tu3929.exe"; depth:11; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906179/; classtype:trojan-activity;sid:84769279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_pro.png"; depth:12; endswith; nocase; http.host; content:"www.2goelectricity.cloud"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906180/; classtype:trojan-activity;sid:84769280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload_v10.sh"; depth:15; endswith; nocase; http.host; content:"178.132.198.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906176/; classtype:trojan-activity;sid:84769276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.84.173"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906175/; classtype:trojan-activity;sid:84769275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.93.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906174/; classtype:trojan-activity;sid:84769274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.41.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906173/; classtype:trojan-activity;sid:84769273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.84.173"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906172/; classtype:trojan-activity;sid:84769272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.178.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906171/; classtype:trojan-activity;sid:84769271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.178.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906170/; classtype:trojan-activity;sid:84769270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"85.108.86.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906169/; classtype:trojan-activity;sid:84769269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.217.123.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906168/; classtype:trojan-activity;sid:84769268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.23.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906167/; classtype:trojan-activity;sid:84769267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.206.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906166/; classtype:trojan-activity;sid:84769266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.23.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906165/; classtype:trojan-activity;sid:84769265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.51.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906164/; classtype:trojan-activity;sid:84769264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.247.247"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906163/; classtype:trojan-activity;sid:84769263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.49.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906162/; classtype:trojan-activity;sid:84769262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.51.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906161/; classtype:trojan-activity;sid:84769261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.103.241"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906160/; classtype:trojan-activity;sid:84769260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.5.87.54"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906159/; classtype:trojan-activity;sid:84769259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.159.178"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906158/; classtype:trojan-activity;sid:84769258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"211.229.127.206"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906157/; classtype:trojan-activity;sid:84769257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.117.108.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906156/; classtype:trojan-activity;sid:84769256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"121.40.213.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906155/; classtype:trojan-activity;sid:84769255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"85.137.246.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906153/; classtype:trojan-activity;sid:84769253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.215.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906154/; classtype:trojan-activity;sid:84769254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.6.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906152/; classtype:trojan-activity;sid:84769252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"79.106.231.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906151/; classtype:trojan-activity;sid:84769251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dustinsergio/connect2/releases/download/v2.0.0/screenconnectsetup.exe"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906150/; classtype:trojan-activity;sid:84769250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dustinsergio/myprogramambitious/releases/download/v1.0.0/screenconnectsetup.exe"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906149/; classtype:trojan-activity;sid:84769249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.159.178"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906148/; classtype:trojan-activity;sid:84769248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/knujwn.png"; depth:11; endswith; nocase; http.host; content:"files.catbox.moe"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906147/; classtype:trojan-activity;sid:84769247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.233.155"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906146/; classtype:trojan-activity;sid:84769246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.233.155"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906145/; classtype:trojan-activity;sid:84769245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.6.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906144/; classtype:trojan-activity;sid:84769244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.240.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906143/; classtype:trojan-activity;sid:84769243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.153.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906142/; classtype:trojan-activity;sid:84769242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e3d7348c34787506/adobeacrobat.iso"; depth:34; endswith; nocase; http.host; content:"bucketforada.s3.ap-south-1.amazonaws.com"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906141/; classtype:trojan-activity;sid:84769241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rfuc/f98f/finanzam-agreement.html"; depth:35; endswith; nocase; http.host; content:"paularavanelli.com.br"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906140/; classtype:trojan-activity;sid:84769240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.47.104.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906139/; classtype:trojan-activity;sid:84769239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.240.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906138/; classtype:trojan-activity;sid:84769238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/niceorgimg_082205.png"; depth:29; endswith; nocase; http.host; content:"sunix-technology.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906137/; classtype:trojan-activity;sid:84769237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//wp-content/bin44.exe"; depth:22; endswith; nocase; http.host; content:"nieuw.technoberg.nl"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906136/; classtype:trojan-activity;sid:84769236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20/stego_cm94aawwlf.png"; depth:24; endswith; nocase; http.host; content:"sixmexicos.com"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906135/; classtype:trojan-activity;sid:84769235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_171507.png"; depth:15; endswith; nocase; http.host; content:"pub-378362a70f714a30b26c109732cabca4.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906134/; classtype:trojan-activity;sid:84769234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shsw2tu4/image/upload/v1787199607/img_001951.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906133/; classtype:trojan-activity;sid:84769233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shsw2tu4/image/upload/v1787185571/img_202554.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906132/; classtype:trojan-activity;sid:84769232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/obi/obi-64bit-remcos_a.bin"; depth:27; endswith; nocase; http.host; content:"sivrex.click"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906131/; classtype:trojan-activity;sid:84769231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.61.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906129/; classtype:trojan-activity;sid:84769229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.47.104.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906130/; classtype:trojan-activity;sid:84769230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c8tdweya/image/upload/v1787186570/img_204142.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906128/; classtype:trojan-activity;sid:84769228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shsw2tu4/image/upload/v1787096999/img_194944.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906127/; classtype:trojan-activity;sid:84769227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"23.95.103.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906126/; classtype:trojan-activity;sid:84769226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rumpyu18.png"; depth:13; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906125/; classtype:trojan-activity;sid:84769225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_gas.png"; depth:12; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906124/; classtype:trojan-activity;sid:84769224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rumpyu13th.png"; depth:15; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906123/; classtype:trojan-activity;sid:84769223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rumpyu14th.png"; depth:15; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906122/; classtype:trojan-activity;sid:84769222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.232.226.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906121/; classtype:trojan-activity;sid:84769221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shsw2tu4/image/upload/v1787199350/img_001530.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906120/; classtype:trojan-activity;sid:84769220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.253.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906119/; classtype:trojan-activity;sid:84769219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.184.140.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906118/; classtype:trojan-activity;sid:84769218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.95.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906117/; classtype:trojan-activity;sid:84769217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.236.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906116/; classtype:trojan-activity;sid:84769216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/v1/ps1/bf57fba60c91af3c5b2a12a00824e554/payload|3f|gk=8548a53bccb76780011e980c89530d41dc9762640a4cc2664b532a045e8dee8b"; depth:123; endswith; nocase; http.host; content:"23.94.145.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906115/; classtype:trojan-activity;sid:84769215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/client.exe"; depth:11; endswith; nocase; http.host; content:"85.203.4.64"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906114/; classtype:trojan-activity;sid:84769214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"120.77.1.20"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906113/; classtype:trojan-activity;sid:84769213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.117.76.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906112/; classtype:trojan-activity;sid:84769212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.212.210"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906111/; classtype:trojan-activity;sid:84769211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.229.190.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906110/; classtype:trojan-activity;sid:84769210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.23.132.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906109/; classtype:trojan-activity;sid:84769209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.117.76.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906108/; classtype:trojan-activity;sid:84769208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906107/; classtype:trojan-activity;sid:84769207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apiti.png"; depth:10; endswith; nocase; http.host; content:"pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906106/; classtype:trojan-activity;sid:84769206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"elxxvvx.xyz"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906105/; classtype:trojan-activity;sid:84769205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ncx"; depth:4; endswith; nocase; http.host; content:"multisavcx.xyz"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906104/; classtype:trojan-activity;sid:84769204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jquery.min.js"; depth:14; endswith; nocase; http.host; content:"python3.en-us--balancing.co"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906103/; classtype:trojan-activity;sid:84769203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.220.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906102/; classtype:trojan-activity;sid:84769202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.23.132.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906101/; classtype:trojan-activity;sid:84769201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atomic/atomic.sh"; depth:17; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906100/; classtype:trojan-activity;sid:84769200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"110.186.229.108"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906099/; classtype:trojan-activity;sid:84769199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"183.63.8.194"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906097/; classtype:trojan-activity;sid:84769197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"115.57.182.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906098/; classtype:trojan-activity;sid:84769198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.52.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906096/; classtype:trojan-activity;sid:84769196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/76e6f5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906084/; classtype:trojan-activity;sid:84769184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/85692b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906085/; classtype:trojan-activity;sid:84769185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b39f8f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906086/; classtype:trojan-activity;sid:84769186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e00ee7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906087/; classtype:trojan-activity;sid:84769187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6a20da"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906088/; classtype:trojan-activity;sid:84769188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/de19ef"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906089/; classtype:trojan-activity;sid:84769189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b74d4d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906090/; classtype:trojan-activity;sid:84769190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/589a29"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906091/; classtype:trojan-activity;sid:84769191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4d493d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906092/; classtype:trojan-activity;sid:84769192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1498b2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906093/; classtype:trojan-activity;sid:84769193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/804c43"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906094/; classtype:trojan-activity;sid:84769194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/55bd33"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906095/; classtype:trojan-activity;sid:84769195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.mipsel"; depth:17; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906083/; classtype:trojan-activity;sid:84769183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/faedd6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906081/; classtype:trojan-activity;sid:84769181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/78f157"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906082/; classtype:trojan-activity;sid:84769182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/676064"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906059/; classtype:trojan-activity;sid:84769159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c72382"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906060/; classtype:trojan-activity;sid:84769160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0b1663"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906061/; classtype:trojan-activity;sid:84769161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/515c80"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906062/; classtype:trojan-activity;sid:84769162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8ac363"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906063/; classtype:trojan-activity;sid:84769163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/db7a9c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906064/; classtype:trojan-activity;sid:84769164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0db2ec"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906065/; classtype:trojan-activity;sid:84769165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2b08fb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906066/; classtype:trojan-activity;sid:84769166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/456417"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906067/; classtype:trojan-activity;sid:84769167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/279fe0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906068/; classtype:trojan-activity;sid:84769168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/69d5f2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906069/; classtype:trojan-activity;sid:84769169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/acb326"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906070/; classtype:trojan-activity;sid:84769170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/473c1a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906071/; classtype:trojan-activity;sid:84769171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/065109"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906072/; classtype:trojan-activity;sid:84769172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/49fa35"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906073/; classtype:trojan-activity;sid:84769173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9dfbc4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906074/; classtype:trojan-activity;sid:84769174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b3679a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906075/; classtype:trojan-activity;sid:84769175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/094392"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906076/; classtype:trojan-activity;sid:84769176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c4844d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906077/; classtype:trojan-activity;sid:84769177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/573976"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906078/; classtype:trojan-activity;sid:84769178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c515ee"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906079/; classtype:trojan-activity;sid:84769179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/344f7e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906080/; classtype:trojan-activity;sid:84769180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv4l"; depth:17; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906054/; classtype:trojan-activity;sid:84769154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.x86_64"; depth:17; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906055/; classtype:trojan-activity;sid:84769155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv7l"; depth:17; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906056/; classtype:trojan-activity;sid:84769156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv5l"; depth:17; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906057/; classtype:trojan-activity;sid:84769157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv6l"; depth:17; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906058/; classtype:trojan-activity;sid:84769158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.mips"; depth:15; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906053/; classtype:trojan-activity;sid:84769153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.12.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906052/; classtype:trojan-activity;sid:84769152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.52.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906051/; classtype:trojan-activity;sid:84769151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.190.189.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906050/; classtype:trojan-activity;sid:84769150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.12.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906049/; classtype:trojan-activity;sid:84769149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.250.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906048/; classtype:trojan-activity;sid:84769148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.98.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906047/; classtype:trojan-activity;sid:84769147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/10y8r8/ac.xor"; depth:14; endswith; nocase; http.host; content:"dl.myresult.co.za"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906046/; classtype:trojan-activity;sid:84769146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/10y8r8/wupd.bat"; depth:16; endswith; nocase; http.host; content:"dl.myresult.co.za"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906045/; classtype:trojan-activity;sid:84769145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/10y8r8/as.xor"; depth:14; endswith; nocase; http.host; content:"dl.myresult.co.za"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906043/; classtype:trojan-activity;sid:84769143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/10y8r8/inject.ps1"; depth:18; endswith; nocase; http.host; content:"dl.myresult.co.za"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906044/; classtype:trojan-activity;sid:84769144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/10y8r8/launch.vbs"; depth:18; endswith; nocase; http.host; content:"dl.myresult.co.za"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906042/; classtype:trojan-activity;sid:84769142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.90.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906041/; classtype:trojan-activity;sid:84769141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.98.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906040/; classtype:trojan-activity;sid:84769140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.m68k"; depth:10; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906039/; classtype:trojan-activity;sid:84769139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.sparc"; depth:11; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906037/; classtype:trojan-activity;sid:84769137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.ppc"; depth:9; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906038/; classtype:trojan-activity;sid:84769138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.arm6"; depth:10; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906033/; classtype:trojan-activity;sid:84769133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.x86_32"; depth:12; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906034/; classtype:trojan-activity;sid:84769134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.mpsl"; depth:10; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906035/; classtype:trojan-activity;sid:84769135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.sh4"; depth:9; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906036/; classtype:trojan-activity;sid:84769136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.mips"; depth:10; endswith; nocase; http.host; content:"ip-69-33-213-199.dfw.megapath.net"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906032/; classtype:trojan-activity;sid:84769132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.arm7"; depth:10; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906031/; classtype:trojan-activity;sid:84769131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.dbg"; depth:9; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906025/; classtype:trojan-activity;sid:84769125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.x86"; depth:9; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906026/; classtype:trojan-activity;sid:84769126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.arm5"; depth:10; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906027/; classtype:trojan-activity;sid:84769127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.x86_64"; depth:12; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906028/; classtype:trojan-activity;sid:84769128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.mips"; depth:10; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906029/; classtype:trojan-activity;sid:84769129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.arm4"; depth:10; endswith; nocase; http.host; content:"69.33.213.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906030/; classtype:trojan-activity;sid:84769130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/v1/install"; depth:15; endswith; nocase; http.host; content:"94.154.43.196"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906024/; classtype:trojan-activity;sid:84769124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_0d90bf33aa3e6c18.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906023/; classtype:trojan-activity;sid:84769123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/servicer.apk"; depth:13; endswith; nocase; http.host; content:"37.221.93.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906019/; classtype:trojan-activity;sid:84769119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4799cc1c552dbe75.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906020/; classtype:trojan-activity;sid:84769120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/services.apk"; depth:13; endswith; nocase; http.host; content:"176.65.139.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906021/; classtype:trojan-activity;sid:84769121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/services.apk"; depth:13; endswith; nocase; http.host; content:"38.97.56.196"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906022/; classtype:trojan-activity;sid:84769122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_fedb1cae70e15500.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906017/; classtype:trojan-activity;sid:84769117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5531355e31758cd9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906018/; classtype:trojan-activity;sid:84769118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nxtlvllnk/screenconnect.clientsetup.exe"; depth:40; endswith; nocase; http.host; content:"bm2contabilidade.com.br"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906016/; classtype:trojan-activity;sid:84769116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bembemi.exe"; depth:12; endswith; nocase; http.host; content:"pub-f225fc4c925f4cad963c543c3378b1ae.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906015/; classtype:trojan-activity;sid:84769115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bac_pc%e5%a3%b3.exe"; depth:20; endswith; nocase; http.host; content:"xxpro.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906014/; classtype:trojan-activity;sid:84769114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/sp.zip"; depth:9; endswith; nocase; http.host; content:"baoxissde.one"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906013/; classtype:trojan-activity;sid:84769113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ocudlomo.msi"; depth:13; endswith; nocase; http.host; content:"pub-a6ae2d4aa393400aa29f7b02ac7ab213.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906012/; classtype:trojan-activity;sid:84769112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohijfalqvzldlhaqw.exe"; depth:22; endswith; nocase; http.host; content:"pub-1f5a501a59d74a6a97e77126cf1fc526.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906010/; classtype:trojan-activity;sid:84769110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/client.exe"; depth:11; endswith; nocase; http.host; content:"94.26.90.90"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906011/; classtype:trojan-activity;sid:84769111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/screenconnect.clientsetup.msi"; depth:30; endswith; nocase; http.host; content:"importantdocumentscopys.s3.us-east-2.amazonaws.com"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906009/; classtype:trojan-activity;sid:84769109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/deadlock/loader.exe"; depth:23; endswith; nocase; http.host; content:"itsmystik.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906008/; classtype:trojan-activity;sid:84769108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/10y8r8/go_b3.bat"; depth:17; endswith; nocase; http.host; content:"dl.myresult.co.za"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906006/; classtype:trojan-activity;sid:84769106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/client/battlebot.exe"; depth:21; endswith; nocase; http.host; content:"tantralegacy.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906007/; classtype:trojan-activity;sid:84769107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"meeting.supply-reflection.shop"; depth:30; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906005/; classtype:trojan-activity;sid:84769105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/spxploy.vbs"; depth:14; endswith; nocase; http.host; content:"baoxissde.one"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906004/; classtype:trojan-activity;sid:84769104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty/s.bat"; depth:9; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906003/; classtype:trojan-activity;sid:84769103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty/load.bat"; depth:12; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906002/; classtype:trojan-activity;sid:84769102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty/v/client_carrier.ahk"; depth:24; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906001/; classtype:trojan-activity;sid:84769101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.239.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906000/; classtype:trojan-activity;sid:84769100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44/goodcommuncaitionskilldevleipedfromthegood.js"; depth:49; endswith; nocase; http.host; content:"172.245.209.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905999/; classtype:trojan-activity;sid:84769099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/09890/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905995/; classtype:trojan-activity;sid:84769095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/29039/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905996/; classtype:trojan-activity;sid:84769096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/63748/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905997/; classtype:trojan-activity;sid:84769097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/93/goodthingswithbestnetworkingskillcomingfromtheheartforme.js"; depth:63; endswith; nocase; http.host; content:"204.44.69.216"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905998/; classtype:trojan-activity;sid:84769098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wed/crypted.ps1"; depth:16; endswith; nocase; http.host; content:"198.23.144.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905994/; classtype:trojan-activity;sid:84769094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ph/velogs.exe"; depth:14; endswith; nocase; http.host; content:"172.245.95.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905993/; classtype:trojan-activity;sid:84769093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22/goodpersonforbestthingsfor.hta"; depth:34; endswith; nocase; http.host; content:"107.175.88.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905992/; classtype:trojan-activity;sid:84769092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/decerkdepesl.apk"; depth:17; endswith; nocase; http.host; content:"azq0yqtjd.s3.ap-southeast-1.amazonaws.com"; depth:41; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905986/; classtype:trojan-activity;sid:84769086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60/document_picture_0994950005995.jpg/verygoodthingsarecomingentiretimeforbest.hta"; depth:83; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905987/; classtype:trojan-activity;sid:84769087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaze.exe"; depth:9; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905988/; classtype:trojan-activity;sid:84769088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/93/ecce/givenmethebestthignswithbetterplacescomingfromthebest.hta"; depth:66; endswith; nocase; http.host; content:"204.44.69.216"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905989/; classtype:trojan-activity;sid:84769089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r843.exe"; depth:9; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905990/; classtype:trojan-activity;sid:84769090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.2.53.55"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905991/; classtype:trojan-activity;sid:84769091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty/p/cgnty_carrier.ahk"; depth:23; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905984/; classtype:trojan-activity;sid:84769084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35/goodthingsarecomingfromthebestplacescomingforme.hta"; depth:55; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905985/; classtype:trojan-activity;sid:84769085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60/goodthingsarebestformehappeninggood.vbe"; depth:43; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905982/; classtype:trojan-activity;sid:84769082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35/eas/niceworking.vbe"; depth:23; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905983/; classtype:trojan-activity;sid:84769083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sike/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905978/; classtype:trojan-activity;sid:84769078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8089/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905979/; classtype:trojan-activity;sid:84769079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/36/ecc/iwantsomethingbetterformegetbackgoodthings.vbe"; depth:54; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905980/; classtype:trojan-activity;sid:84769080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carboncopycloner7.dmg"; depth:22; endswith; nocase; http.host; content:"connectmagazineads.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905981/; classtype:trojan-activity;sid:84769081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.190.189.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905977/; classtype:trojan-activity;sid:84769077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.250.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905976/; classtype:trojan-activity;sid:84769076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.bash_history"; depth:14; endswith; nocase; http.host; content:"191.44.114.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905975/; classtype:trojan-activity;sid:84769075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.10.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905974/; classtype:trojan-activity;sid:84769074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.145.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905973/; classtype:trojan-activity;sid:84769073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.11.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905972/; classtype:trojan-activity;sid:84769072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.132.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905971/; classtype:trojan-activity;sid:84769071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg11"; depth:5; endswith; nocase; http.host; content:"191.44.114.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905970/; classtype:trojan-activity;sid:84769070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.186.126.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905969/; classtype:trojan-activity;sid:84769069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.11.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905968/; classtype:trojan-activity;sid:84769068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905967/; classtype:trojan-activity;sid:84769067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.121.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905966/; classtype:trojan-activity;sid:84769066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.151.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905965/; classtype:trojan-activity;sid:84769065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905964/; classtype:trojan-activity;sid:84769064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905963/; classtype:trojan-activity;sid:84769063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.121.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905962/; classtype:trojan-activity;sid:84769062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.151.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905961/; classtype:trojan-activity;sid:84769061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905960/; classtype:trojan-activity;sid:84769060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.249.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905959/; classtype:trojan-activity;sid:84769059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.163.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905958/; classtype:trojan-activity;sid:84769058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.172.77.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905957/; classtype:trojan-activity;sid:84769057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_aarch64"; depth:13; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905956/; classtype:trojan-activity;sid:84769056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_powerpc"; depth:13; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905955/; classtype:trojan-activity;sid:84769055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm6"; depth:10; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905954/; classtype:trojan-activity;sid:84769054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm4"; depth:10; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905953/; classtype:trojan-activity;sid:84769053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm7"; depth:10; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905952/; classtype:trojan-activity;sid:84769052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbc"; depth:4; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905951/; classtype:trojan-activity;sid:84769051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86"; depth:9; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905949/; classtype:trojan-activity;sid:84769049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86_64"; depth:12; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905950/; classtype:trojan-activity;sid:84769050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm5"; depth:10; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905948/; classtype:trojan-activity;sid:84769048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.233.205.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905947/; classtype:trojan-activity;sid:84769047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.163.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905946/; classtype:trojan-activity;sid:84769046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.45.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905945/; classtype:trojan-activity;sid:84769045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.233.205.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905944/; classtype:trojan-activity;sid:84769044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.108.7.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905943/; classtype:trojan-activity;sid:84769043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.45.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905942/; classtype:trojan-activity;sid:84769042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.46.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3905941/; classtype:trojan-activity;sid:84769041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.114.59.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905940/; classtype:trojan-activity;sid:84769040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.108.7.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905939/; classtype:trojan-activity;sid:84769039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.46.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905938/; classtype:trojan-activity;sid:84769038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.169.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905937/; classtype:trojan-activity;sid:84769037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.81.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905936/; classtype:trojan-activity;sid:84769036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905935/; classtype:trojan-activity;sid:84769035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.169.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905934/; classtype:trojan-activity;sid:84769034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mips"; depth:10; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905933/; classtype:trojan-activity;sid:84769033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mipsel"; depth:12; endswith; nocase; http.host; content:"31.58.171.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905932/; classtype:trojan-activity;sid:84769032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.197.114"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905931/; classtype:trojan-activity;sid:84769031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.81.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905930/; classtype:trojan-activity;sid:84769030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/cl1786993325592.exe"; depth:28; endswith; nocase; http.host; content:"threedrows.net"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905929/; classtype:trojan-activity;sid:84769029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.197.114"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905928/; classtype:trojan-activity;sid:84769028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/updater.exe"; depth:12; endswith; nocase; http.host; content:"firstratezim.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905927/; classtype:trojan-activity;sid:84769027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.241.88.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905926/; classtype:trojan-activity;sid:84769026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.103.241"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905925/; classtype:trojan-activity;sid:84769025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.241.88.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905924/; classtype:trojan-activity;sid:84769024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig.sh"; depth:9; endswith; nocase; http.host; content:"154.90.70.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905923/; classtype:trojan-activity;sid:84769023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.210.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905922/; classtype:trojan-activity;sid:84769022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.229.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905921/; classtype:trojan-activity;sid:84769021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.218.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905920/; classtype:trojan-activity;sid:84769020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.229.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905919/; classtype:trojan-activity;sid:84769019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.210.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905918/; classtype:trojan-activity;sid:84769018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.5.26.85"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905917/; classtype:trojan-activity;sid:84769017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.190.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905916/; classtype:trojan-activity;sid:84769016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.182.97.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905915/; classtype:trojan-activity;sid:84769015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.190.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905914/; classtype:trojan-activity;sid:84769014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.255.41.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905913/; classtype:trojan-activity;sid:84769013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.185.241.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905912/; classtype:trojan-activity;sid:84769012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zuyoking.png"; depth:13; endswith; nocase; http.host; content:"pub-1c4ef2a315ec4b89b9dfad9472afee69.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905911/; classtype:trojan-activity;sid:84769011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lui.hta"; depth:8; endswith; nocase; http.host; content:"one-graup.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905910/; classtype:trojan-activity;sid:84769010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teddywon.hta"; depth:13; endswith; nocase; http.host; content:"pub-eab9eb7761644f51bceeecfefdf0ec2b.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905909/; classtype:trojan-activity;sid:84769009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/radman.png"; depth:11; endswith; nocase; http.host; content:"pub-1c4ef2a315ec4b89b9dfad9472afee69.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905908/; classtype:trojan-activity;sid:84769008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clpr6.exe"; depth:10; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905907/; classtype:trojan-activity;sid:84769007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uniform_4.44_install.exe"; depth:25; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905906/; classtype:trojan-activity;sid:84769006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zs/config.bin"; depth:14; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905905/; classtype:trojan-activity;sid:84769005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.68.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905904/; classtype:trojan-activity;sid:84769004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin"; depth:4; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905903/; classtype:trojan-activity;sid:84769003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data"; depth:5; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905901/; classtype:trojan-activity;sid:84769001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chromelevator_x64.exe"; depth:22; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905902/; classtype:trojan-activity;sid:84769002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/package.zip"; depth:12; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905900/; classtype:trojan-activity;sid:84769000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/enc"; depth:4; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905899/; classtype:trojan-activity;sid:84768999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.ps1"; depth:8; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905896/; classtype:trojan-activity;sid:84768996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r.ps1"; depth:6; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905897/; classtype:trojan-activity;sid:84768997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dll"; depth:4; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905898/; classtype:trojan-activity;sid:84768998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update.ps1"; depth:11; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905894/; classtype:trojan-activity;sid:84768994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upd"; depth:4; endswith; nocase; http.host; content:"103.229.53.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905895/; classtype:trojan-activity;sid:84768995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/msi_pro_last.jpeg"; depth:25; endswith; nocase; http.host; content:"pic.li"; depth:6; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905892/; classtype:trojan-activity;sid:84768992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/img_222651.png"; depth:18; endswith; nocase; http.host; content:"23.94.148.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905893/; classtype:trojan-activity;sid:84768993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/weareinthebestplaceforbetterfuturecomingforme.hta"; depth:53; endswith; nocase; http.host; content:"23.94.148.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905891/; classtype:trojan-activity;sid:84768991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/common_offline_utility_itr-1_to_4_ay2026-07-27.vhdx"; depth:52; endswith; nocase; http.host; content:"bmnjhy.shop"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905890/; classtype:trojan-activity;sid:84768990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/common_offline_utility_itr-1_to_4_ay2026-07-27.vhdx"; depth:52; endswith; nocase; http.host; content:"mkjiun.shop"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905889/; classtype:trojan-activity;sid:84768989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.68.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905888/; classtype:trojan-activity;sid:84768988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/common_offline_utility_itr-1_to_4_ay2026-07-27.vhdx"; depth:52; endswith; nocase; http.host; content:"nmhjnu.shop"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905887/; classtype:trojan-activity;sid:84768987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys/x2/x2-payload_dfyihao.zip"; depth:30; endswith; nocase; http.host; content:"rukeyou.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905886/; classtype:trojan-activity;sid:84768986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys/x2/x2-payload_baolljp.jpg"; depth:30; endswith; nocase; http.host; content:"rukeyou.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905885/; classtype:trojan-activity;sid:84768985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.255.41.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905884/; classtype:trojan-activity;sid:84768984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.185.241.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905883/; classtype:trojan-activity;sid:84768983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.115.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905882/; classtype:trojan-activity;sid:84768982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/indie.exe"; depth:10; endswith; nocase; http.host; content:"www.justturtle.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905881/; classtype:trojan-activity;sid:84768981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.115.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905880/; classtype:trojan-activity;sid:84768980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905879/; classtype:trojan-activity;sid:84768979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.68.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905878/; classtype:trojan-activity;sid:84768978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905877/; classtype:trojan-activity;sid:84768977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n330"; depth:5; endswith; nocase; http.host; content:"akb.cat"; depth:7; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905876/; classtype:trojan-activity;sid:84768976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check"; depth:6; endswith; nocase; http.host; content:"verifyidentify.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905875/; classtype:trojan-activity;sid:84768975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.7.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905874/; classtype:trojan-activity;sid:84768974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.spc"; depth:13; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905873/; classtype:trojan-activity;sid:84768973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.x86_64"; depth:16; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905871/; classtype:trojan-activity;sid:84768971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b.sh"; depth:5; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905872/; classtype:trojan-activity;sid:84768972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl/epf215dtv0l/2otso19m8v27gj0d381.dat"; depth:41; endswith; nocase; http.host; content:"aspenriver6.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905870/; classtype:trojan-activity;sid:84768970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.s390x"; depth:15; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905865/; classtype:trojan-activity;sid:84768965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.mips"; depth:14; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905866/; classtype:trojan-activity;sid:84768966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.sh4"; depth:13; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905867/; classtype:trojan-activity;sid:84768967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.ppc"; depth:13; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905868/; classtype:trojan-activity;sid:84768968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.ppc64el"; depth:17; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905869/; classtype:trojan-activity;sid:84768969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.arm"; depth:13; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905859/; classtype:trojan-activity;sid:84768959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.m68k"; depth:14; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905860/; classtype:trojan-activity;sid:84768960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.mips64el"; depth:18; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905861/; classtype:trojan-activity;sid:84768961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.x86"; depth:13; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905862/; classtype:trojan-activity;sid:84768962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.arm6"; depth:14; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905863/; classtype:trojan-activity;sid:84768963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.arm5"; depth:14; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905864/; classtype:trojan-activity;sid:84768964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t0907.exe"; depth:10; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905858/; classtype:trojan-activity;sid:84768958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s0907.exe"; depth:10; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905856/; classtype:trojan-activity;sid:84768956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ven9392.exe"; depth:12; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905857/; classtype:trojan-activity;sid:84768957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.arm7"; depth:14; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905853/; classtype:trojan-activity;sid:84768953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.arm64"; depth:15; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905854/; classtype:trojan-activity;sid:84768954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bots/bot.mpsl"; depth:14; endswith; nocase; http.host; content:"wer-ldr.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905855/; classtype:trojan-activity;sid:84768955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.bat"; depth:6; endswith; nocase; http.host; content:"cqintzfep6rw6jc9.public.blob.vercel-storage.com"; depth:47; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905851/; classtype:trojan-activity;sid:84768951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/servicer.apk"; depth:13; endswith; nocase; http.host; content:"77.239.124.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905852/; classtype:trojan-activity;sid:84768952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r4jnneaizebrwckgg"; depth:18; endswith; nocase; http.host; content:"daleeby.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905849/; classtype:trojan-activity;sid:84768949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.217.123.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905848/; classtype:trojan-activity;sid:84768948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.22.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905847/; classtype:trojan-activity;sid:84768947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.121.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905846/; classtype:trojan-activity;sid:84768946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"156.146.26.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905845/; classtype:trojan-activity;sid:84768945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.121.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905844/; classtype:trojan-activity;sid:84768944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.38.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905843/; classtype:trojan-activity;sid:84768943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connectproagentsetup.msi"; depth:25; endswith; nocase; http.host; content:"2.58.56.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905842/; classtype:trojan-activity;sid:84768942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.12.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905841/; classtype:trojan-activity;sid:84768941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"192.142.53.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905840/; classtype:trojan-activity;sid:84768940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"192.142.53.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905839/; classtype:trojan-activity;sid:84768939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/jhgkuyyg.exe"; depth:28; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905836/; classtype:trojan-activity;sid:84768936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/arftu.exe"; depth:25; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905837/; classtype:trojan-activity;sid:84768937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/dflnglkfdmgs.exe"; depth:32; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905838/; classtype:trojan-activity;sid:84768938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/bjbh.exe"; depth:24; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905832/; classtype:trojan-activity;sid:84768932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/kjhgfds.exe"; depth:27; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905833/; classtype:trojan-activity;sid:84768933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/hnmh.exe"; depth:24; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905834/; classtype:trojan-activity;sid:84768934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/kjhjhkjkjh.exe"; depth:30; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905835/; classtype:trojan-activity;sid:84768935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.29.33.253"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905831/; classtype:trojan-activity;sid:84768931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.65.215"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905830/; classtype:trojan-activity;sid:84768930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/kliulij.exe"; depth:27; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905829/; classtype:trojan-activity;sid:84768929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/r7.exe"; depth:21; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905826/; classtype:trojan-activity;sid:84768926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/mixnew2.exe"; depth:26; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905827/; classtype:trojan-activity;sid:84768927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/ojujn.exe"; depth:25; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905828/; classtype:trojan-activity;sid:84768928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/r6.exe"; depth:21; endswith; nocase; http.host; content:"hypercorevector5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905825/; classtype:trojan-activity;sid:84768925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"79.133.57.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905824/; classtype:trojan-activity;sid:84768924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"79.133.57.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905823/; classtype:trojan-activity;sid:84768923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"84.200.80.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905822/; classtype:trojan-activity;sid:84768922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"84.200.80.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905821/; classtype:trojan-activity;sid:84768921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/8133118018/7hc0ffr.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905820/; classtype:trojan-activity;sid:84768920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905819/; classtype:trojan-activity;sid:84768919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905818/; classtype:trojan-activity;sid:84768918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905817/; classtype:trojan-activity;sid:84768917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"45.83.28.121"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905816/; classtype:trojan-activity;sid:84768916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.217.97.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905814/; classtype:trojan-activity;sid:84768914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.217.97.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905815/; classtype:trojan-activity;sid:84768915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.17.83.99"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905813/; classtype:trojan-activity;sid:84768913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905811/; classtype:trojan-activity;sid:84768911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905812/; classtype:trojan-activity;sid:84768912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905810/; classtype:trojan-activity;sid:84768910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905808/; classtype:trojan-activity;sid:84768908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905809/; classtype:trojan-activity;sid:84768909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905799/; classtype:trojan-activity;sid:84768899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905800/; classtype:trojan-activity;sid:84768900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm"; depth:10; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905801/; classtype:trojan-activity;sid:84768901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arc"; depth:10; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905802/; classtype:trojan-activity;sid:84768902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm7"; depth:11; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905803/; classtype:trojan-activity;sid:84768903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905804/; classtype:trojan-activity;sid:84768904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905805/; classtype:trojan-activity;sid:84768905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905806/; classtype:trojan-activity;sid:84768906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905807/; classtype:trojan-activity;sid:84768907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905795/; classtype:trojan-activity;sid:84768895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905796/; classtype:trojan-activity;sid:84768896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i686"; depth:11; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905797/; classtype:trojan-activity;sid:84768897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"176.65.139.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905798/; classtype:trojan-activity;sid:84768898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"178.16.52.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905794/; classtype:trojan-activity;sid:84768894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"178.16.52.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905793/; classtype:trojan-activity;sid:84768893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"193.26.115.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905792/; classtype:trojan-activity;sid:84768892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"193.26.115.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905791/; classtype:trojan-activity;sid:84768891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.12.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905790/; classtype:trojan-activity;sid:84768890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"79.106.74.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905789/; classtype:trojan-activity;sid:84768889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.17.83.99"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905788/; classtype:trojan-activity;sid:84768888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.55.72.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905787/; classtype:trojan-activity;sid:84768887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.236.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905786/; classtype:trojan-activity;sid:84768886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.171.163"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905785/; classtype:trojan-activity;sid:84768885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.76.176"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905784/; classtype:trojan-activity;sid:84768884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.55.72.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905783/; classtype:trojan-activity;sid:84768883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.193.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905782/; classtype:trojan-activity;sid:84768882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"centrodolce.screenconnect.com"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905781/; classtype:trojan-activity;sid:84768881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ofiltytuerutyueiioo/docusign-8901123adobe-reader07zuillnirusi.bat"; depth:66; endswith; nocase; http.host; content:"mkconstructions.net"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905780/; classtype:trojan-activity;sid:84768880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.157.224"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905779/; classtype:trojan-activity;sid:84768879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.27.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905777/; classtype:trojan-activity;sid:84768877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.107.209.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905778/; classtype:trojan-activity;sid:84768878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.143.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905776/; classtype:trojan-activity;sid:84768876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.193.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905775/; classtype:trojan-activity;sid:84768875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.27.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905774/; classtype:trojan-activity;sid:84768874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.143.200"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905773/; classtype:trojan-activity;sid:84768873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.174.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905772/; classtype:trojan-activity;sid:84768872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.59.34.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905771/; classtype:trojan-activity;sid:84768871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.148.157.224"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905770/; classtype:trojan-activity;sid:84768870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.112.59.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905769/; classtype:trojan-activity;sid:84768869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.10.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905768/; classtype:trojan-activity;sid:84768868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b8afcc5c4d1ea78e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905767/; classtype:trojan-activity;sid:84768867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ae0cbdb600ff92fa.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905766/; classtype:trojan-activity;sid:84768866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.11.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905765/; classtype:trojan-activity;sid:84768865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.174.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905764/; classtype:trojan-activity;sid:84768864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.221.254.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905763/; classtype:trojan-activity;sid:84768863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.59.34.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905762/; classtype:trojan-activity;sid:84768862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.173.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905761/; classtype:trojan-activity;sid:84768861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.7.241.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905760/; classtype:trojan-activity;sid:84768860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.10.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905759/; classtype:trojan-activity;sid:84768859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.240.9.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905757/; classtype:trojan-activity;sid:84768857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.27.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905758/; classtype:trojan-activity;sid:84768858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.7.241.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905756/; classtype:trojan-activity;sid:84768856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.144.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905755/; classtype:trojan-activity;sid:84768855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.253.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905754/; classtype:trojan-activity;sid:84768854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.221.254.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905753/; classtype:trojan-activity;sid:84768853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"66.8.135.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905752/; classtype:trojan-activity;sid:84768852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.11.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905751/; classtype:trojan-activity;sid:84768851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.253.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905750/; classtype:trojan-activity;sid:84768850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.146.92.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905749/; classtype:trojan-activity;sid:84768849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.157.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905747/; classtype:trojan-activity;sid:84768847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"66.8.135.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905748/; classtype:trojan-activity;sid:84768848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.i686"; depth:34; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905745/; classtype:trojan-activity;sid:84768845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.arm"; depth:33; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905746/; classtype:trojan-activity;sid:84768846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.204.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905743/; classtype:trojan-activity;sid:84768843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.190.17.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905744/; classtype:trojan-activity;sid:84768844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.153.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905742/; classtype:trojan-activity;sid:84768842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.107.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905739/; classtype:trojan-activity;sid:84768839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.17.34.84"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905740/; classtype:trojan-activity;sid:84768840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daemonc"; depth:8; endswith; nocase; http.host; content:"94.159.98.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905741/; classtype:trojan-activity;sid:84768841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.242.40"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905735/; classtype:trojan-activity;sid:84768835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.i486"; depth:34; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905736/; classtype:trojan-activity;sid:84768836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.105.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905737/; classtype:trojan-activity;sid:84768837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"120.71.0.131"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905738/; classtype:trojan-activity;sid:84768838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.105.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905718/; classtype:trojan-activity;sid:84768818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.163.107.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905719/; classtype:trojan-activity;sid:84768819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.8.116"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905720/; classtype:trojan-activity;sid:84768820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.68.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905721/; classtype:trojan-activity;sid:84768821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.29.39.213"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905722/; classtype:trojan-activity;sid:84768822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.59.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905723/; classtype:trojan-activity;sid:84768823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.194.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905724/; classtype:trojan-activity;sid:84768824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.38.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905725/; classtype:trojan-activity;sid:84768825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.79.195.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905726/; classtype:trojan-activity;sid:84768826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.60.200.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905727/; classtype:trojan-activity;sid:84768827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905728/; classtype:trojan-activity;sid:84768828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.mpsl"; depth:34; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905729/; classtype:trojan-activity;sid:84768829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.33.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905730/; classtype:trojan-activity;sid:84768830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.87.111.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905731/; classtype:trojan-activity;sid:84768831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905732/; classtype:trojan-activity;sid:84768832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.arm7"; depth:34; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905733/; classtype:trojan-activity;sid:84768833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.238.108.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905734/; classtype:trojan-activity;sid:84768834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.198.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905710/; classtype:trojan-activity;sid:84768810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.178.149.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905711/; classtype:trojan-activity;sid:84768811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.130.28"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905712/; classtype:trojan-activity;sid:84768812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.106.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905713/; classtype:trojan-activity;sid:84768813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905714/; classtype:trojan-activity;sid:84768814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.181.83"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905715/; classtype:trojan-activity;sid:84768815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.120.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905716/; classtype:trojan-activity;sid:84768816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.146.92.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905717/; classtype:trojan-activity;sid:84768817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.arc"; depth:33; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905706/; classtype:trojan-activity;sid:84768806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amd"; depth:4; endswith; nocase; http.host; content:"61.184.10.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905707/; classtype:trojan-activity;sid:84768807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.28.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905708/; classtype:trojan-activity;sid:84768808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.252.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905709/; classtype:trojan-activity;sid:84768809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.153.54"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905703/; classtype:trojan-activity;sid:84768803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.arm6"; depth:34; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905704/; classtype:trojan-activity;sid:84768804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905705/; classtype:trojan-activity;sid:84768805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syss"; depth:5; endswith; nocase; http.host; content:"61.184.10.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905702/; classtype:trojan-activity;sid:84768802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.18.84.125"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905700/; classtype:trojan-activity;sid:84768800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.arm5"; depth:34; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905701/; classtype:trojan-activity;sid:84768801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.83.89"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905686/; classtype:trojan-activity;sid:84768786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905687/; classtype:trojan-activity;sid:84768787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.162.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905688/; classtype:trojan-activity;sid:84768788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.83.89"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905689/; classtype:trojan-activity;sid:84768789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.252.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905690/; classtype:trojan-activity;sid:84768790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.7.157.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905691/; classtype:trojan-activity;sid:84768791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.58.130.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905692/; classtype:trojan-activity;sid:84768792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.54.8.116"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905693/; classtype:trojan-activity;sid:84768793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.31.114"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905694/; classtype:trojan-activity;sid:84768794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.x86"; depth:33; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905695/; classtype:trojan-activity;sid:84768795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.x86_64"; depth:36; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905696/; classtype:trojan-activity;sid:84768796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.40.180.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905697/; classtype:trojan-activity;sid:84768797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.120.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905698/; classtype:trojan-activity;sid:84768798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.85.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905699/; classtype:trojan-activity;sid:84768799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.246.143"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905675/; classtype:trojan-activity;sid:84768775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.153.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905676/; classtype:trojan-activity;sid:84768776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.86.128.27"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905677/; classtype:trojan-activity;sid:84768777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905678/; classtype:trojan-activity;sid:84768778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.68.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905679/; classtype:trojan-activity;sid:84768779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.218.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905680/; classtype:trojan-activity;sid:84768780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.73.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905681/; classtype:trojan-activity;sid:84768781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.136.40.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905682/; classtype:trojan-activity;sid:84768782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.109.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905683/; classtype:trojan-activity;sid:84768783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.162.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905684/; classtype:trojan-activity;sid:84768784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.81.188"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905685/; classtype:trojan-activity;sid:84768785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.245.28.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905669/; classtype:trojan-activity;sid:84768769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.229.134"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905670/; classtype:trojan-activity;sid:84768770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.81.188"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905671/; classtype:trojan-activity;sid:84768771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905672/; classtype:trojan-activity;sid:84768772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.106.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905673/; classtype:trojan-activity;sid:84768773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.78.12.145"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905674/; classtype:trojan-activity;sid:84768774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"72.29.46.195"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905668/; classtype:trojan-activity;sid:84768768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.sh4"; depth:33; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905667/; classtype:trojan-activity;sid:84768767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.109.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905661/; classtype:trojan-activity;sid:84768761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.141.218"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905662/; classtype:trojan-activity;sid:84768762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.246.143"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905663/; classtype:trojan-activity;sid:84768763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.236.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905664/; classtype:trojan-activity;sid:84768764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.59.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905665/; classtype:trojan-activity;sid:84768765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.178.149.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905666/; classtype:trojan-activity;sid:84768766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.61.92.78"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905643/; classtype:trojan-activity;sid:84768743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.mips"; depth:34; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905644/; classtype:trojan-activity;sid:84768744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.m68k"; depth:34; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905645/; classtype:trojan-activity;sid:84768745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.12.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905646/; classtype:trojan-activity;sid:84768746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.spc"; depth:33; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905647/; classtype:trojan-activity;sid:84768747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.79.195.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905648/; classtype:trojan-activity;sid:84768748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bin_dir/nullnet_load.ppc"; depth:33; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905649/; classtype:trojan-activity;sid:84768749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.60.200.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905650/; classtype:trojan-activity;sid:84768750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905651/; classtype:trojan-activity;sid:84768751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullnet_bash.sh"; depth:16; endswith; nocase; http.host; content:"132.243.200.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905652/; classtype:trojan-activity;sid:84768752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.139.14.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905653/; classtype:trojan-activity;sid:84768753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"79.135.225.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905654/; classtype:trojan-activity;sid:84768754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.245.28.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905655/; classtype:trojan-activity;sid:84768755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.78.12.145"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905656/; classtype:trojan-activity;sid:84768756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.23.194.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905657/; classtype:trojan-activity;sid:84768757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.181.83"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905658/; classtype:trojan-activity;sid:84768758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.159.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905659/; classtype:trojan-activity;sid:84768759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/linux"; depth:8; endswith; nocase; http.host; content:"194.59.31.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905660/; classtype:trojan-activity;sid:84768760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"66.212.173.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905635/; classtype:trojan-activity;sid:84768735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.102.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905636/; classtype:trojan-activity;sid:84768736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.58.252.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905637/; classtype:trojan-activity;sid:84768737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905638/; classtype:trojan-activity;sid:84768738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.177.244.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905639/; classtype:trojan-activity;sid:84768739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.171.163"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905640/; classtype:trojan-activity;sid:84768740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905641/; classtype:trojan-activity;sid:84768741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.86.128.27"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905642/; classtype:trojan-activity;sid:84768742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/j"; depth:2; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905630/; classtype:trojan-activity;sid:84768730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/routerip.sh"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905631/; classtype:trojan-activity;sid:84768731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl"; depth:3; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905632/; classtype:trojan-activity;sid:84768732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaws.sh"; depth:8; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905633/; classtype:trojan-activity;sid:84768733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r"; depth:2; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905634/; classtype:trojan-activity;sid:84768734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.28.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905629/; classtype:trojan-activity;sid:84768729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.232.226.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905628/; classtype:trojan-activity;sid:84768728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.157.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905627/; classtype:trojan-activity;sid:84768727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlc.zip"; depth:8; endswith; nocase; http.host; content:"baileyemas.com"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905626/; classtype:trojan-activity;sid:84768726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.1.44"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905625/; classtype:trojan-activity;sid:84768725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dubl2/dubl22allremriki/ldrdubl2132.exe"; depth:39; endswith; nocase; http.host; content:"bmpincorporated.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905624/; classtype:trojan-activity;sid:84768724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dubl2/dubl22allremriki/fls/ato15.zip"; depth:37; endswith; nocase; http.host; content:"bmpincorporated.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905623/; classtype:trojan-activity;sid:84768723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.156.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905622/; classtype:trojan-activity;sid:84768722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.1.44"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905621/; classtype:trojan-activity;sid:84768721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/setup.rar"; depth:10; endswith; nocase; http.host; content:"winds11.site"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905620/; classtype:trojan-activity;sid:84768720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/msi_pro.png"; depth:19; endswith; nocase; http.host; content:"sunix-technology.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905618/; classtype:trojan-activity;sid:84768718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/litxwnimg_082224.png"; depth:28; endswith; nocase; http.host; content:"sunix-technology.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905619/; classtype:trojan-activity;sid:84768719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//wp-content/bin.exe"; depth:20; endswith; nocase; http.host; content:"teakivo.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905617/; classtype:trojan-activity;sid:84768717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.156.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905616/; classtype:trojan-activity;sid:84768716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.213.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905615/; classtype:trojan-activity;sid:84768715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1zdauolfaqf-s5nc96ptj-nmi5vljtvmm"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905614/; classtype:trojan-activity;sid:84768714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1u-4hfa9ii1eww1mktvpci878-b9rhvga"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905613/; classtype:trojan-activity;sid:84768713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vfrywunacnkfcqy.exe"; depth:20; endswith; nocase; http.host; content:"crazypianoswebshop.nl"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905612/; classtype:trojan-activity;sid:84768712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/a1crypted.ps1"; depth:59; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905610/; classtype:trojan-activity;sid:84768710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/kk1crypted.ps1"; depth:60; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905611/; classtype:trojan-activity;sid:84768711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/mycrypted.ps1"; depth:59; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905606/; classtype:trojan-activity;sid:84768706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/e32crypted.ps1"; depth:60; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905607/; classtype:trojan-activity;sid:84768707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/k15crypted.ps1"; depth:60; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905608/; classtype:trojan-activity;sid:84768708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/kk2crypted.ps1"; depth:60; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905609/; classtype:trojan-activity;sid:84768709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/a2crypted.ps1"; depth:59; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905605/; classtype:trojan-activity;sid:84768705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/21crypted.ps1"; depth:59; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905602/; classtype:trojan-activity;sid:84768702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/u9crypted.ps1"; depth:59; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905603/; classtype:trojan-activity;sid:84768703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/okcrypted.ps1"; depth:59; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905604/; classtype:trojan-activity;sid:84768704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/sitemaps/uscnvym/c1vhrea/p1mujne/kmcrypted.ps1"; depth:59; endswith; nocase; http.host; content:"alahlam.sa"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905601/; classtype:trojan-activity;sid:84768701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.47.120.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905600/; classtype:trojan-activity;sid:84768700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.119.188"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905599/; classtype:trojan-activity;sid:84768699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1mvi9h_rv6mptfrqbc3cdniyfuriaq2tq"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905598/; classtype:trojan-activity;sid:84768698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.140.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905597/; classtype:trojan-activity;sid:84768697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.115.85.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905596/; classtype:trojan-activity;sid:84768696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.94.7"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905595/; classtype:trojan-activity;sid:84768695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.115.85.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905594/; classtype:trojan-activity;sid:84768694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.94.7"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905593/; classtype:trojan-activity;sid:84768693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.172.144"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905592/; classtype:trojan-activity;sid:84768692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.252.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905591/; classtype:trojan-activity;sid:84768691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905590/; classtype:trojan-activity;sid:84768690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.246.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905589/; classtype:trojan-activity;sid:84768689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.m68k"; depth:15; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905580/; classtype:trojan-activity;sid:84768680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arm6"; depth:15; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905581/; classtype:trojan-activity;sid:84768681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arm7"; depth:15; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905582/; classtype:trojan-activity;sid:84768682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.x86_64"; depth:17; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905583/; classtype:trojan-activity;sid:84768683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.ppc"; depth:14; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905584/; classtype:trojan-activity;sid:84768684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arc"; depth:14; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905585/; classtype:trojan-activity;sid:84768685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arm5"; depth:15; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905586/; classtype:trojan-activity;sid:84768686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.sh4"; depth:14; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905587/; classtype:trojan-activity;sid:84768687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.mpsl"; depth:15; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905588/; classtype:trojan-activity;sid:84768688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.arm"; depth:14; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905579/; classtype:trojan-activity;sid:84768679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.85.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905578/; classtype:trojan-activity;sid:84768678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.252.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905576/; classtype:trojan-activity;sid:84768676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.172.144"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905577/; classtype:trojan-activity;sid:84768677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.2.164"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905575/; classtype:trojan-activity;sid:84768675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quickfetch.exe"; depth:15; endswith; nocase; http.host; content:"tattinamecheap.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905574/; classtype:trojan-activity;sid:84768674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/logs.bat"; depth:9; endswith; nocase; http.host; content:"www.artleadsdigital.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905573/; classtype:trojan-activity;sid:84768673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloadencrypted.bin"; depth:21; endswith; nocase; http.host; content:"www.artleadsdigital.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905572/; classtype:trojan-activity;sid:84768672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/logs.py"; depth:8; endswith; nocase; http.host; content:"www.artleadsdigital.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905571/; classtype:trojan-activity;sid:84768671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.232.49.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905570/; classtype:trojan-activity;sid:84768670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.210.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905569/; classtype:trojan-activity;sid:84768669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.205.0.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905568/; classtype:trojan-activity;sid:84768668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.123.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905567/; classtype:trojan-activity;sid:84768667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.210.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905566/; classtype:trojan-activity;sid:84768666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"88.232.49.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905565/; classtype:trojan-activity;sid:84768665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/edgeupd.dat"; depth:12; endswith; nocase; http.host; content:"c2.11179669.cloud"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905563/; classtype:trojan-activity;sid:84768663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chromereal.exe"; depth:15; endswith; nocase; http.host; content:"c2.11179669.cloud"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905564/; classtype:trojan-activity;sid:84768664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.159.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905562/; classtype:trojan-activity;sid:84768662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.x86"; depth:14; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905560/; classtype:trojan-activity;sid:84768660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/chud.mips"; depth:15; endswith; nocase; http.host; content:"18.236.12.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905561/; classtype:trojan-activity;sid:84768661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_6a286233562894b3.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905559/; classtype:trojan-activity;sid:84768659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"112.74.47.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905558/; classtype:trojan-activity;sid:84768658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg11"; depth:5; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905557/; classtype:trojan-activity;sid:84768657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getit.exe"; depth:10; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905556/; classtype:trojan-activity;sid:84768656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_sh4"; depth:10; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905544/; classtype:trojan-activity;sid:84768644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_sparc"; depth:12; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905545/; classtype:trojan-activity;sid:84768645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_arm7"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905546/; classtype:trojan-activity;sid:84768646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_mips_el"; depth:14; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905547/; classtype:trojan-activity;sid:84768647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_x86_64"; depth:13; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905548/; classtype:trojan-activity;sid:84768648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_m68k"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905549/; classtype:trojan-activity;sid:84768649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_arm"; depth:10; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905550/; classtype:trojan-activity;sid:84768650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/$b"; depth:8; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905551/; classtype:trojan-activity;sid:84768651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_mips"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905552/; classtype:trojan-activity;sid:84768652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_arm6"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905553/; classtype:trojan-activity;sid:84768653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_ppc"; depth:10; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905554/; classtype:trojan-activity;sid:84768654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_00bdcc9da8206c4c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905555/; classtype:trojan-activity;sid:84768655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satan_arm5"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905543/; classtype:trojan-activity;sid:84768643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.205.0.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905542/; classtype:trojan-activity;sid:84768642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.23.123.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905541/; classtype:trojan-activity;sid:84768641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.159.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905540/; classtype:trojan-activity;sid:84768640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.169.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905539/; classtype:trojan-activity;sid:84768639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.169.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905538/; classtype:trojan-activity;sid:84768638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.253.62.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905537/; classtype:trojan-activity;sid:84768637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.190.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905536/; classtype:trojan-activity;sid:84768636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.33.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905535/; classtype:trojan-activity;sid:84768635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.190.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905534/; classtype:trojan-activity;sid:84768634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.173.72.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905533/; classtype:trojan-activity;sid:84768633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.173.72.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905532/; classtype:trojan-activity;sid:84768632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.13.149.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905531/; classtype:trojan-activity;sid:84768631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.13.149.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905530/; classtype:trojan-activity;sid:84768630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2026/updater.exe"; depth:36; endswith; nocase; http.host; content:"mitraperijinan.co.id"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905529/; classtype:trojan-activity;sid:84768629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.13.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905528/; classtype:trojan-activity;sid:84768628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.236.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905527/; classtype:trojan-activity;sid:84768627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.236.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905526/; classtype:trojan-activity;sid:84768626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.13.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905525/; classtype:trojan-activity;sid:84768625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/5046321201/8eimnj7.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905524/; classtype:trojan-activity;sid:84768624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.55.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905523/; classtype:trojan-activity;sid:84768623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.194.211.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905522/; classtype:trojan-activity;sid:84768622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.39.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905521/; classtype:trojan-activity;sid:84768621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.33.126"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905520/; classtype:trojan-activity;sid:84768620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.194.211.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905519/; classtype:trojan-activity;sid:84768619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.146.78"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905518/; classtype:trojan-activity;sid:84768618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.33.126"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905517/; classtype:trojan-activity;sid:84768617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"98.252.87.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905516/; classtype:trojan-activity;sid:84768616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.mipsel"; depth:12; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905515/; classtype:trojan-activity;sid:84768615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.i486"; depth:10; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905502/; classtype:trojan-activity;sid:84768602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.i686"; depth:10; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905503/; classtype:trojan-activity;sid:84768603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm5"; depth:10; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905504/; classtype:trojan-activity;sid:84768604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.mips"; depth:10; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905505/; classtype:trojan-activity;sid:84768605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm7"; depth:10; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905506/; classtype:trojan-activity;sid:84768606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.m68k"; depth:10; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905507/; classtype:trojan-activity;sid:84768607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm6"; depth:10; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905508/; classtype:trojan-activity;sid:84768608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.sh4"; depth:9; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905509/; classtype:trojan-activity;sid:84768609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.x86"; depth:9; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905510/; classtype:trojan-activity;sid:84768610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.ppc"; depth:9; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905511/; classtype:trojan-activity;sid:84768611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm4"; depth:10; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905512/; classtype:trojan-activity;sid:84768612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.sparc"; depth:11; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905513/; classtype:trojan-activity;sid:84768613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.ppc440"; depth:12; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905514/; classtype:trojan-activity;sid:84768614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.x64"; depth:9; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905500/; classtype:trojan-activity;sid:84768600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dp.sh"; depth:6; endswith; nocase; http.host; content:"194.238.57.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905501/; classtype:trojan-activity;sid:84768601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/5046321201/2k4xfeq.bat"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905499/; classtype:trojan-activity;sid:84768599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.165.96.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905498/; classtype:trojan-activity;sid:84768598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.26.210.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905497/; classtype:trojan-activity;sid:84768597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.38.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905496/; classtype:trojan-activity;sid:84768596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"98.252.87.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905495/; classtype:trojan-activity;sid:84768595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.165.96.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905494/; classtype:trojan-activity;sid:84768594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.38.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905493/; classtype:trojan-activity;sid:84768593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905492/; classtype:trojan-activity;sid:84768592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.26.210.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905491/; classtype:trojan-activity;sid:84768591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.146.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905490/; classtype:trojan-activity;sid:84768590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.139.34.163"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905489/; classtype:trojan-activity;sid:84768589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.34.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905488/; classtype:trojan-activity;sid:84768588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.192.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905487/; classtype:trojan-activity;sid:84768587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905486/; classtype:trojan-activity;sid:84768586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.46.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905485/; classtype:trojan-activity;sid:84768585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.129.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905484/; classtype:trojan-activity;sid:84768584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.139.34.163"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905483/; classtype:trojan-activity;sid:84768583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.23.192.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905482/; classtype:trojan-activity;sid:84768582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905481/; classtype:trojan-activity;sid:84768581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"31.77.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905480/; classtype:trojan-activity;sid:84768580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.186.228.173"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905479/; classtype:trojan-activity;sid:84768579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.245.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905478/; classtype:trojan-activity;sid:84768578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.245.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905477/; classtype:trojan-activity;sid:84768577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.36.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905476/; classtype:trojan-activity;sid:84768576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.48.159"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905475/; classtype:trojan-activity;sid:84768575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.186.228.173"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905474/; classtype:trojan-activity;sid:84768574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.22.195.207"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905473/; classtype:trojan-activity;sid:84768573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.36.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905472/; classtype:trojan-activity;sid:84768572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.183.51.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905471/; classtype:trojan-activity;sid:84768571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nmm/a"; depth:6; endswith; nocase; http.host; content:"178.16.55.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905470/; classtype:trojan-activity;sid:84768570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.132.108"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905469/; classtype:trojan-activity;sid:84768569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.34.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905468/; classtype:trojan-activity;sid:84768568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.19.212.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905467/; classtype:trojan-activity;sid:84768567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.53.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905466/; classtype:trojan-activity;sid:84768566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.34.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905465/; classtype:trojan-activity;sid:84768565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.82.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905464/; classtype:trojan-activity;sid:84768564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.107.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905463/; classtype:trojan-activity;sid:84768563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.162.214.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905462/; classtype:trojan-activity;sid:84768562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.53.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905461/; classtype:trojan-activity;sid:84768561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.82.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905460/; classtype:trojan-activity;sid:84768560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.55.107.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905459/; classtype:trojan-activity;sid:84768559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905458/; classtype:trojan-activity;sid:84768558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.6.168.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905457/; classtype:trojan-activity;sid:84768557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a"; depth:2; endswith; nocase; http.host; content:"178.16.55.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905456/; classtype:trojan-activity;sid:84768556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.46.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905455/; classtype:trojan-activity;sid:84768555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.133.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905454/; classtype:trojan-activity;sid:84768554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nm/a"; depth:5; endswith; nocase; http.host; content:"178.16.55.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905453/; classtype:trojan-activity;sid:84768553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.239.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905452/; classtype:trojan-activity;sid:84768552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.23.239.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905451/; classtype:trojan-activity;sid:84768551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.7.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905450/; classtype:trojan-activity;sid:84768550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.160.130.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905449/; classtype:trojan-activity;sid:84768549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"85.12.251.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905448/; classtype:trojan-activity;sid:84768548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.160.130.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905447/; classtype:trojan-activity;sid:84768547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.16.150.139"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905446/; classtype:trojan-activity;sid:84768546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"85.12.251.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905445/; classtype:trojan-activity;sid:84768545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.16.150.139"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905444/; classtype:trojan-activity;sid:84768544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.252.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905443/; classtype:trojan-activity;sid:84768543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.110.38.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905442/; classtype:trojan-activity;sid:84768542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.107.171"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905441/; classtype:trojan-activity;sid:84768541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"81.227.43.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905440/; classtype:trojan-activity;sid:84768540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.215.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905439/; classtype:trojan-activity;sid:84768539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.sh4"; depth:12; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905435/; classtype:trojan-activity;sid:84768535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.i586"; depth:13; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905436/; classtype:trojan-activity;sid:84768536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.m68k"; depth:13; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905437/; classtype:trojan-activity;sid:84768537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv6l"; depth:15; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905438/; classtype:trojan-activity;sid:84768538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.mipsel"; depth:15; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905432/; classtype:trojan-activity;sid:84768532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv5l"; depth:15; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905433/; classtype:trojan-activity;sid:84768533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv7l"; depth:15; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905434/; classtype:trojan-activity;sid:84768534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.mips"; depth:13; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905431/; classtype:trojan-activity;sid:84768531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.i686"; depth:13; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905427/; classtype:trojan-activity;sid:84768527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv4l"; depth:15; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905428/; classtype:trojan-activity;sid:84768528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.powerpc"; depth:16; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905429/; classtype:trojan-activity;sid:84768529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.x86_64"; depth:15; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905430/; classtype:trojan-activity;sid:84768530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.sh"; depth:11; endswith; nocase; http.host; content:"176.65.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905426/; classtype:trojan-activity;sid:84768526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905415/; classtype:trojan-activity;sid:84768515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905416/; classtype:trojan-activity;sid:84768516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905417/; classtype:trojan-activity;sid:84768517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905418/; classtype:trojan-activity;sid:84768518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905419/; classtype:trojan-activity;sid:84768519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905420/; classtype:trojan-activity;sid:84768520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905421/; classtype:trojan-activity;sid:84768521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mipsel"; depth:12; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905422/; classtype:trojan-activity;sid:84768522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905423/; classtype:trojan-activity;sid:84768523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905424/; classtype:trojan-activity;sid:84768524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905425/; classtype:trojan-activity;sid:84768525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905414/; classtype:trojan-activity;sid:84768514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"176.65.139.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905413/; classtype:trojan-activity;sid:84768513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wed/crypted.ps1"; depth:16; endswith; nocase; http.host; content:"198.23.144.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905412/; classtype:trojan-activity;sid:84768512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/40/verygoodpersonwithbestenergycandlekingsformebest.vbe"; depth:56; endswith; nocase; http.host; content:"198.23.144.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905411/; classtype:trojan-activity;sid:84768511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.159.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905410/; classtype:trojan-activity;sid:84768510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.sh"; depth:5; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905409/; classtype:trojan-activity;sid:84768509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.sh"; depth:5; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905407/; classtype:trojan-activity;sid:84768507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.sh"; depth:5; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905408/; classtype:trojan-activity;sid:84768508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.233.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905406/; classtype:trojan-activity;sid:84768506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.233.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905405/; classtype:trojan-activity;sid:84768505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.253.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905404/; classtype:trojan-activity;sid:84768504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.6.252.211"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905403/; classtype:trojan-activity;sid:84768503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.163.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905402/; classtype:trojan-activity;sid:84768502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.54.159.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905401/; classtype:trojan-activity;sid:84768501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905400/; classtype:trojan-activity;sid:84768500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telnet.sh"; depth:10; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905399/; classtype:trojan-activity;sid:84768499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905398/; classtype:trojan-activity;sid:84768498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905390/; classtype:trojan-activity;sid:84768490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905391/; classtype:trojan-activity;sid:84768491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905392/; classtype:trojan-activity;sid:84768492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905393/; classtype:trojan-activity;sid:84768493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905394/; classtype:trojan-activity;sid:84768494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905395/; classtype:trojan-activity;sid:84768495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905396/; classtype:trojan-activity;sid:84768496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsrouter"; depth:16; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905397/; classtype:trojan-activity;sid:84768497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905389/; classtype:trojan-activity;sid:84768489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905388/; classtype:trojan-activity;sid:84768488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.154.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905387/; classtype:trojan-activity;sid:84768487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5770984c4235c5b0.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905386/; classtype:trojan-activity;sid:84768486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.7.exe"; depth:8; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905385/; classtype:trojan-activity;sid:84768485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.6.252.211"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905384/; classtype:trojan-activity;sid:84768484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.7.222.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905383/; classtype:trojan-activity;sid:84768483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.163.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905382/; classtype:trojan-activity;sid:84768482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905381/; classtype:trojan-activity;sid:84768481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.spc"; depth:9; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905378/; classtype:trojan-activity;sid:84768478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mpsl"; depth:10; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905379/; classtype:trojan-activity;sid:84768479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905380/; classtype:trojan-activity;sid:84768480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905374/; classtype:trojan-activity;sid:84768474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905375/; classtype:trojan-activity;sid:84768475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905376/; classtype:trojan-activity;sid:84768476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905377/; classtype:trojan-activity;sid:84768477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905371/; classtype:trojan-activity;sid:84768471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905372/; classtype:trojan-activity;sid:84768472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905373/; classtype:trojan-activity;sid:84768473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.7.222.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905370/; classtype:trojan-activity;sid:84768470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.253.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905369/; classtype:trojan-activity;sid:84768469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b2f628/cronb.sh"; depth:16; endswith; nocase; http.host; content:"209.141.58.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905366/; classtype:trojan-activity;sid:84768466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b2f628/cronb.sh"; depth:16; endswith; nocase; http.host; content:"140.99.32.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905367/; classtype:trojan-activity;sid:84768467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s.ps1"; depth:6; endswith; nocase; http.host; content:"167.172.167.65"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905368/; classtype:trojan-activity;sid:84768468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_49f73ea936886e59.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905365/; classtype:trojan-activity;sid:84768465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/kliulij.exe"; depth:24; endswith; nocase; http.host; content:"cryptomeshforge10.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905364/; classtype:trojan-activity;sid:84768464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vkxen"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905362/; classtype:trojan-activity;sid:84768462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clp4.exe"; depth:9; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905363/; classtype:trojan-activity;sid:84768463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905360/; classtype:trojan-activity;sid:84768460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/topinmsi.png"; depth:13; endswith; nocase; http.host; content:"217.217.97.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905361/; classtype:trojan-activity;sid:84768461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905358/; classtype:trojan-activity;sid:84768458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905359/; classtype:trojan-activity;sid:84768459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.123.40.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905357/; classtype:trojan-activity;sid:84768457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.216.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905356/; classtype:trojan-activity;sid:84768456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.249.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905355/; classtype:trojan-activity;sid:84768455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"138.204.196.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905354/; classtype:trojan-activity;sid:84768454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.216.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905353/; classtype:trojan-activity;sid:84768453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.133.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905352/; classtype:trojan-activity;sid:84768452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"138.204.196.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905351/; classtype:trojan-activity;sid:84768451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.228.109.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905350/; classtype:trojan-activity;sid:84768450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.mpsl"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905349/; classtype:trojan-activity;sid:84768449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm4"; depth:10; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905348/; classtype:trojan-activity;sid:84768448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm64"; depth:11; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905347/; classtype:trojan-activity;sid:84768447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mips"; depth:10; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905336/; classtype:trojan-activity;sid:84768436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.ppc"; depth:9; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905337/; classtype:trojan-activity;sid:84768437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905338/; classtype:trojan-activity;sid:84768438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.ppc440fp"; depth:14; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905339/; classtype:trojan-activity;sid:84768439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mipsel"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905340/; classtype:trojan-activity;sid:84768440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905341/; classtype:trojan-activity;sid:84768441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm64"; depth:6; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905342/; classtype:trojan-activity;sid:84768442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mips64"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905343/; classtype:trojan-activity;sid:84768443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mpsl"; depth:10; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905344/; classtype:trojan-activity;sid:84768444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.powerpc"; depth:13; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905345/; classtype:trojan-activity;sid:84768445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.aarch64"; depth:13; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905346/; classtype:trojan-activity;sid:84768446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905311/; classtype:trojan-activity;sid:84768411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm4n"; depth:11; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905312/; classtype:trojan-activity;sid:84768412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv7l"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905313/; classtype:trojan-activity;sid:84768413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv6l"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905314/; classtype:trojan-activity;sid:84768414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.arm5"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905315/; classtype:trojan-activity;sid:84768415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905316/; classtype:trojan-activity;sid:84768416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm7"; depth:10; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905317/; classtype:trojan-activity;sid:84768417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.arm6"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905318/; classtype:trojan-activity;sid:84768418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm6"; depth:10; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905319/; classtype:trojan-activity;sid:84768419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv7"; depth:11; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905320/; classtype:trojan-activity;sid:84768420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905321/; classtype:trojan-activity;sid:84768421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm5"; depth:10; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905322/; classtype:trojan-activity;sid:84768422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.x86"; depth:9; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905323/; classtype:trojan-activity;sid:84768423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.arm64"; depth:13; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905324/; classtype:trojan-activity;sid:84768424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm6n"; depth:11; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905325/; classtype:trojan-activity;sid:84768425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.x86"; depth:11; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905326/; classtype:trojan-activity;sid:84768426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm7n"; depth:11; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905327/; classtype:trojan-activity;sid:84768427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv4l"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905328/; classtype:trojan-activity;sid:84768428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.arm7"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905329/; classtype:trojan-activity;sid:84768429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv5l"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905330/; classtype:trojan-activity;sid:84768430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.arm"; depth:11; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905331/; classtype:trojan-activity;sid:84768431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.mips"; depth:12; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905332/; classtype:trojan-activity;sid:84768432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm"; depth:9; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905333/; classtype:trojan-activity;sid:84768433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm5n"; depth:11; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905334/; classtype:trojan-activity;sid:84768434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905335/; classtype:trojan-activity;sid:84768435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vitek"; depth:6; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905310/; classtype:trojan-activity;sid:84768410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hik"; depth:4; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905308/; classtype:trojan-activity;sid:84768408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gpon"; depth:5; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905309/; classtype:trojan-activity;sid:84768409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.133.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905307/; classtype:trojan-activity;sid:84768407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.246.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905306/; classtype:trojan-activity;sid:84768406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/dlr.sh"; depth:20; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905305/; classtype:trojan-activity;sid:84768405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_31ea8e1c01e0e0f4.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905304/; classtype:trojan-activity;sid:84768404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.86.155.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905303/; classtype:trojan-activity;sid:84768403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.arc"; depth:20; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905302/; classtype:trojan-activity;sid:84768402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.i686"; depth:21; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905301/; classtype:trojan-activity;sid:84768401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.86.155.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905300/; classtype:trojan-activity;sid:84768400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.26.83.196"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905299/; classtype:trojan-activity;sid:84768399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.231.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905298/; classtype:trojan-activity;sid:84768398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.135.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905297/; classtype:trojan-activity;sid:84768397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.22.193.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905296/; classtype:trojan-activity;sid:84768396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.231.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905295/; classtype:trojan-activity;sid:84768395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.135.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905294/; classtype:trojan-activity;sid:84768394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.242.56.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905293/; classtype:trojan-activity;sid:84768393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905292/; classtype:trojan-activity;sid:84768392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.149.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905291/; classtype:trojan-activity;sid:84768391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.213.168"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905290/; classtype:trojan-activity;sid:84768390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.163.247.38"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905289/; classtype:trojan-activity;sid:84768389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.163.247.38"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905288/; classtype:trojan-activity;sid:84768388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.223.143.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905287/; classtype:trojan-activity;sid:84768387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905286/; classtype:trojan-activity;sid:84768386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"38.46.30.224"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905285/; classtype:trojan-activity;sid:84768385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.149.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905284/; classtype:trojan-activity;sid:84768384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.22.193.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905283/; classtype:trojan-activity;sid:84768383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.16.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905282/; classtype:trojan-activity;sid:84768382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.213.168"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905281/; classtype:trojan-activity;sid:84768381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.175.205.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905280/; classtype:trojan-activity;sid:84768380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.116.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905279/; classtype:trojan-activity;sid:84768379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.240.9.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905278/; classtype:trojan-activity;sid:84768378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905277/; classtype:trojan-activity;sid:84768377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.69.85.225"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905276/; classtype:trojan-activity;sid:84768376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.112.59.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905274/; classtype:trojan-activity;sid:84768374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.116.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905275/; classtype:trojan-activity;sid:84768375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.190.18.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905272/; classtype:trojan-activity;sid:84768372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905273/; classtype:trojan-activity;sid:84768373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.114.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905266/; classtype:trojan-activity;sid:84768366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905267/; classtype:trojan-activity;sid:84768367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.207.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905268/; classtype:trojan-activity;sid:84768368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.180.35"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905269/; classtype:trojan-activity;sid:84768369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.207.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905270/; classtype:trojan-activity;sid:84768370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905271/; classtype:trojan-activity;sid:84768371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.167.86.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905253/; classtype:trojan-activity;sid:84768353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.248.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905254/; classtype:trojan-activity;sid:84768354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.242.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905255/; classtype:trojan-activity;sid:84768355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"92.124.120.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905256/; classtype:trojan-activity;sid:84768356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.43.35"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905257/; classtype:trojan-activity;sid:84768357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.245.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905258/; classtype:trojan-activity;sid:84768358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.250.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905259/; classtype:trojan-activity;sid:84768359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.72.43.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905260/; classtype:trojan-activity;sid:84768360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905261/; classtype:trojan-activity;sid:84768361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.167.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905262/; classtype:trojan-activity;sid:84768362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.144.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905263/; classtype:trojan-activity;sid:84768363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905264/; classtype:trojan-activity;sid:84768364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.97.89.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905265/; classtype:trojan-activity;sid:84768365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.150.168"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905252/; classtype:trojan-activity;sid:84768352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.173.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905240/; classtype:trojan-activity;sid:84768340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.55.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905241/; classtype:trojan-activity;sid:84768341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.245.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905242/; classtype:trojan-activity;sid:84768342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.250.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905243/; classtype:trojan-activity;sid:84768343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.252.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905244/; classtype:trojan-activity;sid:84768344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.229.134"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905245/; classtype:trojan-activity;sid:84768345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.97.89.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905246/; classtype:trojan-activity;sid:84768346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.153.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905247/; classtype:trojan-activity;sid:84768347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.245.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905248/; classtype:trojan-activity;sid:84768348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.167.86.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905249/; classtype:trojan-activity;sid:84768349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.252.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905250/; classtype:trojan-activity;sid:84768350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.182.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905251/; classtype:trojan-activity;sid:84768351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.198.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905221/; classtype:trojan-activity;sid:84768321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.145.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905222/; classtype:trojan-activity;sid:84768322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.226.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905223/; classtype:trojan-activity;sid:84768323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"81.227.43.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905224/; classtype:trojan-activity;sid:84768324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.165.187.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905225/; classtype:trojan-activity;sid:84768325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"189.7.90.15"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905226/; classtype:trojan-activity;sid:84768326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"41.201.226.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905227/; classtype:trojan-activity;sid:84768327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.43.35"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905228/; classtype:trojan-activity;sid:84768328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.209.143"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905229/; classtype:trojan-activity;sid:84768329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.224.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905230/; classtype:trojan-activity;sid:84768330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.236.118.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905231/; classtype:trojan-activity;sid:84768331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.191.230.61"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905232/; classtype:trojan-activity;sid:84768332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.104.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905233/; classtype:trojan-activity;sid:84768333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.209.143"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905234/; classtype:trojan-activity;sid:84768334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.85.51.157"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905235/; classtype:trojan-activity;sid:84768335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.55.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905236/; classtype:trojan-activity;sid:84768336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.230.61"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905237/; classtype:trojan-activity;sid:84768337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.151.74.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905238/; classtype:trojan-activity;sid:84768338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.22.195.207"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905239/; classtype:trojan-activity;sid:84768339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.202.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905219/; classtype:trojan-activity;sid:84768319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.59.109.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905220/; classtype:trojan-activity;sid:84768320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.219.0"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905217/; classtype:trojan-activity;sid:84768317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.44.245"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905218/; classtype:trojan-activity;sid:84768318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.98.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905216/; classtype:trojan-activity;sid:84768316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.13.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905208/; classtype:trojan-activity;sid:84768308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.198.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905209/; classtype:trojan-activity;sid:84768309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.132.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905210/; classtype:trojan-activity;sid:84768310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.224.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905211/; classtype:trojan-activity;sid:84768311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.132.108"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905212/; classtype:trojan-activity;sid:84768312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.101.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905213/; classtype:trojan-activity;sid:84768313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.118.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905214/; classtype:trojan-activity;sid:84768314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.232.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905215/; classtype:trojan-activity;sid:84768315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"92.124.120.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905181/; classtype:trojan-activity;sid:84768281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.81.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905182/; classtype:trojan-activity;sid:84768282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.194.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905183/; classtype:trojan-activity;sid:84768283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.172.77.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905184/; classtype:trojan-activity;sid:84768284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.20.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905185/; classtype:trojan-activity;sid:84768285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.44.245"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905186/; classtype:trojan-activity;sid:84768286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.104.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905187/; classtype:trojan-activity;sid:84768287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.80.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905188/; classtype:trojan-activity;sid:84768288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.157.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905189/; classtype:trojan-activity;sid:84768289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.120.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905190/; classtype:trojan-activity;sid:84768290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905191/; classtype:trojan-activity;sid:84768291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905192/; classtype:trojan-activity;sid:84768292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.85.51.157"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905193/; classtype:trojan-activity;sid:84768293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.106.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905194/; classtype:trojan-activity;sid:84768294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.106.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905195/; classtype:trojan-activity;sid:84768295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.197.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905196/; classtype:trojan-activity;sid:84768296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.72.43.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905197/; classtype:trojan-activity;sid:84768297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.199.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905198/; classtype:trojan-activity;sid:84768298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.199.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905199/; classtype:trojan-activity;sid:84768299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.90.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905200/; classtype:trojan-activity;sid:84768300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.13.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905201/; classtype:trojan-activity;sid:84768301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.245.135.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905202/; classtype:trojan-activity;sid:84768302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.226.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905203/; classtype:trojan-activity;sid:84768303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.213.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905204/; classtype:trojan-activity;sid:84768304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"189.7.90.15"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905205/; classtype:trojan-activity;sid:84768305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.43.84.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905206/; classtype:trojan-activity;sid:84768306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.223.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905207/; classtype:trojan-activity;sid:84768307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.144.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905178/; classtype:trojan-activity;sid:84768278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.197.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905179/; classtype:trojan-activity;sid:84768279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.195.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905180/; classtype:trojan-activity;sid:84768280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.3.106"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905177/; classtype:trojan-activity;sid:84768277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.168.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905176/; classtype:trojan-activity;sid:84768276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.232.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905175/; classtype:trojan-activity;sid:84768275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"38.46.30.224"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905174/; classtype:trojan-activity;sid:84768274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.16.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905173/; classtype:trojan-activity;sid:84768273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.213.139.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905172/; classtype:trojan-activity;sid:84768272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/gpon.sh"; depth:13; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905170/; classtype:trojan-activity;sid:84768270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/react2shell.sh"; depth:20; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905171/; classtype:trojan-activity;sid:84768271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.68.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905169/; classtype:trojan-activity;sid:84768269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.225.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905168/; classtype:trojan-activity;sid:84768268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fdab9755.exe"; depth:13; endswith; nocase; http.host; content:"qorvi.pro"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905167/; classtype:trojan-activity;sid:84768267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips.sh"; depth:8; endswith; nocase; http.host; content:"103.77.246.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905165/; classtype:trojan-activity;sid:84768265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl/2h0w4vtm7c/7b4cckfhojxjbrcjon.json"; depth:40; endswith; nocase; http.host; content:"quill-flint.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905166/; classtype:trojan-activity;sid:84768266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.34.109.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905164/; classtype:trojan-activity;sid:84768264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.225.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905163/; classtype:trojan-activity;sid:84768263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.104.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905162/; classtype:trojan-activity;sid:84768262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.104.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905161/; classtype:trojan-activity;sid:84768261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.34.109.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905160/; classtype:trojan-activity;sid:84768260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.219.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905159/; classtype:trojan-activity;sid:84768259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.195.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905158/; classtype:trojan-activity;sid:84768258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.54.31.40"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905157/; classtype:trojan-activity;sid:84768257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.54.31.40"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905156/; classtype:trojan-activity;sid:84768256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.69.200"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905155/; classtype:trojan-activity;sid:84768255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.115.102.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905154/; classtype:trojan-activity;sid:84768254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905153/; classtype:trojan-activity;sid:84768253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.132.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905152/; classtype:trojan-activity;sid:84768252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"200.115.102.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905151/; classtype:trojan-activity;sid:84768251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.98.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905150/; classtype:trojan-activity;sid:84768250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.208.42.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905149/; classtype:trojan-activity;sid:84768249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.208.42.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905148/; classtype:trojan-activity;sid:84768248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.2.60.14"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905147/; classtype:trojan-activity;sid:84768247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905146/; classtype:trojan-activity;sid:84768246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.22.127"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905145/; classtype:trojan-activity;sid:84768245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.36.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905144/; classtype:trojan-activity;sid:84768244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.104.173"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905143/; classtype:trojan-activity;sid:84768243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.7.9"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905142/; classtype:trojan-activity;sid:84768242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.107.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905141/; classtype:trojan-activity;sid:84768241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.147.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905140/; classtype:trojan-activity;sid:84768240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.201.163.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905139/; classtype:trojan-activity;sid:84768239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zyemb6slon_3vwvlkskdijurcyhy5cfntchnavrnmgu/jetbrains/update"; depth:61; endswith; nocase; http.host; content:"quill-flint.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905138/; classtype:trojan-activity;sid:84768238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.107.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905136/; classtype:trojan-activity;sid:84768236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.104.173"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905137/; classtype:trojan-activity;sid:84768237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unifi"; depth:6; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905135/; classtype:trojan-activity;sid:84768235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.48.159"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905134/; classtype:trojan-activity;sid:84768234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.7.9"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905133/; classtype:trojan-activity;sid:84768233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.137.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905132/; classtype:trojan-activity;sid:84768232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.243.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905131/; classtype:trojan-activity;sid:84768231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.137.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905130/; classtype:trojan-activity;sid:84768230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.2.60.14"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905129/; classtype:trojan-activity;sid:84768229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.73.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905128/; classtype:trojan-activity;sid:84768228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905126/; classtype:trojan-activity;sid:84768226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905127/; classtype:trojan-activity;sid:84768227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905125/; classtype:trojan-activity;sid:84768225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905122/; classtype:trojan-activity;sid:84768222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905123/; classtype:trojan-activity;sid:84768223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905124/; classtype:trojan-activity;sid:84768224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905120/; classtype:trojan-activity;sid:84768220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905121/; classtype:trojan-activity;sid:84768221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905118/; classtype:trojan-activity;sid:84768218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905119/; classtype:trojan-activity;sid:84768219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905116/; classtype:trojan-activity;sid:84768216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905117/; classtype:trojan-activity;sid:84768217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905115/; classtype:trojan-activity;sid:84768215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.mips"; depth:21; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905113/; classtype:trojan-activity;sid:84768213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.arm6"; depth:21; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905114/; classtype:trojan-activity;sid:84768214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.ppc"; depth:20; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905112/; classtype:trojan-activity;sid:84768212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.x86"; depth:20; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905111/; classtype:trojan-activity;sid:84768211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.sh4"; depth:20; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905109/; classtype:trojan-activity;sid:84768209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.mpsl"; depth:21; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905110/; classtype:trojan-activity;sid:84768210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.arm"; depth:20; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905103/; classtype:trojan-activity;sid:84768203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.arm7"; depth:21; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905104/; classtype:trojan-activity;sid:84768204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.x86_64"; depth:23; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905105/; classtype:trojan-activity;sid:84768205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.arm5"; depth:21; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905106/; classtype:trojan-activity;sid:84768206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.m68k"; depth:21; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905107/; classtype:trojan-activity;sid:84768207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/space.spc"; depth:20; endswith; nocase; http.host; content:"37.49.230.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905108/; classtype:trojan-activity;sid:84768208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.arm7"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905102/; classtype:trojan-activity;sid:84768202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.m68k"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905101/; classtype:trojan-activity;sid:84768201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.arm5"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905095/; classtype:trojan-activity;sid:84768195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.sh4"; depth:25; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905096/; classtype:trojan-activity;sid:84768196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.mpsl"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905097/; classtype:trojan-activity;sid:84768197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.ppc"; depth:25; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905098/; classtype:trojan-activity;sid:84768198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.spc"; depth:25; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905099/; classtype:trojan-activity;sid:84768199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.arm6"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905100/; classtype:trojan-activity;sid:84768200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.243.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905094/; classtype:trojan-activity;sid:84768194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huawei"; depth:7; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905093/; classtype:trojan-activity;sid:84768193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telegram_v12.8.3.apk"; depth:21; endswith; nocase; http.host; content:"app.faster-cdn-hk.click"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905092/; classtype:trojan-activity;sid:84768192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5607a34d16e59914.cmd"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905090/; classtype:trojan-activity;sid:84768190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cabin/diocle.emz"; depth:17; endswith; nocase; http.host; content:"bserail.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905091/; classtype:trojan-activity;sid:84768191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/bin.exe"; depth:19; endswith; nocase; http.host; content:"www.mixierealty.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905089/; classtype:trojan-activity;sid:84768189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_1d2e34021664fd28.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905087/; classtype:trojan-activity;sid:84768187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_27fd3a19e4e1e1b6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905088/; classtype:trojan-activity;sid:84768188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.38.203.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905086/; classtype:trojan-activity;sid:84768186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2026/ovdbot.exe"; depth:35; endswith; nocase; http.host; content:"brandtinoda.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905085/; classtype:trojan-activity;sid:84768185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905084/; classtype:trojan-activity;sid:84768184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.239.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905083/; classtype:trojan-activity;sid:84768183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.179.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905082/; classtype:trojan-activity;sid:84768182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.179.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905081/; classtype:trojan-activity;sid:84768181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.119.188"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905080/; classtype:trojan-activity;sid:84768180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.34.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905079/; classtype:trojan-activity;sid:84768179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.72.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905078/; classtype:trojan-activity;sid:84768178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905077/; classtype:trojan-activity;sid:84768177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.72.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905076/; classtype:trojan-activity;sid:84768176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.8.180"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905075/; classtype:trojan-activity;sid:84768175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.8.180"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905074/; classtype:trojan-activity;sid:84768174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.156.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905073/; classtype:trojan-activity;sid:84768173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.76.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905072/; classtype:trojan-activity;sid:84768172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905071/; classtype:trojan-activity;sid:84768171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.146.92.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905070/; classtype:trojan-activity;sid:84768170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/services.apk"; depth:13; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905069/; classtype:trojan-activity;sid:84768169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.190.85.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905068/; classtype:trojan-activity;sid:84768168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905065/; classtype:trojan-activity;sid:84768165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905066/; classtype:trojan-activity;sid:84768166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905067/; classtype:trojan-activity;sid:84768167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905052/; classtype:trojan-activity;sid:84768152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905053/; classtype:trojan-activity;sid:84768153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905054/; classtype:trojan-activity;sid:84768154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/persist.arm7"; depth:13; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905055/; classtype:trojan-activity;sid:84768155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905056/; classtype:trojan-activity;sid:84768156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905057/; classtype:trojan-activity;sid:84768157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905058/; classtype:trojan-activity;sid:84768158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905059/; classtype:trojan-activity;sid:84768159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905060/; classtype:trojan-activity;sid:84768160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pay.xml"; depth:8; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905061/; classtype:trojan-activity;sid:84768161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905062/; classtype:trojan-activity;sid:84768162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905063/; classtype:trojan-activity;sid:84768163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"45.133.74.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905064/; classtype:trojan-activity;sid:84768164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.195.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905051/; classtype:trojan-activity;sid:84768151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.190.85.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905050/; classtype:trojan-activity;sid:84768150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.150.250.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905049/; classtype:trojan-activity;sid:84768149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tispciphraloader.exe"; depth:21; endswith; nocase; http.host; content:"thu-iphone-07.cfd"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905048/; classtype:trojan-activity;sid:84768148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.68.136"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905047/; classtype:trojan-activity;sid:84768147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.150.250.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905046/; classtype:trojan-activity;sid:84768146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.38.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905045/; classtype:trojan-activity;sid:84768145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.197.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905044/; classtype:trojan-activity;sid:84768144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.197.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905043/; classtype:trojan-activity;sid:84768143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.154.116"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905042/; classtype:trojan-activity;sid:84768142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.6.168.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905041/; classtype:trojan-activity;sid:84768141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.154.116"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905040/; classtype:trojan-activity;sid:84768140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.178.134"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905039/; classtype:trojan-activity;sid:84768139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_952a4ed2428c675f.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905038/; classtype:trojan-activity;sid:84768138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.178.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905037/; classtype:trojan-activity;sid:84768137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.150.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905036/; classtype:trojan-activity;sid:84768136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.167.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905035/; classtype:trojan-activity;sid:84768135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"179.108.89.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905034/; classtype:trojan-activity;sid:84768134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.204.195.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905033/; classtype:trojan-activity;sid:84768133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.62.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905031/; classtype:trojan-activity;sid:84768131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.62.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905032/; classtype:trojan-activity;sid:84768132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.204.195.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905030/; classtype:trojan-activity;sid:84768130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.84.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905028/; classtype:trojan-activity;sid:84768128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.84.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905029/; classtype:trojan-activity;sid:84768129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.195.76"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905027/; classtype:trojan-activity;sid:84768127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"179.108.89.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905026/; classtype:trojan-activity;sid:84768126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.6.146"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905025/; classtype:trojan-activity;sid:84768125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.36.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905024/; classtype:trojan-activity;sid:84768124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.101.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905023/; classtype:trojan-activity;sid:84768123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.18.25.174"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905022/; classtype:trojan-activity;sid:84768122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.83.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905021/; classtype:trojan-activity;sid:84768121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.6.146"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905020/; classtype:trojan-activity;sid:84768120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.83.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905019/; classtype:trojan-activity;sid:84768119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.36.197.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905018/; classtype:trojan-activity;sid:84768118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/y"; depth:2; endswith; nocase; http.host; content:"154.90.70.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905017/; classtype:trojan-activity;sid:84768117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.25.174"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905016/; classtype:trojan-activity;sid:84768116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.76.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905015/; classtype:trojan-activity;sid:84768115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.189.139.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905014/; classtype:trojan-activity;sid:84768114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/8714097194/vicvgdl.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905013/; classtype:trojan-activity;sid:84768113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.52.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905012/; classtype:trojan-activity;sid:84768112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.51"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905011/; classtype:trojan-activity;sid:84768111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.150.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905010/; classtype:trojan-activity;sid:84768110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.218.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905009/; classtype:trojan-activity;sid:84768109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"14.188.143.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905008/; classtype:trojan-activity;sid:84768108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.52.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905007/; classtype:trojan-activity;sid:84768107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.189.139.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905006/; classtype:trojan-activity;sid:84768106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.51"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905005/; classtype:trojan-activity;sid:84768105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.122.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905004/; classtype:trojan-activity;sid:84768104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.191.122.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905003/; classtype:trojan-activity;sid:84768103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/cl1786993325592.exe"; depth:28; endswith; nocase; http.host; content:"192.162.199.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905002/; classtype:trojan-activity;sid:84768102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/8722997249/utrrfwx.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905001/; classtype:trojan-activity;sid:84768101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.94.194.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3905000/; classtype:trojan-activity;sid:84768100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.241.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904999/; classtype:trojan-activity;sid:84768099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.30.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904998/; classtype:trojan-activity;sid:84768098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904993/; classtype:trojan-activity;sid:84768093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.i486"; depth:15; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904994/; classtype:trojan-activity;sid:84768094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.mipsrouter"; depth:21; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904995/; classtype:trojan-activity;sid:84768095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.arc"; depth:14; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904996/; classtype:trojan-activity;sid:84768096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.m68k"; depth:15; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904997/; classtype:trojan-activity;sid:84768097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.mips"; depth:15; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904987/; classtype:trojan-activity;sid:84768087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv4l"; depth:17; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904988/; classtype:trojan-activity;sid:84768088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.sparc"; depth:16; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904989/; classtype:trojan-activity;sid:84768089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv7l"; depth:17; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904990/; classtype:trojan-activity;sid:84768090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.mipsel"; depth:17; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904991/; classtype:trojan-activity;sid:84768091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.x86_64"; depth:17; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904992/; classtype:trojan-activity;sid:84768092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.sh4"; depth:14; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904986/; classtype:trojan-activity;sid:84768086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.powerpc"; depth:18; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904983/; classtype:trojan-activity;sid:84768083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv5l"; depth:17; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904984/; classtype:trojan-activity;sid:84768084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daredevil.armv6l"; depth:17; endswith; nocase; http.host; content:"176.65.139.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904985/; classtype:trojan-activity;sid:84768085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.156.24"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904982/; classtype:trojan-activity;sid:84768082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_mips"; depth:10; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904981/; classtype:trojan-activity;sid:84768081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_mpsl"; depth:10; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904980/; classtype:trojan-activity;sid:84768080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie.sh"; depth:8; endswith; nocase; http.host; content:"103.226.250.88"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904979/; classtype:trojan-activity;sid:84768079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_x86"; depth:9; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904969/; classtype:trojan-activity;sid:84768069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_arm5"; depth:10; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904970/; classtype:trojan-activity;sid:84768070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_arm"; depth:9; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904971/; classtype:trojan-activity;sid:84768071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_arm7"; depth:10; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904972/; classtype:trojan-activity;sid:84768072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_arm6"; depth:10; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904973/; classtype:trojan-activity;sid:84768073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_m68k"; depth:10; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904974/; classtype:trojan-activity;sid:84768074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_ppc"; depth:9; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904975/; classtype:trojan-activity;sid:84768075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_x86_64"; depth:12; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904976/; classtype:trojan-activity;sid:84768076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_sh4"; depth:9; endswith; nocase; http.host; content:"game.dualuoilocphu.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904977/; classtype:trojan-activity;sid:84768077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onie_sh4"; depth:9; endswith; nocase; http.host; content:"103.226.250.88"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904978/; classtype:trojan-activity;sid:84768078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.176.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904968/; classtype:trojan-activity;sid:84768068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.176.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904967/; classtype:trojan-activity;sid:84768067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.169.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904966/; classtype:trojan-activity;sid:84768066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.170.224.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904965/; classtype:trojan-activity;sid:84768065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.170.224.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904964/; classtype:trojan-activity;sid:84768064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.196.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904963/; classtype:trojan-activity;sid:84768063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.59.37.62"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904962/; classtype:trojan-activity;sid:84768062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.110.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904961/; classtype:trojan-activity;sid:84768061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.237.71.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904960/; classtype:trojan-activity;sid:84768060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.237.71.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904959/; classtype:trojan-activity;sid:84768059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.196.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904958/; classtype:trojan-activity;sid:84768058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.237.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904957/; classtype:trojan-activity;sid:84768057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/persist.arm7"; depth:13; endswith; nocase; http.host; content:"94.154.43.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904956/; classtype:trojan-activity;sid:84768056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/services.apk"; depth:13; endswith; nocase; http.host; content:"94.154.43.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904955/; classtype:trojan-activity;sid:84768055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.219.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904954/; classtype:trojan-activity;sid:84768054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.219.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904953/; classtype:trojan-activity;sid:84768053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904952/; classtype:trojan-activity;sid:84768052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904951/; classtype:trojan-activity;sid:84768051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904950/; classtype:trojan-activity;sid:84768050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904949/; classtype:trojan-activity;sid:84768049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"104.249.10.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904947/; classtype:trojan-activity;sid:84768047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904948/; classtype:trojan-activity;sid:84768048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.80.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904946/; classtype:trojan-activity;sid:84768046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904945/; classtype:trojan-activity;sid:84768045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904944/; classtype:trojan-activity;sid:84768044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904943/; classtype:trojan-activity;sid:84768043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904942/; classtype:trojan-activity;sid:84768042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"104.249.10.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904941/; classtype:trojan-activity;sid:84768041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.88.136.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904939/; classtype:trojan-activity;sid:84768039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.88.136.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904940/; classtype:trojan-activity;sid:84768040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904938/; classtype:trojan-activity;sid:84768038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904937/; classtype:trojan-activity;sid:84768037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"193.26.115.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904936/; classtype:trojan-activity;sid:84768036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"193.26.115.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904935/; classtype:trojan-activity;sid:84768035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904934/; classtype:trojan-activity;sid:84768034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904933/; classtype:trojan-activity;sid:84768033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/144.exe"; depth:8; endswith; nocase; http.host; content:"purbalinggamandiri.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904932/; classtype:trojan-activity;sid:84768032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.exe"; depth:6; endswith; nocase; http.host; content:"purbalinggamandiri.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904931/; classtype:trojan-activity;sid:84768031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zs/zs64.exe"; depth:12; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904930/; classtype:trojan-activity;sid:84768030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/get.sh"; depth:7; endswith; nocase; http.host; content:"103.77.246.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904928/; classtype:trojan-activity;sid:84768028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clp.exe"; depth:8; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904929/; classtype:trojan-activity;sid:84768029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arm6"; depth:22; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904926/; classtype:trojan-activity;sid:84768026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.mpsl"; depth:22; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904927/; classtype:trojan-activity;sid:84768027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.mips"; depth:22; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904923/; classtype:trojan-activity;sid:84768023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.i686"; depth:22; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904924/; classtype:trojan-activity;sid:84768024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.m68k"; depth:22; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904925/; classtype:trojan-activity;sid:84768025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arm"; depth:21; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904918/; classtype:trojan-activity;sid:84768018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arm7"; depth:22; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904919/; classtype:trojan-activity;sid:84768019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.ppc"; depth:21; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904920/; classtype:trojan-activity;sid:84768020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.spc"; depth:21; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904921/; classtype:trojan-activity;sid:84768021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arm5"; depth:22; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904922/; classtype:trojan-activity;sid:84768022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.x86_64"; depth:24; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904915/; classtype:trojan-activity;sid:84768015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.x86"; depth:21; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904916/; classtype:trojan-activity;sid:84768016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arc"; depth:21; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904917/; classtype:trojan-activity;sid:84768017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.sh4"; depth:21; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904914/; classtype:trojan-activity;sid:84768014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.189.155.7"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904913/; classtype:trojan-activity;sid:84768013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.165.91.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904912/; classtype:trojan-activity;sid:84768012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.157.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904911/; classtype:trojan-activity;sid:84768011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.148.157.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904910/; classtype:trojan-activity;sid:84768010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.101.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904909/; classtype:trojan-activity;sid:84768009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_eead3d0c419daff9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904908/; classtype:trojan-activity;sid:84768008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_9e042abf89f49e45.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904907/; classtype:trojan-activity;sid:84768007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_d91af7a531637b1f.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904906/; classtype:trojan-activity;sid:84768006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904905/; classtype:trojan-activity;sid:84768005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.22.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904904/; classtype:trojan-activity;sid:84768004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.8.145"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904903/; classtype:trojan-activity;sid:84768003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.72.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904902/; classtype:trojan-activity;sid:84768002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.37.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904900/; classtype:trojan-activity;sid:84768000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.53.241.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904901/; classtype:trojan-activity;sid:84768001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.8.145"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904899/; classtype:trojan-activity;sid:84767999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.54.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904898/; classtype:trojan-activity;sid:84767998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/etc.exe"; depth:8; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904897/; classtype:trojan-activity;sid:84767997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ebb368c7ee29bd5e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904896/; classtype:trojan-activity;sid:84767996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.17.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904895/; classtype:trojan-activity;sid:84767995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.226.200.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904894/; classtype:trojan-activity;sid:84767994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.226.200.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904893/; classtype:trojan-activity;sid:84767993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.164.115.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904892/; classtype:trojan-activity;sid:84767992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.15.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904891/; classtype:trojan-activity;sid:84767991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904890/; classtype:trojan-activity;sid:84767990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.89.94.52"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904889/; classtype:trojan-activity;sid:84767989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"212.164.115.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904888/; classtype:trojan-activity;sid:84767988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.89.94.52"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904887/; classtype:trojan-activity;sid:84767987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.194.25.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904886/; classtype:trojan-activity;sid:84767986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.93.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904885/; classtype:trojan-activity;sid:84767985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.194.25.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904884/; classtype:trojan-activity;sid:84767984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.168.51"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904883/; classtype:trojan-activity;sid:84767983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.75.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904882/; classtype:trojan-activity;sid:84767982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.208.46"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904881/; classtype:trojan-activity;sid:84767981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.72.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904880/; classtype:trojan-activity;sid:84767980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.75.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904879/; classtype:trojan-activity;sid:84767979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.37.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904878/; classtype:trojan-activity;sid:84767978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.174.110.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904877/; classtype:trojan-activity;sid:84767977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.212.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904876/; classtype:trojan-activity;sid:84767976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.78.26.151"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904864/; classtype:trojan-activity;sid:84767964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.253.241"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904865/; classtype:trojan-activity;sid:84767965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.66.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904866/; classtype:trojan-activity;sid:84767966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.113.101.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904867/; classtype:trojan-activity;sid:84767967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.159.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904868/; classtype:trojan-activity;sid:84767968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.212.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904869/; classtype:trojan-activity;sid:84767969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.242.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904870/; classtype:trojan-activity;sid:84767970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.66.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904871/; classtype:trojan-activity;sid:84767971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.231.77.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904872/; classtype:trojan-activity;sid:84767972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.113.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904873/; classtype:trojan-activity;sid:84767973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.242.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904874/; classtype:trojan-activity;sid:84767974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.174.110.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904875/; classtype:trojan-activity;sid:84767975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.252.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904849/; classtype:trojan-activity;sid:84767949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"84.53.221.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904850/; classtype:trojan-activity;sid:84767950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.147.94.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904851/; classtype:trojan-activity;sid:84767951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.221.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904852/; classtype:trojan-activity;sid:84767952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.221.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904853/; classtype:trojan-activity;sid:84767953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904854/; classtype:trojan-activity;sid:84767954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.255.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904855/; classtype:trojan-activity;sid:84767955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.41.95"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904856/; classtype:trojan-activity;sid:84767956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.146.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904857/; classtype:trojan-activity;sid:84767957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.110.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904858/; classtype:trojan-activity;sid:84767958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.53.155"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904859/; classtype:trojan-activity;sid:84767959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"66.212.173.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904860/; classtype:trojan-activity;sid:84767960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.192.77"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904861/; classtype:trojan-activity;sid:84767961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.238.18"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904862/; classtype:trojan-activity;sid:84767962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.204.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904863/; classtype:trojan-activity;sid:84767963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.252.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904845/; classtype:trojan-activity;sid:84767945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.238.18"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904846/; classtype:trojan-activity;sid:84767946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.159.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904847/; classtype:trojan-activity;sid:84767947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904848/; classtype:trojan-activity;sid:84767948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.80.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904844/; classtype:trojan-activity;sid:84767944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.176.10.219"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904842/; classtype:trojan-activity;sid:84767942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.0.3"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904843/; classtype:trojan-activity;sid:84767943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.118.241.162"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904841/; classtype:trojan-activity;sid:84767941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.110.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904830/; classtype:trojan-activity;sid:84767930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.87.163.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904831/; classtype:trojan-activity;sid:84767931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.26.83.196"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904832/; classtype:trojan-activity;sid:84767932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.87.163.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904833/; classtype:trojan-activity;sid:84767933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.173.224.60"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904834/; classtype:trojan-activity;sid:84767934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.144.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904835/; classtype:trojan-activity;sid:84767935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.177.11.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904836/; classtype:trojan-activity;sid:84767936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.66.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904837/; classtype:trojan-activity;sid:84767937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.66.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904838/; classtype:trojan-activity;sid:84767938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.74.117"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904839/; classtype:trojan-activity;sid:84767939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.20.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904840/; classtype:trojan-activity;sid:84767940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.157.219.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904818/; classtype:trojan-activity;sid:84767918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.118.246.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904819/; classtype:trojan-activity;sid:84767919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904820/; classtype:trojan-activity;sid:84767920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.101.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904821/; classtype:trojan-activity;sid:84767921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.78.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904822/; classtype:trojan-activity;sid:84767922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.179.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904823/; classtype:trojan-activity;sid:84767923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.6.34.92"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904824/; classtype:trojan-activity;sid:84767924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.80.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904825/; classtype:trojan-activity;sid:84767925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.30.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904826/; classtype:trojan-activity;sid:84767926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.157.219.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904827/; classtype:trojan-activity;sid:84767927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.145.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904828/; classtype:trojan-activity;sid:84767928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.173.224.60"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904829/; classtype:trojan-activity;sid:84767929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.70.226.107"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904809/; classtype:trojan-activity;sid:84767909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.227.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904810/; classtype:trojan-activity;sid:84767910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.244.13"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904811/; classtype:trojan-activity;sid:84767911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.34.223"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904812/; classtype:trojan-activity;sid:84767912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.207.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904813/; classtype:trojan-activity;sid:84767913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.113.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904814/; classtype:trojan-activity;sid:84767914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.73.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904815/; classtype:trojan-activity;sid:84767915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.119.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904816/; classtype:trojan-activity;sid:84767916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.30.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904817/; classtype:trojan-activity;sid:84767917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.34.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904807/; classtype:trojan-activity;sid:84767907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.45.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904808/; classtype:trojan-activity;sid:84767908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.113.101.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904806/; classtype:trojan-activity;sid:84767906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.86.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904794/; classtype:trojan-activity;sid:84767894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"146.158.4.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904795/; classtype:trojan-activity;sid:84767895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.235.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904796/; classtype:trojan-activity;sid:84767896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.216.179"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904797/; classtype:trojan-activity;sid:84767897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.216.179"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904798/; classtype:trojan-activity;sid:84767898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.192.77"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904799/; classtype:trojan-activity;sid:84767899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.34.223"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904800/; classtype:trojan-activity;sid:84767900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.118.24"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904801/; classtype:trojan-activity;sid:84767901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.178.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904802/; classtype:trojan-activity;sid:84767902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.131.83"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904803/; classtype:trojan-activity;sid:84767903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.42.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904804/; classtype:trojan-activity;sid:84767904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.159.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904805/; classtype:trojan-activity;sid:84767905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.161.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904772/; classtype:trojan-activity;sid:84767872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.15.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904773/; classtype:trojan-activity;sid:84767873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"72.255.30.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904774/; classtype:trojan-activity;sid:84767874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.0.3"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904775/; classtype:trojan-activity;sid:84767875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.34.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904776/; classtype:trojan-activity;sid:84767876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"84.53.221.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904777/; classtype:trojan-activity;sid:84767877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.191.34.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904778/; classtype:trojan-activity;sid:84767878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.140.186.83"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904779/; classtype:trojan-activity;sid:84767879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.161.116.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904780/; classtype:trojan-activity;sid:84767880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.117.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904781/; classtype:trojan-activity;sid:84767881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.66.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904782/; classtype:trojan-activity;sid:84767882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.3.106"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904783/; classtype:trojan-activity;sid:84767883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.34.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904784/; classtype:trojan-activity;sid:84767884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.212.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904785/; classtype:trojan-activity;sid:84767885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.255.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904786/; classtype:trojan-activity;sid:84767886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.144.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904787/; classtype:trojan-activity;sid:84767887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.119.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904788/; classtype:trojan-activity;sid:84767888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.53.20.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904789/; classtype:trojan-activity;sid:84767889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.35.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904790/; classtype:trojan-activity;sid:84767890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.59.109.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904791/; classtype:trojan-activity;sid:84767891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.21.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904792/; classtype:trojan-activity;sid:84767892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.178.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904793/; classtype:trojan-activity;sid:84767893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"156.146.26.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904771/; classtype:trojan-activity;sid:84767871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.210.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904770/; classtype:trojan-activity;sid:84767870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.11.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904769/; classtype:trojan-activity;sid:84767869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm"; depth:22; endswith; nocase; http.host; content:"38.124.152.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904764/; classtype:trojan-activity;sid:84767864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm6"; depth:23; endswith; nocase; http.host; content:"38.124.152.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904765/; classtype:trojan-activity;sid:84767865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.sh4"; depth:22; endswith; nocase; http.host; content:"38.124.152.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904766/; classtype:trojan-activity;sid:84767866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86"; depth:22; endswith; nocase; http.host; content:"38.124.152.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904767/; classtype:trojan-activity;sid:84767867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm7"; depth:23; endswith; nocase; http.host; content:"38.124.152.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904768/; classtype:trojan-activity;sid:84767868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.ppc"; depth:22; endswith; nocase; http.host; content:"38.124.152.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904761/; classtype:trojan-activity;sid:84767861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mpsl"; depth:23; endswith; nocase; http.host; content:"38.124.152.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904762/; classtype:trojan-activity;sid:84767862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arc"; depth:22; endswith; nocase; http.host; content:"38.124.152.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904763/; classtype:trojan-activity;sid:84767863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.217.35.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904760/; classtype:trojan-activity;sid:84767860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.173.101.30"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904759/; classtype:trojan-activity;sid:84767859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.196.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904758/; classtype:trojan-activity;sid:84767858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.101.187.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904757/; classtype:trojan-activity;sid:84767857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telegram_v12.8.3.apk"; depth:21; endswith; nocase; http.host; content:"dl.faster-cdn-hk.click"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904756/; classtype:trojan-activity;sid:84767856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.173.101.30"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904755/; classtype:trojan-activity;sid:84767855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.131.92.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904754/; classtype:trojan-activity;sid:84767854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.237.104.66"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904753/; classtype:trojan-activity;sid:84767853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.36.197.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904752/; classtype:trojan-activity;sid:84767852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.237.104.66"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904751/; classtype:trojan-activity;sid:84767851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.132.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904750/; classtype:trojan-activity;sid:84767850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"203.101.187.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904749/; classtype:trojan-activity;sid:84767849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.236.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904748/; classtype:trojan-activity;sid:84767848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.255.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904747/; classtype:trojan-activity;sid:84767847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader"; depth:7; endswith; nocase; http.host; content:"176.65.139.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904746/; classtype:trojan-activity;sid:84767846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"110.38.210.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904745/; classtype:trojan-activity;sid:84767845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rondo.gej.sh"; depth:13; endswith; nocase; http.host; content:"194.26.192.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904744/; classtype:trojan-activity;sid:84767844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.112.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904743/; classtype:trojan-activity;sid:84767843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.251.128"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904742/; classtype:trojan-activity;sid:84767842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/big"; depth:4; endswith; nocase; http.host; content:"timelevel12.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904741/; classtype:trojan-activity;sid:84767841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.bat"; depth:8; endswith; nocase; http.host; content:"smsechodata.cc"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904740/; classtype:trojan-activity;sid:84767840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.30.71"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904739/; classtype:trojan-activity;sid:84767839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/shares/aaws5fq3/files/322f1f5b-e04e-48f7-bf8e-91ad1bfeb2b4"; depth:63; endswith; nocase; http.host; content:"share.dovgertz.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904738/; classtype:trojan-activity;sid:84767838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.131.92.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904737/; classtype:trojan-activity;sid:84767837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.112.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904736/; classtype:trojan-activity;sid:84767836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.236.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904735/; classtype:trojan-activity;sid:84767835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.30.71"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904734/; classtype:trojan-activity;sid:84767834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.52.223"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904733/; classtype:trojan-activity;sid:84767833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904732/; classtype:trojan-activity;sid:84767832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.52.223"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904731/; classtype:trojan-activity;sid:84767831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.193.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904730/; classtype:trojan-activity;sid:84767830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.88.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904729/; classtype:trojan-activity;sid:84767829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904728/; classtype:trojan-activity;sid:84767828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.193.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904727/; classtype:trojan-activity;sid:84767827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.50.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904726/; classtype:trojan-activity;sid:84767826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.143.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904725/; classtype:trojan-activity;sid:84767825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.50.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904724/; classtype:trojan-activity;sid:84767824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.13.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904723/; classtype:trojan-activity;sid:84767823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.235.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904722/; classtype:trojan-activity;sid:84767822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.m68k"; depth:13; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904719/; classtype:trojan-activity;sid:84767819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.ppc"; depth:12; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904720/; classtype:trojan-activity;sid:84767820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.x86_64"; depth:15; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904721/; classtype:trojan-activity;sid:84767821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check3.sh"; depth:10; endswith; nocase; http.host; content:"43.228.157.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904718/; classtype:trojan-activity;sid:84767818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.sparc"; depth:17; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904710/; classtype:trojan-activity;sid:84767810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.x86_64"; depth:18; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904711/; classtype:trojan-activity;sid:84767811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mips64"; depth:18; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904712/; classtype:trojan-activity;sid:84767812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.i586"; depth:16; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904713/; classtype:trojan-activity;sid:84767813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arc"; depth:15; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904714/; classtype:trojan-activity;sid:84767814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl.sh"; depth:6; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904715/; classtype:trojan-activity;sid:84767815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlink.sh"; depth:9; endswith; nocase; http.host; content:"31.77.227.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904716/; classtype:trojan-activity;sid:84767816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl.sh"; depth:6; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904717/; classtype:trojan-activity;sid:84767817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm7"; depth:13; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904695/; classtype:trojan-activity;sid:84767795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.mipsel"; depth:15; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904696/; classtype:trojan-activity;sid:84767796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm8"; depth:13; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904697/; classtype:trojan-activity;sid:84767797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.x86"; depth:12; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904698/; classtype:trojan-activity;sid:84767798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm"; depth:12; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904699/; classtype:trojan-activity;sid:84767799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.mips"; depth:13; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904700/; classtype:trojan-activity;sid:84767800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.ppc"; depth:12; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904701/; classtype:trojan-activity;sid:84767801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.x86"; depth:12; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904702/; classtype:trojan-activity;sid:84767802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.m68k"; depth:13; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904703/; classtype:trojan-activity;sid:84767803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm"; depth:12; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904704/; classtype:trojan-activity;sid:84767804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.x86_64"; depth:15; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904705/; classtype:trojan-activity;sid:84767805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.mipsel"; depth:15; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904706/; classtype:trojan-activity;sid:84767806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm7"; depth:13; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904707/; classtype:trojan-activity;sid:84767807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm8"; depth:13; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904708/; classtype:trojan-activity;sid:84767808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.mips"; depth:13; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904709/; classtype:trojan-activity;sid:84767809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.sparc"; depth:14; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904693/; classtype:trojan-activity;sid:84767793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.sh4"; depth:12; endswith; nocase; http.host; content:"vps.atlas101.us.kg"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904694/; classtype:trojan-activity;sid:84767794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_31dd752749e9338c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904687/; classtype:trojan-activity;sid:84767787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_babe547392332f73.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904688/; classtype:trojan-activity;sid:84767788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.sh4"; depth:12; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904689/; classtype:trojan-activity;sid:84767789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_40500e12ca54e02b.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904690/; classtype:trojan-activity;sid:84767790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3cca71a2b980b74a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904691/; classtype:trojan-activity;sid:84767791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ba5747ef480cf9f7.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904692/; classtype:trojan-activity;sid:84767792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.sparc"; depth:14; endswith; nocase; http.host; content:"91.92.42.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904686/; classtype:trojan-activity;sid:84767786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904685/; classtype:trojan-activity;sid:84767785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904684/; classtype:trojan-activity;sid:84767784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904683/; classtype:trojan-activity;sid:84767783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904681/; classtype:trojan-activity;sid:84767781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904682/; classtype:trojan-activity;sid:84767782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904678/; classtype:trojan-activity;sid:84767778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904679/; classtype:trojan-activity;sid:84767779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904680/; classtype:trojan-activity;sid:84767780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904673/; classtype:trojan-activity;sid:84767773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904674/; classtype:trojan-activity;sid:84767774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904675/; classtype:trojan-activity;sid:84767775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904676/; classtype:trojan-activity;sid:84767776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904677/; classtype:trojan-activity;sid:84767777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904670/; classtype:trojan-activity;sid:84767770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904671/; classtype:trojan-activity;sid:84767771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904672/; classtype:trojan-activity;sid:84767772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904669/; classtype:trojan-activity;sid:84767769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904668/; classtype:trojan-activity;sid:84767768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904667/; classtype:trojan-activity;sid:84767767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904666/; classtype:trojan-activity;sid:84767766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904664/; classtype:trojan-activity;sid:84767764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904665/; classtype:trojan-activity;sid:84767765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904660/; classtype:trojan-activity;sid:84767760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86_64"; depth:13; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904661/; classtype:trojan-activity;sid:84767761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904662/; classtype:trojan-activity;sid:84767762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"157.173.119.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904663/; classtype:trojan-activity;sid:84767763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8e9f60"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904651/; classtype:trojan-activity;sid:84767751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ef2a92"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904652/; classtype:trojan-activity;sid:84767752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e6af82"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904653/; classtype:trojan-activity;sid:84767753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/18c0c9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904654/; classtype:trojan-activity;sid:84767754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1493f3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904655/; classtype:trojan-activity;sid:84767755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1b2ad0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904656/; classtype:trojan-activity;sid:84767756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a74d7e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904657/; classtype:trojan-activity;sid:84767757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dfbfd1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904658/; classtype:trojan-activity;sid:84767758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/af8816"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904659/; classtype:trojan-activity;sid:84767759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c6503e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904645/; classtype:trojan-activity;sid:84767745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/de3e3b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904646/; classtype:trojan-activity;sid:84767746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ba982a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904647/; classtype:trojan-activity;sid:84767747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b7e327"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904648/; classtype:trojan-activity;sid:84767748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fefd81"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904649/; classtype:trojan-activity;sid:84767749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d1d1d3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904650/; classtype:trojan-activity;sid:84767750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8ec572"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904640/; classtype:trojan-activity;sid:84767740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a1d493"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904641/; classtype:trojan-activity;sid:84767741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f873b2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904642/; classtype:trojan-activity;sid:84767742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c9023c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904643/; classtype:trojan-activity;sid:84767743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4b26b9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904644/; classtype:trojan-activity;sid:84767744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c5ee89"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904631/; classtype:trojan-activity;sid:84767731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e51ddb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904632/; classtype:trojan-activity;sid:84767732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/acdc3b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904633/; classtype:trojan-activity;sid:84767733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/47b560"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904634/; classtype:trojan-activity;sid:84767734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6b8b4d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904635/; classtype:trojan-activity;sid:84767735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1a029e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904636/; classtype:trojan-activity;sid:84767736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5969e9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904637/; classtype:trojan-activity;sid:84767737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a8ac25"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904638/; classtype:trojan-activity;sid:84767738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/796fc4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904639/; classtype:trojan-activity;sid:84767739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8e5a00"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904624/; classtype:trojan-activity;sid:84767724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00df69"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904625/; classtype:trojan-activity;sid:84767725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7836d7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904626/; classtype:trojan-activity;sid:84767726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9846b5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904627/; classtype:trojan-activity;sid:84767727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/46c7b2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904628/; classtype:trojan-activity;sid:84767728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/694268"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904629/; classtype:trojan-activity;sid:84767729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/523965"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904630/; classtype:trojan-activity;sid:84767730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.248.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904623/; classtype:trojan-activity;sid:84767723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.184.149.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904622/; classtype:trojan-activity;sid:84767722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.77.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904621/; classtype:trojan-activity;sid:84767721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.143.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904620/; classtype:trojan-activity;sid:84767720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.13.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904619/; classtype:trojan-activity;sid:84767719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.117.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904618/; classtype:trojan-activity;sid:84767718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.184.149.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904617/; classtype:trojan-activity;sid:84767717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904616/; classtype:trojan-activity;sid:84767716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.x86"; depth:13; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904600/; classtype:trojan-activity;sid:84767700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm7"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904601/; classtype:trojan-activity;sid:84767701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.m68k"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904602/; classtype:trojan-activity;sid:84767702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm4"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904603/; classtype:trojan-activity;sid:84767703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm8"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904604/; classtype:trojan-activity;sid:84767704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.i586"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904605/; classtype:trojan-activity;sid:84767705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.ppc440"; depth:16; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904606/; classtype:trojan-activity;sid:84767706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm5"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904607/; classtype:trojan-activity;sid:84767707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arc"; depth:13; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904608/; classtype:trojan-activity;sid:84767708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.spc"; depth:13; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904609/; classtype:trojan-activity;sid:84767709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.mips"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904610/; classtype:trojan-activity;sid:84767710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm6"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904611/; classtype:trojan-activity;sid:84767711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.x86_64"; depth:16; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904612/; classtype:trojan-activity;sid:84767712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.mpsl"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904613/; classtype:trojan-activity;sid:84767713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.sh4"; depth:13; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904614/; classtype:trojan-activity;sid:84767714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.ppc"; depth:13; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904615/; classtype:trojan-activity;sid:84767715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/wget.sh"; depth:13; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904599/; classtype:trojan-activity;sid:84767699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.i486"; depth:14; endswith; nocase; http.host; content:"91.92.47.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904598/; classtype:trojan-activity;sid:84767698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.9.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904597/; classtype:trojan-activity;sid:84767697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.77.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904596/; classtype:trojan-activity;sid:84767696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.67.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904595/; classtype:trojan-activity;sid:84767695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.41.95"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904594/; classtype:trojan-activity;sid:84767694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.187.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904593/; classtype:trojan-activity;sid:84767693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.211.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904592/; classtype:trojan-activity;sid:84767692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.225.253.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904591/; classtype:trojan-activity;sid:84767691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.236.135.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904590/; classtype:trojan-activity;sid:84767690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.67.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904589/; classtype:trojan-activity;sid:84767689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.166.79.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904588/; classtype:trojan-activity;sid:84767688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.166.79.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904587/; classtype:trojan-activity;sid:84767687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.225.253.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904586/; classtype:trojan-activity;sid:84767686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.210.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904585/; classtype:trojan-activity;sid:84767685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.78.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904584/; classtype:trojan-activity;sid:84767684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.78.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904583/; classtype:trojan-activity;sid:84767683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.236.135.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904582/; classtype:trojan-activity;sid:84767682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.187.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904581/; classtype:trojan-activity;sid:84767681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.194.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904580/; classtype:trojan-activity;sid:84767680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.113.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904579/; classtype:trojan-activity;sid:84767679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.153.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904578/; classtype:trojan-activity;sid:84767678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.127.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904577/; classtype:trojan-activity;sid:84767677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.162.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904576/; classtype:trojan-activity;sid:84767676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.227.64.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904575/; classtype:trojan-activity;sid:84767675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4b8d61b5a6f660b5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904574/; classtype:trojan-activity;sid:84767674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.153.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904573/; classtype:trojan-activity;sid:84767673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.133.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904572/; classtype:trojan-activity;sid:84767672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.127.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904571/; classtype:trojan-activity;sid:84767671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.133.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904570/; classtype:trojan-activity;sid:84767670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.69.203"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904569/; classtype:trojan-activity;sid:84767669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.69.203"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904568/; classtype:trojan-activity;sid:84767668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.180.132.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904567/; classtype:trojan-activity;sid:84767667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.56.232.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904566/; classtype:trojan-activity;sid:84767666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.108.253.192"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904565/; classtype:trojan-activity;sid:84767665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.194.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904564/; classtype:trojan-activity;sid:84767664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.41.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904563/; classtype:trojan-activity;sid:84767663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/bp7dbsur0q|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904562/; classtype:trojan-activity;sid:84767662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/kn6kof4crc|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904551/; classtype:trojan-activity;sid:84767651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/68p6ojwjvh|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904552/; classtype:trojan-activity;sid:84767652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/5yfzhpc2to|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904553/; classtype:trojan-activity;sid:84767653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/p6ov18cev6|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904554/; classtype:trojan-activity;sid:84767654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/r3vupm6d65|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904555/; classtype:trojan-activity;sid:84767655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/tbzh1mia7u|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904556/; classtype:trojan-activity;sid:84767656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/2b672mob79|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904557/; classtype:trojan-activity;sid:84767657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/qn9ioh7vz4|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904558/; classtype:trojan-activity;sid:84767658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/ix31e5lx8q|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904559/; classtype:trojan-activity;sid:84767659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/mqm274gghg|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904560/; classtype:trojan-activity;sid:84767660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/8a68bbgk43|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904561/; classtype:trojan-activity;sid:84767661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/d9ci5mrwdp|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904541/; classtype:trojan-activity;sid:84767641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/retlfugt5m|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904542/; classtype:trojan-activity;sid:84767642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/keexr0blbj|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904543/; classtype:trojan-activity;sid:84767643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/vuh58w66ti|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904544/; classtype:trojan-activity;sid:84767644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/bnah2628wi|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904545/; classtype:trojan-activity;sid:84767645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/f0f46g94yc|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904546/; classtype:trojan-activity;sid:84767646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/xwrwybh158|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904547/; classtype:trojan-activity;sid:84767647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/y6lkjsua3s|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904548/; classtype:trojan-activity;sid:84767648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/pecxqaf4jh|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904549/; classtype:trojan-activity;sid:84767649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rxmh7q5xk2g/assets/js/qqp40e2zv0|3f|token=ckcwx4we4trhshh4szhmdh3dk40yy9kb"; depth:76; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904550/; classtype:trojan-activity;sid:84767650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904540/; classtype:trojan-activity;sid:84767640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ef0a1d0d3c396203.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904539/; classtype:trojan-activity;sid:84767639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.143.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904538/; classtype:trojan-activity;sid:84767638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.121.27"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904537/; classtype:trojan-activity;sid:84767637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.108.253.192"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904536/; classtype:trojan-activity;sid:84767636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.175.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904535/; classtype:trojan-activity;sid:84767635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.143.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904534/; classtype:trojan-activity;sid:84767634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.48.114.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904533/; classtype:trojan-activity;sid:84767633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.177.244.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904532/; classtype:trojan-activity;sid:84767632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.203.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904531/; classtype:trojan-activity;sid:84767631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.224.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904530/; classtype:trojan-activity;sid:84767630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.56.232.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904529/; classtype:trojan-activity;sid:84767629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.48.114.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904528/; classtype:trojan-activity;sid:84767628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.181.102.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904527/; classtype:trojan-activity;sid:84767627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.224.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904526/; classtype:trojan-activity;sid:84767626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/8894093030/v8eace4.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904525/; classtype:trojan-activity;sid:84767625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904514/; classtype:trojan-activity;sid:84767614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm64"; depth:6; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904515/; classtype:trojan-activity;sid:84767615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904516/; classtype:trojan-activity;sid:84767616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904517/; classtype:trojan-activity;sid:84767617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904518/; classtype:trojan-activity;sid:84767618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904519/; classtype:trojan-activity;sid:84767619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904520/; classtype:trojan-activity;sid:84767620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904521/; classtype:trojan-activity;sid:84767621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904522/; classtype:trojan-activity;sid:84767622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904523/; classtype:trojan-activity;sid:84767623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904524/; classtype:trojan-activity;sid:84767624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904511/; classtype:trojan-activity;sid:84767611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904512/; classtype:trojan-activity;sid:84767612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/debug.dbg"; depth:10; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904513/; classtype:trojan-activity;sid:84767613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.151.64.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904510/; classtype:trojan-activity;sid:84767610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.81.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904509/; classtype:trojan-activity;sid:84767609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.194.27.62"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904508/; classtype:trojan-activity;sid:84767608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.252.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904507/; classtype:trojan-activity;sid:84767607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904506/; classtype:trojan-activity;sid:84767606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.88.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904505/; classtype:trojan-activity;sid:84767605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904504/; classtype:trojan-activity;sid:84767604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/1372270670/cgt6xb8.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904503/; classtype:trojan-activity;sid:84767603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.160.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904501/; classtype:trojan-activity;sid:84767601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.160.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904502/; classtype:trojan-activity;sid:84767602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.13.149.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904500/; classtype:trojan-activity;sid:84767600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.23.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904499/; classtype:trojan-activity;sid:84767599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.149.135.190"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904498/; classtype:trojan-activity;sid:84767598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pithnomodule.exe"; depth:17; endswith; nocase; http.host; content:"thu-iphone-07.cfd"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904497/; classtype:trojan-activity;sid:84767597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.13.149.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904496/; classtype:trojan-activity;sid:84767596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.224.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904495/; classtype:trojan-activity;sid:84767595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/1372270670/0nojffc.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904494/; classtype:trojan-activity;sid:84767594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.239.66.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904493/; classtype:trojan-activity;sid:84767593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svc.exe"; depth:8; endswith; nocase; http.host; content:"93.152.223.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904492/; classtype:trojan-activity;sid:84767592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.224.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904491/; classtype:trojan-activity;sid:84767591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.149.135.190"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904490/; classtype:trojan-activity;sid:84767590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904489/; classtype:trojan-activity;sid:84767589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.13.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904488/; classtype:trojan-activity;sid:84767588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904487/; classtype:trojan-activity;sid:84767587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904478/; classtype:trojan-activity;sid:84767578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904479/; classtype:trojan-activity;sid:84767579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904480/; classtype:trojan-activity;sid:84767580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904481/; classtype:trojan-activity;sid:84767581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904482/; classtype:trojan-activity;sid:84767582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904483/; classtype:trojan-activity;sid:84767583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mipsel"; depth:12; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904484/; classtype:trojan-activity;sid:84767584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904485/; classtype:trojan-activity;sid:84767585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904486/; classtype:trojan-activity;sid:84767586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904477/; classtype:trojan-activity;sid:84767577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904475/; classtype:trojan-activity;sid:84767575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904476/; classtype:trojan-activity;sid:84767576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv7l"; depth:15; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904473/; classtype:trojan-activity;sid:84767573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.mips"; depth:13; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904474/; classtype:trojan-activity;sid:84767574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.m68k"; depth:13; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904463/; classtype:trojan-activity;sid:84767563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv6l"; depth:15; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904464/; classtype:trojan-activity;sid:84767564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.powerpc"; depth:16; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904465/; classtype:trojan-activity;sid:84767565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv5l"; depth:15; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904466/; classtype:trojan-activity;sid:84767566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.i686"; depth:13; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904467/; classtype:trojan-activity;sid:84767567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.sh4"; depth:12; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904468/; classtype:trojan-activity;sid:84767568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.x86_64"; depth:15; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904469/; classtype:trojan-activity;sid:84767569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv4l"; depth:15; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904470/; classtype:trojan-activity;sid:84767570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.mipsel"; depth:15; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904471/; classtype:trojan-activity;sid:84767571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.i586"; depth:13; endswith; nocase; http.host; content:"94.154.43.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904472/; classtype:trojan-activity;sid:84767572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904462/; classtype:trojan-activity;sid:84767562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904458/; classtype:trojan-activity;sid:84767558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904459/; classtype:trojan-activity;sid:84767559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904460/; classtype:trojan-activity;sid:84767560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arc"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904461/; classtype:trojan-activity;sid:84767561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904446/; classtype:trojan-activity;sid:84767546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904447/; classtype:trojan-activity;sid:84767547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904448/; classtype:trojan-activity;sid:84767548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904449/; classtype:trojan-activity;sid:84767549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i686"; depth:11; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904450/; classtype:trojan-activity;sid:84767550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904451/; classtype:trojan-activity;sid:84767551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904452/; classtype:trojan-activity;sid:84767552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904453/; classtype:trojan-activity;sid:84767553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904454/; classtype:trojan-activity;sid:84767554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904455/; classtype:trojan-activity;sid:84767555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904456/; classtype:trojan-activity;sid:84767556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm7"; depth:11; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904457/; classtype:trojan-activity;sid:84767557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904443/; classtype:trojan-activity;sid:84767543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"94.154.43.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904444/; classtype:trojan-activity;sid:84767544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"94.154.43.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904445/; classtype:trojan-activity;sid:84767545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mipsrouter"; depth:17; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904441/; classtype:trojan-activity;sid:84767541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"94.154.43.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904442/; classtype:trojan-activity;sid:84767542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.sparc"; depth:12; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904440/; classtype:trojan-activity;sid:84767540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.x86_64"; depth:13; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904439/; classtype:trojan-activity;sid:84767539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv7l"; depth:13; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904434/; classtype:trojan-activity;sid:84767534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv4l"; depth:13; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904435/; classtype:trojan-activity;sid:84767535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.sh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904436/; classtype:trojan-activity;sid:84767536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904437/; classtype:trojan-activity;sid:84767537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mipsel"; depth:13; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904438/; classtype:trojan-activity;sid:84767538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.powerpc"; depth:14; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904430/; classtype:trojan-activity;sid:84767530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.i486"; depth:11; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904431/; classtype:trojan-activity;sid:84767531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv6l"; depth:13; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904432/; classtype:trojan-activity;sid:84767532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mips"; depth:11; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904433/; classtype:trojan-activity;sid:84767533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904425/; classtype:trojan-activity;sid:84767525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"94.154.43.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904426/; classtype:trojan-activity;sid:84767526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv5l"; depth:13; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904427/; classtype:trojan-activity;sid:84767527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.arc"; depth:10; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904428/; classtype:trojan-activity;sid:84767528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.m68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904429/; classtype:trojan-activity;sid:84767529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"94.154.43.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904420/; classtype:trojan-activity;sid:84767520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904421/; classtype:trojan-activity;sid:84767521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"94.154.43.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904422/; classtype:trojan-activity;sid:84767522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"94.154.43.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904423/; classtype:trojan-activity;sid:84767523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"94.154.43.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904424/; classtype:trojan-activity;sid:84767524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.23.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904419/; classtype:trojan-activity;sid:84767519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/1372270670/jz4kcas.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904418/; classtype:trojan-activity;sid:84767518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.68.176"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904417/; classtype:trojan-activity;sid:84767517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.194.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904416/; classtype:trojan-activity;sid:84767516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.211.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904415/; classtype:trojan-activity;sid:84767515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.196.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904414/; classtype:trojan-activity;sid:84767514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.10.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904413/; classtype:trojan-activity;sid:84767513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.10.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904412/; classtype:trojan-activity;sid:84767512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.211.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904411/; classtype:trojan-activity;sid:84767511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/installer_c2cea6.msi"; depth:21; endswith; nocase; http.host; content:"funneldiy.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904410/; classtype:trojan-activity;sid:84767510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.202.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904409/; classtype:trojan-activity;sid:84767509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.202.0"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904407/; classtype:trojan-activity;sid:84767507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.239.102.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904408/; classtype:trojan-activity;sid:84767508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.150.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904406/; classtype:trojan-activity;sid:84767506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.239.102.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904405/; classtype:trojan-activity;sid:84767505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.203.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904404/; classtype:trojan-activity;sid:84767504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"89.189.181.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904403/; classtype:trojan-activity;sid:84767503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.149.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904402/; classtype:trojan-activity;sid:84767502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.150.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904401/; classtype:trojan-activity;sid:84767501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.194.27.62"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904400/; classtype:trojan-activity;sid:84767500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.192.252.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904399/; classtype:trojan-activity;sid:84767499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.196.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904398/; classtype:trojan-activity;sid:84767498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.90.149.223"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904397/; classtype:trojan-activity;sid:84767497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg11"; depth:5; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904396/; classtype:trojan-activity;sid:84767496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deploy.sh"; depth:10; endswith; nocase; http.host; content:"43.228.157.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904395/; classtype:trojan-activity;sid:84767495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"59.96.138.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904393/; classtype:trojan-activity;sid:84767493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rondo.rxx.sh"; depth:13; endswith; nocase; http.host; content:"194.26.192.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904394/; classtype:trojan-activity;sid:84767494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sysorbit.apk"; depth:13; endswith; nocase; http.host; content:"176.65.139.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904392/; classtype:trojan-activity;sid:84767492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_e1a3f1926532a1e0.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904390/; classtype:trojan-activity;sid:84767490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_9022b6350736111c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904391/; classtype:trojan-activity;sid:84767491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meower.so"; depth:10; endswith; nocase; http.host; content:"31.77.227.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904389/; classtype:trojan-activity;sid:84767489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/services.apk"; depth:13; endswith; nocase; http.host; content:"31.77.227.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904387/; classtype:trojan-activity;sid:84767487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meower.arm7"; depth:12; endswith; nocase; http.host; content:"31.77.227.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904388/; classtype:trojan-activity;sid:84767488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4144dfb259ed3b1b.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904382/; classtype:trojan-activity;sid:84767482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904383/; classtype:trojan-activity;sid:84767483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"31.77.227.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904384/; classtype:trojan-activity;sid:84767484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-webpage/aoncontentspagesviewscontentsfilesevelopmentviewscxpagessuccessorfilesd/vhgvgcjg.exe"; depth:97; endswith; nocase; http.host; content:"revengegrompegroups.pl"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904385/; classtype:trojan-activity;sid:84767485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ff630ced898745f7.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904386/; classtype:trojan-activity;sid:84767486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.202.74"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904381/; classtype:trojan-activity;sid:84767481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.90.149.223"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904380/; classtype:trojan-activity;sid:84767480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.9.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904379/; classtype:trojan-activity;sid:84767479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.146.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904378/; classtype:trojan-activity;sid:84767478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.30.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904377/; classtype:trojan-activity;sid:84767477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.sh"; depth:5; endswith; nocase; http.host; content:"198.144.179.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904376/; classtype:trojan-activity;sid:84767476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/1372270670/gpzbwsi.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904375/; classtype:trojan-activity;sid:84767475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.19.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904374/; classtype:trojan-activity;sid:84767474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.208.46"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904373/; classtype:trojan-activity;sid:84767473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_c4ed5358194cb9dd.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904372/; classtype:trojan-activity;sid:84767472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.162.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904371/; classtype:trojan-activity;sid:84767471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.84.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904370/; classtype:trojan-activity;sid:84767470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.10.187"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904369/; classtype:trojan-activity;sid:84767469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.57.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904368/; classtype:trojan-activity;sid:84767468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.57.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904367/; classtype:trojan-activity;sid:84767467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.218.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904366/; classtype:trojan-activity;sid:84767466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.252.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904365/; classtype:trojan-activity;sid:84767465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.68.176"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904364/; classtype:trojan-activity;sid:84767464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.179.125.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904363/; classtype:trojan-activity;sid:84767463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"202.107.0.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904361/; classtype:trojan-activity;sid:84767461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.177.28.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904362/; classtype:trojan-activity;sid:84767462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.150.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904359/; classtype:trojan-activity;sid:84767459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.113.189.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904360/; classtype:trojan-activity;sid:84767460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.174.41.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904356/; classtype:trojan-activity;sid:84767456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"203.177.28.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904357/; classtype:trojan-activity;sid:84767457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.85.169.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904358/; classtype:trojan-activity;sid:84767458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.109.201.128"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904330/; classtype:trojan-activity;sid:84767430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.235.207.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904331/; classtype:trojan-activity;sid:84767431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.205.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904332/; classtype:trojan-activity;sid:84767432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.240.11.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904333/; classtype:trojan-activity;sid:84767433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.87.221.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904334/; classtype:trojan-activity;sid:84767434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.83.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904335/; classtype:trojan-activity;sid:84767435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.152.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904336/; classtype:trojan-activity;sid:84767436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.149.88.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904337/; classtype:trojan-activity;sid:84767437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.244.13"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904338/; classtype:trojan-activity;sid:84767438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.142.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904339/; classtype:trojan-activity;sid:84767439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.200.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904340/; classtype:trojan-activity;sid:84767440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.194.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904341/; classtype:trojan-activity;sid:84767441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.21.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904342/; classtype:trojan-activity;sid:84767442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.9.165.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904343/; classtype:trojan-activity;sid:84767443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.161.90.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904344/; classtype:trojan-activity;sid:84767444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.182.97.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904345/; classtype:trojan-activity;sid:84767445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.9.165.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904346/; classtype:trojan-activity;sid:84767446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.73.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904347/; classtype:trojan-activity;sid:84767447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904348/; classtype:trojan-activity;sid:84767448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.113.196.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904349/; classtype:trojan-activity;sid:84767449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.182.97.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904350/; classtype:trojan-activity;sid:84767450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.83.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904351/; classtype:trojan-activity;sid:84767451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.174.41.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904352/; classtype:trojan-activity;sid:84767452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.171.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904353/; classtype:trojan-activity;sid:84767453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.171.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904354/; classtype:trojan-activity;sid:84767454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.134.160.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904355/; classtype:trojan-activity;sid:84767455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.84.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904325/; classtype:trojan-activity;sid:84767425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.80.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904326/; classtype:trojan-activity;sid:84767426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"203.2.151.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904327/; classtype:trojan-activity;sid:84767427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.247.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904328/; classtype:trojan-activity;sid:84767428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.102.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904329/; classtype:trojan-activity;sid:84767429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.107.0.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904324/; classtype:trojan-activity;sid:84767424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.152.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904316/; classtype:trojan-activity;sid:84767416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.72.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904317/; classtype:trojan-activity;sid:84767417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.72.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904318/; classtype:trojan-activity;sid:84767418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.102.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904319/; classtype:trojan-activity;sid:84767419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.102.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904320/; classtype:trojan-activity;sid:84767420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.192.138"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904321/; classtype:trojan-activity;sid:84767421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.149.88.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904322/; classtype:trojan-activity;sid:84767422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.84.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904323/; classtype:trojan-activity;sid:84767423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.80.57.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904296/; classtype:trojan-activity;sid:84767396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"175.174.68.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904297/; classtype:trojan-activity;sid:84767397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.73.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904298/; classtype:trojan-activity;sid:84767398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.86.137.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904299/; classtype:trojan-activity;sid:84767399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.128.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904300/; classtype:trojan-activity;sid:84767400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904301/; classtype:trojan-activity;sid:84767401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.224.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904302/; classtype:trojan-activity;sid:84767402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.130.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904303/; classtype:trojan-activity;sid:84767403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.185.199.96"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904304/; classtype:trojan-activity;sid:84767404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.179.240.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904305/; classtype:trojan-activity;sid:84767405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.227.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904306/; classtype:trojan-activity;sid:84767406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.86.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904307/; classtype:trojan-activity;sid:84767407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.85.169.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904308/; classtype:trojan-activity;sid:84767408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.84.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904309/; classtype:trojan-activity;sid:84767409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.161.90.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904310/; classtype:trojan-activity;sid:84767410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.229.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904311/; classtype:trojan-activity;sid:84767411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.128.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904312/; classtype:trojan-activity;sid:84767412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.247.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904313/; classtype:trojan-activity;sid:84767413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.149.219.183"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904314/; classtype:trojan-activity;sid:84767414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.8.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904315/; classtype:trojan-activity;sid:84767415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.88.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904290/; classtype:trojan-activity;sid:84767390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"77.236.74.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904291/; classtype:trojan-activity;sid:84767391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.73.126.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904292/; classtype:trojan-activity;sid:84767392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.224.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904293/; classtype:trojan-activity;sid:84767393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.130.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904294/; classtype:trojan-activity;sid:84767394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.65.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904295/; classtype:trojan-activity;sid:84767395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904288/; classtype:trojan-activity;sid:84767388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"193.163.187.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904289/; classtype:trojan-activity;sid:84767389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.109.201.128"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904285/; classtype:trojan-activity;sid:84767385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.194.17.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904286/; classtype:trojan-activity;sid:84767386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.228.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904287/; classtype:trojan-activity;sid:84767387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.14.231"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904270/; classtype:trojan-activity;sid:84767370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.14.231"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904271/; classtype:trojan-activity;sid:84767371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.9.103"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904272/; classtype:trojan-activity;sid:84767372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.114.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904273/; classtype:trojan-activity;sid:84767373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.59.235.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904274/; classtype:trojan-activity;sid:84767374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.59.237.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904275/; classtype:trojan-activity;sid:84767375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.73.126.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904276/; classtype:trojan-activity;sid:84767376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.227.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904277/; classtype:trojan-activity;sid:84767377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.205.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904278/; classtype:trojan-activity;sid:84767378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.150.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904279/; classtype:trojan-activity;sid:84767379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.162.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904280/; classtype:trojan-activity;sid:84767380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.153.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904281/; classtype:trojan-activity;sid:84767381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.185.199.96"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904282/; classtype:trojan-activity;sid:84767382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.73.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904283/; classtype:trojan-activity;sid:84767383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.79.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904284/; classtype:trojan-activity;sid:84767384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"193.163.187.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904254/; classtype:trojan-activity;sid:84767354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904255/; classtype:trojan-activity;sid:84767355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.80.57.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904256/; classtype:trojan-activity;sid:84767356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.179.240.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904257/; classtype:trojan-activity;sid:84767357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.87.221.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904258/; classtype:trojan-activity;sid:84767358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"38.137.250.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904259/; classtype:trojan-activity;sid:84767359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.114.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904260/; classtype:trojan-activity;sid:84767360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.236.74.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904261/; classtype:trojan-activity;sid:84767361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904262/; classtype:trojan-activity;sid:84767362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.194.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904263/; classtype:trojan-activity;sid:84767363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.2.151.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904264/; classtype:trojan-activity;sid:84767364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.190.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904265/; classtype:trojan-activity;sid:84767365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904266/; classtype:trojan-activity;sid:84767366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.202.0"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904267/; classtype:trojan-activity;sid:84767367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.222.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904268/; classtype:trojan-activity;sid:84767368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.4.138"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904269/; classtype:trojan-activity;sid:84767369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904253/; classtype:trojan-activity;sid:84767353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.233.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904252/; classtype:trojan-activity;sid:84767352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.10.7"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904251/; classtype:trojan-activity;sid:84767351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/base64/mduzotixndy2mdvjmtm4ndu5nta1owrjyzbjmwjjzdqynzc0odawzmuzztrkogi4mwrmyte5otczn2i0ntiwma=="; depth:96; endswith; nocase; http.host; content:"httpbin.org"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904250/; classtype:trojan-activity;sid:84767350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.37.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904249/; classtype:trojan-activity;sid:84767349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.60.241.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904248/; classtype:trojan-activity;sid:84767348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.60.241.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904247/; classtype:trojan-activity;sid:84767347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.69.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904246/; classtype:trojan-activity;sid:84767346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.29.28.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904245/; classtype:trojan-activity;sid:84767345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb4cb2cb097b20.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904244/; classtype:trojan-activity;sid:84767344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.107.209.223"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904242/; classtype:trojan-activity;sid:84767342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb72c503457787.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904243/; classtype:trojan-activity;sid:84767343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb72c503457787.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904235/; classtype:trojan-activity;sid:84767335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb7333cef1df5b.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904236/; classtype:trojan-activity;sid:84767336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb4d3ad86bac08.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904237/; classtype:trojan-activity;sid:84767337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb7441f57b1a78.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904238/; classtype:trojan-activity;sid:84767338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb4d062cca7589.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904239/; classtype:trojan-activity;sid:84767339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload/18cb9cea2d96337e.bin"; depth:29; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904240/; classtype:trojan-activity;sid:84767340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb7182b6e8e7b6.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904241/; classtype:trojan-activity;sid:84767341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb73a84c0c2684.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904232/; classtype:trojan-activity;sid:84767332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb9c2f86cabdb2.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904233/; classtype:trojan-activity;sid:84767333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb4ccfb9e27fc2.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904234/; classtype:trojan-activity;sid:84767334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb7ca62cfb04e6.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904229/; classtype:trojan-activity;sid:84767329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb4cef6566cc70.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904230/; classtype:trojan-activity;sid:84767330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb7296bb21486f.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904231/; classtype:trojan-activity;sid:84767331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb73a84c0c2684.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904228/; classtype:trojan-activity;sid:84767328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb7a9ae6f1d608.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904227/; classtype:trojan-activity;sid:84767327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb9c2f86cabdb2.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904223/; classtype:trojan-activity;sid:84767323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb7441f57b1a78.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904224/; classtype:trojan-activity;sid:84767324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb7296bb21486f.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904225/; classtype:trojan-activity;sid:84767325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb7333cef1df5b.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904226/; classtype:trojan-activity;sid:84767326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb9cea2d96337e.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904221/; classtype:trojan-activity;sid:84767321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/18cb7182b6e8e7b6.exe"; depth:28; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904222/; classtype:trojan-activity;sid:84767322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypter_server_linux"; depth:21; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904220/; classtype:trojan-activity;sid:84767320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypter_server_linux.exe"; depth:25; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904219/; classtype:trojan-activity;sid:84767319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb4b870df50ce6.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904217/; classtype:trojan-activity;sid:84767317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb4bd89774939d.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904218/; classtype:trojan-activity;sid:84767318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/18cb4ba64c9fd789.bin"; depth:30; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904216/; classtype:trojan-activity;sid:84767316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.exe"; depth:12; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904213/; classtype:trojan-activity;sid:84767313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload/18cb7ca62cfb04e6.bin"; depth:29; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904214/; classtype:trojan-activity;sid:84767314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload/18cb7a9ae6f1d608.bin"; depth:29; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904215/; classtype:trojan-activity;sid:84767315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.65.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904212/; classtype:trojan-activity;sid:84767312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.69.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904211/; classtype:trojan-activity;sid:84767311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.25.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904210/; classtype:trojan-activity;sid:84767310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.29.28.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904209/; classtype:trojan-activity;sid:84767309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.107.209.223"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904208/; classtype:trojan-activity;sid:84767308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.188.223.103"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904207/; classtype:trojan-activity;sid:84767307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904206/; classtype:trojan-activity;sid:84767306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.165.184.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904205/; classtype:trojan-activity;sid:84767305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.59.204.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904204/; classtype:trojan-activity;sid:84767304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.140.186.83"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904202/; classtype:trojan-activity;sid:84767302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.91.14.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904203/; classtype:trojan-activity;sid:84767303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.181.178"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904201/; classtype:trojan-activity;sid:84767301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.91.14.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904200/; classtype:trojan-activity;sid:84767300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.202.206.125"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904199/; classtype:trojan-activity;sid:84767299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.181.178"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904198/; classtype:trojan-activity;sid:84767298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.227.49.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904197/; classtype:trojan-activity;sid:84767297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.227.49.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904196/; classtype:trojan-activity;sid:84767296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.130.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904195/; classtype:trojan-activity;sid:84767295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.202.206.125"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904194/; classtype:trojan-activity;sid:84767294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.182.37"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904193/; classtype:trojan-activity;sid:84767293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.255.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904192/; classtype:trojan-activity;sid:84767292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"171.213.150.35"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904191/; classtype:trojan-activity;sid:84767291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asset/update.dat"; depth:17; endswith; nocase; http.host; content:"newstan.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904190/; classtype:trojan-activity;sid:84767290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s.ps1"; depth:6; endswith; nocase; http.host; content:"94.154.32.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904189/; classtype:trojan-activity;sid:84767289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.239.122.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904188/; classtype:trojan-activity;sid:84767288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.182.37"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904187/; classtype:trojan-activity;sid:84767287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.43.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904186/; classtype:trojan-activity;sid:84767286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.239.122.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904185/; classtype:trojan-activity;sid:84767285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.118.246.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904184/; classtype:trojan-activity;sid:84767284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.193.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904183/; classtype:trojan-activity;sid:84767283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.188.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904182/; classtype:trojan-activity;sid:84767282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.60.241.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904181/; classtype:trojan-activity;sid:84767281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.60.241.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904180/; classtype:trojan-activity;sid:84767280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.60.241.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904179/; classtype:trojan-activity;sid:84767279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.60.241.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904178/; classtype:trojan-activity;sid:84767278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"77.83.39.9"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904176/; classtype:trojan-activity;sid:84767276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"77.83.39.9"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904177/; classtype:trojan-activity;sid:84767277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"77.83.39.66"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904175/; classtype:trojan-activity;sid:84767275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.193.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904174/; classtype:trojan-activity;sid:84767274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.190.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904173/; classtype:trojan-activity;sid:84767273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.188.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904172/; classtype:trojan-activity;sid:84767272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.248.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904171/; classtype:trojan-activity;sid:84767271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.239.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904169/; classtype:trojan-activity;sid:84767269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.19.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904170/; classtype:trojan-activity;sid:84767270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.148.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904168/; classtype:trojan-activity;sid:84767268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.248.123.33"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904167/; classtype:trojan-activity;sid:84767267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.248.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904166/; classtype:trojan-activity;sid:84767266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.116.88.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904165/; classtype:trojan-activity;sid:84767265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.148.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904164/; classtype:trojan-activity;sid:84767264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.242.56.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904163/; classtype:trojan-activity;sid:84767263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.248.123.33"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904162/; classtype:trojan-activity;sid:84767262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.114.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904161/; classtype:trojan-activity;sid:84767261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.142.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904160/; classtype:trojan-activity;sid:84767260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904159/; classtype:trojan-activity;sid:84767259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.114.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904158/; classtype:trojan-activity;sid:84767258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.100.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904157/; classtype:trojan-activity;sid:84767257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.188.204.211"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904156/; classtype:trojan-activity;sid:84767256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.133.101.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904155/; classtype:trojan-activity;sid:84767255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jutrvoservice.exe"; depth:18; endswith; nocase; http.host; content:"thu-iphone-07.cfd"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904154/; classtype:trojan-activity;sid:84767254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.179.238.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904153/; classtype:trojan-activity;sid:84767253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.188.204.211"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904152/; classtype:trojan-activity;sid:84767252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.sparc"; depth:11; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904136/; classtype:trojan-activity;sid:84767236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.m68k"; depth:10; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904137/; classtype:trojan-activity;sid:84767237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.i686"; depth:10; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904138/; classtype:trojan-activity;sid:84767238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.x64"; depth:9; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904139/; classtype:trojan-activity;sid:84767239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.ppc"; depth:9; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904140/; classtype:trojan-activity;sid:84767240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.mipsel"; depth:12; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904141/; classtype:trojan-activity;sid:84767241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm4"; depth:10; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904142/; classtype:trojan-activity;sid:84767242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm7"; depth:10; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904143/; classtype:trojan-activity;sid:84767243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.i486"; depth:10; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904144/; classtype:trojan-activity;sid:84767244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.sh4"; depth:9; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904145/; classtype:trojan-activity;sid:84767245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm5"; depth:10; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904146/; classtype:trojan-activity;sid:84767246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm6"; depth:10; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904147/; classtype:trojan-activity;sid:84767247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.mips"; depth:10; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904148/; classtype:trojan-activity;sid:84767248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.ppc440"; depth:12; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904149/; classtype:trojan-activity;sid:84767249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.x86"; depth:9; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904150/; classtype:trojan-activity;sid:84767250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dp.sh"; depth:6; endswith; nocase; http.host; content:"191.44.112.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904151/; classtype:trojan-activity;sid:84767251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.133.101.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904135/; classtype:trojan-activity;sid:84767235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"72.255.30.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904133/; classtype:trojan-activity;sid:84767233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.179.238.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904134/; classtype:trojan-activity;sid:84767234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.249.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904132/; classtype:trojan-activity;sid:84767232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.249.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904131/; classtype:trojan-activity;sid:84767231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.13.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904130/; classtype:trojan-activity;sid:84767230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.228.4.224"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904129/; classtype:trojan-activity;sid:84767229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.152.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904128/; classtype:trojan-activity;sid:84767228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"108.170.136.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904127/; classtype:trojan-activity;sid:84767227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.150.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904126/; classtype:trojan-activity;sid:84767226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.152.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904125/; classtype:trojan-activity;sid:84767225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.78.26.151"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904124/; classtype:trojan-activity;sid:84767224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"108.170.136.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904123/; classtype:trojan-activity;sid:84767223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.150.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904122/; classtype:trojan-activity;sid:84767222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.228.4.224"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904121/; classtype:trojan-activity;sid:84767221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.24.217.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904120/; classtype:trojan-activity;sid:84767220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.159.154.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904119/; classtype:trojan-activity;sid:84767219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7782139129/tz2szvl.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904118/; classtype:trojan-activity;sid:84767218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.203.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904117/; classtype:trojan-activity;sid:84767217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.38.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904116/; classtype:trojan-activity;sid:84767216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.231.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904115/; classtype:trojan-activity;sid:84767215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.124.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904114/; classtype:trojan-activity;sid:84767214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.186.231.247"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904113/; classtype:trojan-activity;sid:84767213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.53.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904112/; classtype:trojan-activity;sid:84767212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.116.88.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904111/; classtype:trojan-activity;sid:84767211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.122.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904110/; classtype:trojan-activity;sid:84767210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.127.53.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904109/; classtype:trojan-activity;sid:84767209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.119.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904108/; classtype:trojan-activity;sid:84767208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.40.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904107/; classtype:trojan-activity;sid:84767207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.68.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904106/; classtype:trojan-activity;sid:84767206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.61.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904105/; classtype:trojan-activity;sid:84767205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.155.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904104/; classtype:trojan-activity;sid:84767204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.90.150.62"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904103/; classtype:trojan-activity;sid:84767203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.119.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904102/; classtype:trojan-activity;sid:84767202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.61.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904101/; classtype:trojan-activity;sid:84767201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.223.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904100/; classtype:trojan-activity;sid:84767200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"156.146.24.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904099/; classtype:trojan-activity;sid:84767199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.68.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904098/; classtype:trojan-activity;sid:84767198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.155.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904097/; classtype:trojan-activity;sid:84767197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.118.104"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904096/; classtype:trojan-activity;sid:84767196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.90.150.62"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904095/; classtype:trojan-activity;sid:84767195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"156.146.24.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904094/; classtype:trojan-activity;sid:84767194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.174.66.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904093/; classtype:trojan-activity;sid:84767193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.231.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904092/; classtype:trojan-activity;sid:84767192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.159.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904091/; classtype:trojan-activity;sid:84767191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.231.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904090/; classtype:trojan-activity;sid:84767190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.82.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904089/; classtype:trojan-activity;sid:84767189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.38.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904088/; classtype:trojan-activity;sid:84767188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.82.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904087/; classtype:trojan-activity;sid:84767187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"1.58.182.84"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904086/; classtype:trojan-activity;sid:84767186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.110.49.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904085/; classtype:trojan-activity;sid:84767185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.101.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904084/; classtype:trojan-activity;sid:84767184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.110.49.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904083/; classtype:trojan-activity;sid:84767183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.8.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904082/; classtype:trojan-activity;sid:84767182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.101.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904081/; classtype:trojan-activity;sid:84767181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.64.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904080/; classtype:trojan-activity;sid:84767180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.64.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904079/; classtype:trojan-activity;sid:84767179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"200.115.102.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904078/; classtype:trojan-activity;sid:84767178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.186.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904077/; classtype:trojan-activity;sid:84767177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.127.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904076/; classtype:trojan-activity;sid:84767176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.138.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904075/; classtype:trojan-activity;sid:84767175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.179.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904074/; classtype:trojan-activity;sid:84767174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandora.x86_64"; depth:15; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904073/; classtype:trojan-activity;sid:84767173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm6"; depth:10; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904070/; classtype:trojan-activity;sid:84767170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm7"; depth:10; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904071/; classtype:trojan-activity;sid:84767171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scanner"; depth:8; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904072/; classtype:trojan-activity;sid:84767172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_m68k"; depth:10; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904068/; classtype:trojan-activity;sid:84767168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm5"; depth:10; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904069/; classtype:trojan-activity;sid:84767169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gfg.sh"; depth:7; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904067/; classtype:trojan-activity;sid:84767167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.224.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904066/; classtype:trojan-activity;sid:84767166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.138.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904065/; classtype:trojan-activity;sid:84767165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.72.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904064/; classtype:trojan-activity;sid:84767164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.224.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904063/; classtype:trojan-activity;sid:84767163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.243.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904062/; classtype:trojan-activity;sid:84767162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.30.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904061/; classtype:trojan-activity;sid:84767161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.5.157"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904060/; classtype:trojan-activity;sid:84767160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.243.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904059/; classtype:trojan-activity;sid:84767159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.30.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904058/; classtype:trojan-activity;sid:84767158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.5.157"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904057/; classtype:trojan-activity;sid:84767157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_14cf0ee8101600e7.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904056/; classtype:trojan-activity;sid:84767156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"77.239.124.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904054/; classtype:trojan-activity;sid:84767154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_76fd7c41ddb193a5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904055/; classtype:trojan-activity;sid:84767155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"105.186.143.37"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904053/; classtype:trojan-activity;sid:84767153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"111.127.232.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904052/; classtype:trojan-activity;sid:84767152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_f5ae52914bf7056f.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904051/; classtype:trojan-activity;sid:84767151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/__l5e/assets-v1/a2ff2b05-f09a-413d-96b1-14a028790953/kryptonplus-liista.jar"; depth:76; endswith; nocase; http.host; content:"kryptonclientliista.lovable.app"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904050/; classtype:trojan-activity;sid:84767150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/assets/krypton-free.jar"; depth:24; endswith; nocase; http.host; content:"www.krypton-client.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904048/; classtype:trojan-activity;sid:84767148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/d6a0dbb9ae834113a8401012b1f9aa18.exe"; depth:45; endswith; nocase; http.host; content:"192.162.199.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904049/; classtype:trojan-activity;sid:84767149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader.sh"; depth:10; endswith; nocase; http.host; content:"103.77.246.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904047/; classtype:trojan-activity;sid:84767147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_48852a33f51921f1.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904046/; classtype:trojan-activity;sid:84767146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"218.0.112.226"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904045/; classtype:trojan-activity;sid:84767145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_776621fa56cb2ef8.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904042/; classtype:trojan-activity;sid:84767142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_cb2aa48501d6d3b6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904043/; classtype:trojan-activity;sid:84767143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_64858a8342cb3c62.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904044/; classtype:trojan-activity;sid:84767144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.10.187"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904041/; classtype:trojan-activity;sid:84767141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904040/; classtype:trojan-activity;sid:84767140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.30.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904039/; classtype:trojan-activity;sid:84767139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.131.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904038/; classtype:trojan-activity;sid:84767138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.228.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904037/; classtype:trojan-activity;sid:84767137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.131.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904036/; classtype:trojan-activity;sid:84767136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.222.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904035/; classtype:trojan-activity;sid:84767135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.228.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904034/; classtype:trojan-activity;sid:84767134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"98.36.141.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904033/; classtype:trojan-activity;sid:84767133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.187.252.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904032/; classtype:trojan-activity;sid:84767132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"98.36.141.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904031/; classtype:trojan-activity;sid:84767131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.232.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904030/; classtype:trojan-activity;sid:84767130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.132.156.143"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904029/; classtype:trojan-activity;sid:84767129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.72.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904028/; classtype:trojan-activity;sid:84767128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.1.186"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904027/; classtype:trojan-activity;sid:84767127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.115.232.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904026/; classtype:trojan-activity;sid:84767126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.1.186"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904025/; classtype:trojan-activity;sid:84767125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.254.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904024/; classtype:trojan-activity;sid:84767124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.88.136.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904023/; classtype:trojan-activity;sid:84767123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.254.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904022/; classtype:trojan-activity;sid:84767122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.9.35.137"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904021/; classtype:trojan-activity;sid:84767121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.124.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904020/; classtype:trojan-activity;sid:84767120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.124.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904019/; classtype:trojan-activity;sid:84767119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_ppc"; depth:9; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904018/; classtype:trojan-activity;sid:84767118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.21.174.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904017/; classtype:trojan-activity;sid:84767117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.78.61"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904016/; classtype:trojan-activity;sid:84767116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.21.174.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904015/; classtype:trojan-activity;sid:84767115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.58.42.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904013/; classtype:trojan-activity;sid:84767113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.113.206"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904014/; classtype:trojan-activity;sid:84767114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.197.32.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904012/; classtype:trojan-activity;sid:84767112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.70.226.107"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904011/; classtype:trojan-activity;sid:84767111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.213.104"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904008/; classtype:trojan-activity;sid:84767108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.64.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904009/; classtype:trojan-activity;sid:84767109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.240.11.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904010/; classtype:trojan-activity;sid:84767110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.185.91.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904007/; classtype:trojan-activity;sid:84767107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.95.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904005/; classtype:trojan-activity;sid:84767105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.105.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904006/; classtype:trojan-activity;sid:84767106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.115.102.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903989/; classtype:trojan-activity;sid:84767089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.230.79.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903990/; classtype:trojan-activity;sid:84767090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p1.sh"; depth:6; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903991/; classtype:trojan-activity;sid:84767091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.22.216"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903992/; classtype:trojan-activity;sid:84767092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.94.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903993/; classtype:trojan-activity;sid:84767093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.14.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903994/; classtype:trojan-activity;sid:84767094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.94.194.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903995/; classtype:trojan-activity;sid:84767095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.73.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903996/; classtype:trojan-activity;sid:84767096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.44.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903997/; classtype:trojan-activity;sid:84767097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.121.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903998/; classtype:trojan-activity;sid:84767098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903999/; classtype:trojan-activity;sid:84767099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.1.247.58"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904000/; classtype:trojan-activity;sid:84767100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.149.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904001/; classtype:trojan-activity;sid:84767101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.23.133.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904002/; classtype:trojan-activity;sid:84767102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.53.20.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904003/; classtype:trojan-activity;sid:84767103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.184.12.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904004/; classtype:trojan-activity;sid:84767104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.54.4.193"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903983/; classtype:trojan-activity;sid:84767083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.2.53.55"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903984/; classtype:trojan-activity;sid:84767084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.194.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903985/; classtype:trojan-activity;sid:84767085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903986/; classtype:trojan-activity;sid:84767086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.179.125.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903987/; classtype:trojan-activity;sid:84767087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.183.3.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903988/; classtype:trojan-activity;sid:84767088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.4.138"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903980/; classtype:trojan-activity;sid:84767080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.44.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903981/; classtype:trojan-activity;sid:84767081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.187.252.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903982/; classtype:trojan-activity;sid:84767082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.239.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903978/; classtype:trojan-activity;sid:84767078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.91.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903979/; classtype:trojan-activity;sid:84767079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.116.142.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903977/; classtype:trojan-activity;sid:84767077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.206.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903975/; classtype:trojan-activity;sid:84767075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.129.144.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903976/; classtype:trojan-activity;sid:84767076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903971/; classtype:trojan-activity;sid:84767071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.196.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903972/; classtype:trojan-activity;sid:84767072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.189.159.141"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903973/; classtype:trojan-activity;sid:84767073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.235.207.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903974/; classtype:trojan-activity;sid:84767074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.85.15.27"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903955/; classtype:trojan-activity;sid:84767055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.77.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903956/; classtype:trojan-activity;sid:84767056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.4.250.38"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903957/; classtype:trojan-activity;sid:84767057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.148.111.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903958/; classtype:trojan-activity;sid:84767058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.156.139.177"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903959/; classtype:trojan-activity;sid:84767059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.185.91.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903960/; classtype:trojan-activity;sid:84767060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.111.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903961/; classtype:trojan-activity;sid:84767061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.34.242.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903962/; classtype:trojan-activity;sid:84767062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.94.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903963/; classtype:trojan-activity;sid:84767063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"74.127.168.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903964/; classtype:trojan-activity;sid:84767064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.207.229.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903965/; classtype:trojan-activity;sid:84767065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.85.43.191"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903966/; classtype:trojan-activity;sid:84767066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.201.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903967/; classtype:trojan-activity;sid:84767067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.21.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903968/; classtype:trojan-activity;sid:84767068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.4.250.38"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903969/; classtype:trojan-activity;sid:84767069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.161.116.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903970/; classtype:trojan-activity;sid:84767070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.64.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903952/; classtype:trojan-activity;sid:84767052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.54.4.193"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903953/; classtype:trojan-activity;sid:84767053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.122.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903954/; classtype:trojan-activity;sid:84767054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.14.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903950/; classtype:trojan-activity;sid:84767050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.64.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903951/; classtype:trojan-activity;sid:84767051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"140.237.44.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903946/; classtype:trojan-activity;sid:84767046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.116.142.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903947/; classtype:trojan-activity;sid:84767047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"140.237.44.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903948/; classtype:trojan-activity;sid:84767048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.83.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903949/; classtype:trojan-activity;sid:84767049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.156.139.177"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903945/; classtype:trojan-activity;sid:84767045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/got"; depth:4; endswith; nocase; http.host; content:"213.177.179.52"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903944/; classtype:trojan-activity;sid:84767044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.231.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903933/; classtype:trojan-activity;sid:84767033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"74.127.168.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903934/; classtype:trojan-activity;sid:84767034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.149.87.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903935/; classtype:trojan-activity;sid:84767035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.113.206"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903936/; classtype:trojan-activity;sid:84767036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.136.169.228"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903937/; classtype:trojan-activity;sid:84767037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.149.87.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903938/; classtype:trojan-activity;sid:84767038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.160.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903939/; classtype:trojan-activity;sid:84767039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.254.40"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903940/; classtype:trojan-activity;sid:84767040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.136.169.228"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903941/; classtype:trojan-activity;sid:84767041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.85.43.191"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903942/; classtype:trojan-activity;sid:84767042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.77.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903943/; classtype:trojan-activity;sid:84767043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"79.106.74.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903917/; classtype:trojan-activity;sid:84767017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.141.233.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903918/; classtype:trojan-activity;sid:84767018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.120.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903919/; classtype:trojan-activity;sid:84767019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.10.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903920/; classtype:trojan-activity;sid:84767020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.94.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903921/; classtype:trojan-activity;sid:84767021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.35.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903922/; classtype:trojan-activity;sid:84767022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.22.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903923/; classtype:trojan-activity;sid:84767023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903924/; classtype:trojan-activity;sid:84767024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.72.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903925/; classtype:trojan-activity;sid:84767025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.91.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903926/; classtype:trojan-activity;sid:84767026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.24.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903927/; classtype:trojan-activity;sid:84767027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.180.57.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903928/; classtype:trojan-activity;sid:84767028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.58.252.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903929/; classtype:trojan-activity;sid:84767029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.86.137.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903930/; classtype:trojan-activity;sid:84767030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.85.15.27"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903931/; classtype:trojan-activity;sid:84767031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903932/; classtype:trojan-activity;sid:84767032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.196.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903915/; classtype:trojan-activity;sid:84767015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.196.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903916/; classtype:trojan-activity;sid:84767016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.43.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903914/; classtype:trojan-activity;sid:84767014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.105.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903913/; classtype:trojan-activity;sid:84767013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.10.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903912/; classtype:trojan-activity;sid:84767012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.34.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903911/; classtype:trojan-activity;sid:84767011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.13.17.211"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903910/; classtype:trojan-activity;sid:84767010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.9.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903909/; classtype:trojan-activity;sid:84767009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.190.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903908/; classtype:trojan-activity;sid:84767008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.62.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903907/; classtype:trojan-activity;sid:84767007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.34.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903906/; classtype:trojan-activity;sid:84767006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.48.166.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903905/; classtype:trojan-activity;sid:84767005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.230.51.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903904/; classtype:trojan-activity;sid:84767004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/omega/file.exe"; depth:21; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903903/; classtype:trojan-activity;sid:84767003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.190.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903902/; classtype:trojan-activity;sid:84767002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.187.158.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903901/; classtype:trojan-activity;sid:84767001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.207.141.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903900/; classtype:trojan-activity;sid:84767000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.48.166.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903899/; classtype:trojan-activity;sid:84766999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.69.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903898/; classtype:trojan-activity;sid:84766998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.192.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903897/; classtype:trojan-activity;sid:84766997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.190.18.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903896/; classtype:trojan-activity;sid:84766996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.207.141.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903895/; classtype:trojan-activity;sid:84766995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.69.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903894/; classtype:trojan-activity;sid:84766994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.217.139.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903893/; classtype:trojan-activity;sid:84766993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_865135af23551105.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903892/; classtype:trojan-activity;sid:84766992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.192.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903891/; classtype:trojan-activity;sid:84766991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.223.140.197"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903890/; classtype:trojan-activity;sid:84766990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.217.139.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903889/; classtype:trojan-activity;sid:84766989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.223.140.197"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903888/; classtype:trojan-activity;sid:84766988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.22.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903887/; classtype:trojan-activity;sid:84766987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.228.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903886/; classtype:trojan-activity;sid:84766986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.76.206.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903885/; classtype:trojan-activity;sid:84766985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.6.205"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903884/; classtype:trojan-activity;sid:84766984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.248.80"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903883/; classtype:trojan-activity;sid:84766983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.2.135"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903882/; classtype:trojan-activity;sid:84766982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.201.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903881/; classtype:trojan-activity;sid:84766981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.2.135"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903880/; classtype:trojan-activity;sid:84766980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.201.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903879/; classtype:trojan-activity;sid:84766979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.174.107.238"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903878/; classtype:trojan-activity;sid:84766978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.148.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903877/; classtype:trojan-activity;sid:84766977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.143.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903876/; classtype:trojan-activity;sid:84766976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.148.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903875/; classtype:trojan-activity;sid:84766975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.228.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903874/; classtype:trojan-activity;sid:84766974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.29.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903873/; classtype:trojan-activity;sid:84766973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.248.80"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903872/; classtype:trojan-activity;sid:84766972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.191.228.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903871/; classtype:trojan-activity;sid:84766971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.249.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903869/; classtype:trojan-activity;sid:84766969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.249.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903870/; classtype:trojan-activity;sid:84766970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.215.95"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903868/; classtype:trojan-activity;sid:84766968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.29.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903867/; classtype:trojan-activity;sid:84766967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.143.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903866/; classtype:trojan-activity;sid:84766966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.215.95"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903865/; classtype:trojan-activity;sid:84766965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.141.211"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903864/; classtype:trojan-activity;sid:84766964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.32.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903863/; classtype:trojan-activity;sid:84766963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.68.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903862/; classtype:trojan-activity;sid:84766962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.228.239.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903861/; classtype:trojan-activity;sid:84766961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.106.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903860/; classtype:trojan-activity;sid:84766960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.34.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903859/; classtype:trojan-activity;sid:84766959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.32.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903858/; classtype:trojan-activity;sid:84766958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x86"; depth:9; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903852/; classtype:trojan-activity;sid:84766952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mips"; depth:10; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903853/; classtype:trojan-activity;sid:84766953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x86_64"; depth:12; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903854/; classtype:trojan-activity;sid:84766954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mpsl"; depth:10; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903855/; classtype:trojan-activity;sid:84766955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm"; depth:9; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903856/; classtype:trojan-activity;sid:84766956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_sh4"; depth:9; endswith; nocase; http.host; content:"62.60.249.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903857/; classtype:trojan-activity;sid:84766957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.68.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903851/; classtype:trojan-activity;sid:84766951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.203.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903850/; classtype:trojan-activity;sid:84766950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_f50d0ed2eef01870.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903849/; classtype:trojan-activity;sid:84766949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.133.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903848/; classtype:trojan-activity;sid:84766948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.252.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903847/; classtype:trojan-activity;sid:84766947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.78.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903846/; classtype:trojan-activity;sid:84766946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update_bde3c4.msi"; depth:18; endswith; nocase; http.host; content:"lomeqpe.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903845/; classtype:trojan-activity;sid:84766945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.32.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903844/; classtype:trojan-activity;sid:84766944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.78.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903843/; classtype:trojan-activity;sid:84766943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.4.125"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903842/; classtype:trojan-activity;sid:84766942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.93.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903841/; classtype:trojan-activity;sid:84766941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.69.88.195"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903840/; classtype:trojan-activity;sid:84766940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.183.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903839/; classtype:trojan-activity;sid:84766939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.93.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903838/; classtype:trojan-activity;sid:84766938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.72.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903837/; classtype:trojan-activity;sid:84766937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"138.255.178.214"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903836/; classtype:trojan-activity;sid:84766936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.139.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903835/; classtype:trojan-activity;sid:84766935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"138.255.178.214"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903834/; classtype:trojan-activity;sid:84766934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.31.205"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903833/; classtype:trojan-activity;sid:84766933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.174.68.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903832/; classtype:trojan-activity;sid:84766932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.39.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903831/; classtype:trojan-activity;sid:84766931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.139.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903830/; classtype:trojan-activity;sid:84766930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.165.236.7"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903829/; classtype:trojan-activity;sid:84766929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.146.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903828/; classtype:trojan-activity;sid:84766928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.165.236.7"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903827/; classtype:trojan-activity;sid:84766927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.174.68.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903826/; classtype:trojan-activity;sid:84766926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.201.110.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903825/; classtype:trojan-activity;sid:84766925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.201.110.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903824/; classtype:trojan-activity;sid:84766924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.113.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903823/; classtype:trojan-activity;sid:84766923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.177.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903822/; classtype:trojan-activity;sid:84766922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.70.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903821/; classtype:trojan-activity;sid:84766921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.229.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903820/; classtype:trojan-activity;sid:84766920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.177.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903819/; classtype:trojan-activity;sid:84766919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.18.71"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903818/; classtype:trojan-activity;sid:84766918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.18.71"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903817/; classtype:trojan-activity;sid:84766917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"1.58.182.84"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903816/; classtype:trojan-activity;sid:84766916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.192.252.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903815/; classtype:trojan-activity;sid:84766915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"179.108.89.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903814/; classtype:trojan-activity;sid:84766914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.250.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903813/; classtype:trojan-activity;sid:84766913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.250.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903812/; classtype:trojan-activity;sid:84766912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_8f2a9c058325ac38.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903811/; classtype:trojan-activity;sid:84766911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903810/; classtype:trojan-activity;sid:84766910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86"; depth:9; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903809/; classtype:trojan-activity;sid:84766909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm7"; depth:10; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903803/; classtype:trojan-activity;sid:84766903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm5"; depth:10; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903804/; classtype:trojan-activity;sid:84766904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_aarch64"; depth:13; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903805/; classtype:trojan-activity;sid:84766905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm6"; depth:10; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903806/; classtype:trojan-activity;sid:84766906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm4"; depth:10; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903807/; classtype:trojan-activity;sid:84766907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86_64"; depth:12; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903808/; classtype:trojan-activity;sid:84766908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_powerpc"; depth:13; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903802/; classtype:trojan-activity;sid:84766902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbc"; depth:4; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903801/; classtype:trojan-activity;sid:84766901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mips"; depth:10; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903800/; classtype:trojan-activity;sid:84766900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mipsel"; depth:12; endswith; nocase; http.host; content:"45.38.249.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903799/; classtype:trojan-activity;sid:84766899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.162.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903798/; classtype:trojan-activity;sid:84766898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.220.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903797/; classtype:trojan-activity;sid:84766897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.183.3.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903796/; classtype:trojan-activity;sid:84766896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.43.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903795/; classtype:trojan-activity;sid:84766895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"96.245.232.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903794/; classtype:trojan-activity;sid:84766894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.68.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903793/; classtype:trojan-activity;sid:84766893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.72.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903791/; classtype:trojan-activity;sid:84766891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"47.215.224.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903792/; classtype:trojan-activity;sid:84766892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.233.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903790/; classtype:trojan-activity;sid:84766890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.235.157.125"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903789/; classtype:trojan-activity;sid:84766889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"47.215.224.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903788/; classtype:trojan-activity;sid:84766888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.233.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903787/; classtype:trojan-activity;sid:84766887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.168.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903786/; classtype:trojan-activity;sid:84766886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.168.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903785/; classtype:trojan-activity;sid:84766885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.82.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903784/; classtype:trojan-activity;sid:84766884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.50.219"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903783/; classtype:trojan-activity;sid:84766883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903782/; classtype:trojan-activity;sid:84766882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.82.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903781/; classtype:trojan-activity;sid:84766881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.221.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903780/; classtype:trojan-activity;sid:84766880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.172.186.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903779/; classtype:trojan-activity;sid:84766879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903778/; classtype:trojan-activity;sid:84766878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.221.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903777/; classtype:trojan-activity;sid:84766877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.198.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903776/; classtype:trojan-activity;sid:84766876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.46.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903775/; classtype:trojan-activity;sid:84766875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.46.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903774/; classtype:trojan-activity;sid:84766874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.181.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903773/; classtype:trojan-activity;sid:84766873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.181.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903772/; classtype:trojan-activity;sid:84766872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.119.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903771/; classtype:trojan-activity;sid:84766871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"179.108.89.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903770/; classtype:trojan-activity;sid:84766870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.119.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903769/; classtype:trojan-activity;sid:84766869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.78.32"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903768/; classtype:trojan-activity;sid:84766868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.206.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903767/; classtype:trojan-activity;sid:84766867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.109.232.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903766/; classtype:trojan-activity;sid:84766866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.54.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903765/; classtype:trojan-activity;sid:84766865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.238.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903764/; classtype:trojan-activity;sid:84766864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.206.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903763/; classtype:trojan-activity;sid:84766863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.109.232.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903762/; classtype:trojan-activity;sid:84766862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.54.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903761/; classtype:trojan-activity;sid:84766861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.115.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903760/; classtype:trojan-activity;sid:84766860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.115.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903759/; classtype:trojan-activity;sid:84766859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.238.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903758/; classtype:trojan-activity;sid:84766858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.87.217.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903757/; classtype:trojan-activity;sid:84766857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.87.217.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903756/; classtype:trojan-activity;sid:84766856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader"; depth:7; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903755/; classtype:trojan-activity;sid:84766855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.exe"; depth:6; endswith; nocase; http.host; content:"serdaregitim.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903753/; classtype:trojan-activity;sid:84766853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/144.exe"; depth:8; endswith; nocase; http.host; content:"serdaregitim.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903754/; classtype:trojan-activity;sid:84766854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.50.219"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903752/; classtype:trojan-activity;sid:84766852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.52.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903751/; classtype:trojan-activity;sid:84766851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903750/; classtype:trojan-activity;sid:84766850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.86.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903749/; classtype:trojan-activity;sid:84766849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.36.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903748/; classtype:trojan-activity;sid:84766848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.18.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903747/; classtype:trojan-activity;sid:84766847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.152.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903746/; classtype:trojan-activity;sid:84766846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_59d28a25d618df87.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903745/; classtype:trojan-activity;sid:84766845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.36.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903744/; classtype:trojan-activity;sid:84766844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.101.179"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903743/; classtype:trojan-activity;sid:84766843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.193.159"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903742/; classtype:trojan-activity;sid:84766842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.70.197.245"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903741/; classtype:trojan-activity;sid:84766841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.136.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903740/; classtype:trojan-activity;sid:84766840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/installer-4"; depth:14; endswith; nocase; http.host; content:"87.120.104.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903739/; classtype:trojan-activity;sid:84766839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.228.87"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903738/; classtype:trojan-activity;sid:84766838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.186.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903737/; classtype:trojan-activity;sid:84766837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amd"; depth:4; endswith; nocase; http.host; content:"223.76.100.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903736/; classtype:trojan-activity;sid:84766836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syss"; depth:5; endswith; nocase; http.host; content:"223.76.100.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903735/; classtype:trojan-activity;sid:84766835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.69.88.195"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903734/; classtype:trojan-activity;sid:84766834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.203.31.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903733/; classtype:trojan-activity;sid:84766833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.188.223.103"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903732/; classtype:trojan-activity;sid:84766832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.242.62.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903731/; classtype:trojan-activity;sid:84766831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"140.237.6.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903729/; classtype:trojan-activity;sid:84766829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.39.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903730/; classtype:trojan-activity;sid:84766830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.220.238.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903728/; classtype:trojan-activity;sid:84766828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.120.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903727/; classtype:trojan-activity;sid:84766827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.220.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903725/; classtype:trojan-activity;sid:84766825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.226.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903726/; classtype:trojan-activity;sid:84766826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.228.239.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903723/; classtype:trojan-activity;sid:84766823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.151.73.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903724/; classtype:trojan-activity;sid:84766824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.85.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903707/; classtype:trojan-activity;sid:84766807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.159.186"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903708/; classtype:trojan-activity;sid:84766808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.129.144.52"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903709/; classtype:trojan-activity;sid:84766809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.232.174"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903710/; classtype:trojan-activity;sid:84766810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.229.171"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903711/; classtype:trojan-activity;sid:84766811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.230.51.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903712/; classtype:trojan-activity;sid:84766812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.18.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903713/; classtype:trojan-activity;sid:84766813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.14.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903714/; classtype:trojan-activity;sid:84766814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.85.134.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903715/; classtype:trojan-activity;sid:84766815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.215.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903716/; classtype:trojan-activity;sid:84766816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.221.246.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903717/; classtype:trojan-activity;sid:84766817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.2.23"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903718/; classtype:trojan-activity;sid:84766818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.197.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903719/; classtype:trojan-activity;sid:84766819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.46.36"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903720/; classtype:trojan-activity;sid:84766820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.118.145"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903721/; classtype:trojan-activity;sid:84766821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.195.40"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903722/; classtype:trojan-activity;sid:84766822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.14.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903704/; classtype:trojan-activity;sid:84766804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.159.186"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903705/; classtype:trojan-activity;sid:84766805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.185.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903706/; classtype:trojan-activity;sid:84766806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.228.87"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903701/; classtype:trojan-activity;sid:84766801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.2.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903702/; classtype:trojan-activity;sid:84766802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.151.64.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903703/; classtype:trojan-activity;sid:84766803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.194.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903696/; classtype:trojan-activity;sid:84766796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.58.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903697/; classtype:trojan-activity;sid:84766797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.218.50"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903698/; classtype:trojan-activity;sid:84766798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.233.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903699/; classtype:trojan-activity;sid:84766799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.149.219.183"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903700/; classtype:trojan-activity;sid:84766800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.215.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903691/; classtype:trojan-activity;sid:84766791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.85.134.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903692/; classtype:trojan-activity;sid:84766792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903693/; classtype:trojan-activity;sid:84766793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.195.76"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903694/; classtype:trojan-activity;sid:84766794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.33.47"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903695/; classtype:trojan-activity;sid:84766795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.132.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903680/; classtype:trojan-activity;sid:84766780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.151.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903681/; classtype:trojan-activity;sid:84766781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.185.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903682/; classtype:trojan-activity;sid:84766782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.189.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903683/; classtype:trojan-activity;sid:84766783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.173.78.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903684/; classtype:trojan-activity;sid:84766784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.9.35.137"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903685/; classtype:trojan-activity;sid:84766785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.5.247.27"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903686/; classtype:trojan-activity;sid:84766786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.18.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903687/; classtype:trojan-activity;sid:84766787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.175.7.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903688/; classtype:trojan-activity;sid:84766788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.169.147.128"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903689/; classtype:trojan-activity;sid:84766789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.143.37"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903690/; classtype:trojan-activity;sid:84766790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903678/; classtype:trojan-activity;sid:84766778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.241.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903679/; classtype:trojan-activity;sid:84766779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.197.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903676/; classtype:trojan-activity;sid:84766776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zot"; depth:4; endswith; nocase; http.host; content:"213.177.179.32"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903677/; classtype:trojan-activity;sid:84766777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.52.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903675/; classtype:trojan-activity;sid:84766775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.148.216.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903671/; classtype:trojan-activity;sid:84766771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.191.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903672/; classtype:trojan-activity;sid:84766772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.85.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903673/; classtype:trojan-activity;sid:84766773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.191.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903674/; classtype:trojan-activity;sid:84766774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.115.36.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903665/; classtype:trojan-activity;sid:84766765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.221.246.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903666/; classtype:trojan-activity;sid:84766766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.220.238.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903667/; classtype:trojan-activity;sid:84766767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.151.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903668/; classtype:trojan-activity;sid:84766768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.147.114"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903669/; classtype:trojan-activity;sid:84766769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.197.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903670/; classtype:trojan-activity;sid:84766770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.56.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903647/; classtype:trojan-activity;sid:84766747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.73.172.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903648/; classtype:trojan-activity;sid:84766748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.191.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903649/; classtype:trojan-activity;sid:84766749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.35.65"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903650/; classtype:trojan-activity;sid:84766750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.136.5.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903651/; classtype:trojan-activity;sid:84766751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.157.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903652/; classtype:trojan-activity;sid:84766752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"178.141.132.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903653/; classtype:trojan-activity;sid:84766753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.2.23"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903654/; classtype:trojan-activity;sid:84766754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.115.246.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903655/; classtype:trojan-activity;sid:84766755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.56.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903656/; classtype:trojan-activity;sid:84766756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.180.66.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903657/; classtype:trojan-activity;sid:84766757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.251.225.122"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903658/; classtype:trojan-activity;sid:84766758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.69.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903659/; classtype:trojan-activity;sid:84766759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"66.8.135.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903660/; classtype:trojan-activity;sid:84766760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.203.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903661/; classtype:trojan-activity;sid:84766761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"162.246.26.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903662/; classtype:trojan-activity;sid:84766762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.97.90.188"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903663/; classtype:trojan-activity;sid:84766763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.97.90.188"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903664/; classtype:trojan-activity;sid:84766764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.5.247.27"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903646/; classtype:trojan-activity;sid:84766746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.208.16.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903644/; classtype:trojan-activity;sid:84766744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.146.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903645/; classtype:trojan-activity;sid:84766745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.35.65"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903643/; classtype:trojan-activity;sid:84766743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.236.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903625/; classtype:trojan-activity;sid:84766725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.131.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903626/; classtype:trojan-activity;sid:84766726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.218.50"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903627/; classtype:trojan-activity;sid:84766727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.141.132.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903628/; classtype:trojan-activity;sid:84766728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.155.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903629/; classtype:trojan-activity;sid:84766729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.58.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903630/; classtype:trojan-activity;sid:84766730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.150.57.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903631/; classtype:trojan-activity;sid:84766731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.143.37"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903632/; classtype:trojan-activity;sid:84766732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.46.36"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903633/; classtype:trojan-activity;sid:84766733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.172.186.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903634/; classtype:trojan-activity;sid:84766734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.155.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903635/; classtype:trojan-activity;sid:84766735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.203.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903636/; classtype:trojan-activity;sid:84766736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.224.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903637/; classtype:trojan-activity;sid:84766737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.51.98"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903638/; classtype:trojan-activity;sid:84766738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.215.27"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903639/; classtype:trojan-activity;sid:84766739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.51.98"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903640/; classtype:trojan-activity;sid:84766740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.132.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903641/; classtype:trojan-activity;sid:84766741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.73.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903642/; classtype:trojan-activity;sid:84766742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.64.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903610/; classtype:trojan-activity;sid:84766710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.25.171.108"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903611/; classtype:trojan-activity;sid:84766711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.203.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903612/; classtype:trojan-activity;sid:84766712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.198.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903613/; classtype:trojan-activity;sid:84766713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.115.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903614/; classtype:trojan-activity;sid:84766714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.12.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903615/; classtype:trojan-activity;sid:84766715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"66.8.135.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903616/; classtype:trojan-activity;sid:84766716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"202.1.26.69"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903617/; classtype:trojan-activity;sid:84766717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.33.47"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903618/; classtype:trojan-activity;sid:84766718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.202.24.36"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903619/; classtype:trojan-activity;sid:84766719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.18.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903620/; classtype:trojan-activity;sid:84766720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.203.138.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903621/; classtype:trojan-activity;sid:84766721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.115.102.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903622/; classtype:trojan-activity;sid:84766722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.115.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903623/; classtype:trojan-activity;sid:84766723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"212.169.147.128"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903624/; classtype:trojan-activity;sid:84766724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.233.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903609/; classtype:trojan-activity;sid:84766709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.16.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903608/; classtype:trojan-activity;sid:84766708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.155.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903607/; classtype:trojan-activity;sid:84766707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.186.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903606/; classtype:trojan-activity;sid:84766706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.16.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903605/; classtype:trojan-activity;sid:84766705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.spc"; depth:15; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903604/; classtype:trojan-activity;sid:84766704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm7"; depth:16; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903594/; classtype:trojan-activity;sid:84766694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.sh4"; depth:15; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903595/; classtype:trojan-activity;sid:84766695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903596/; classtype:trojan-activity;sid:84766696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.ppc"; depth:15; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903597/; classtype:trojan-activity;sid:84766697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm6"; depth:16; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903598/; classtype:trojan-activity;sid:84766698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm"; depth:15; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903599/; classtype:trojan-activity;sid:84766699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm5"; depth:16; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903600/; classtype:trojan-activity;sid:84766700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.x86"; depth:15; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903601/; classtype:trojan-activity;sid:84766701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.m68k"; depth:16; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903602/; classtype:trojan-activity;sid:84766702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mpsl"; depth:16; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903603/; classtype:trojan-activity;sid:84766703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mips"; depth:16; endswith; nocase; http.host; content:"94.154.43.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903593/; classtype:trojan-activity;sid:84766693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"144.48.123.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903592/; classtype:trojan-activity;sid:84766692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.mips"; depth:14; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903590/; classtype:trojan-activity;sid:84766690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.powerpc-440fp"; depth:23; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903591/; classtype:trojan-activity;sid:84766691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.powerpc"; depth:17; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903585/; classtype:trojan-activity;sid:84766685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.mipsel"; depth:16; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903586/; classtype:trojan-activity;sid:84766686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.sh4"; depth:13; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903587/; classtype:trojan-activity;sid:84766687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.i586"; depth:14; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903588/; classtype:trojan-activity;sid:84766688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.i686"; depth:14; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903589/; classtype:trojan-activity;sid:84766689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.m68k"; depth:14; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903579/; classtype:trojan-activity;sid:84766679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv4tl"; depth:17; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903580/; classtype:trojan-activity;sid:84766680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv4eb"; depth:17; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903581/; classtype:trojan-activity;sid:84766681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.x86_64"; depth:16; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903582/; classtype:trojan-activity;sid:84766682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.mips64"; depth:16; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903583/; classtype:trojan-activity;sid:84766683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv4l"; depth:16; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903584/; classtype:trojan-activity;sid:84766684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv7l"; depth:16; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903576/; classtype:trojan-activity;sid:84766676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.i486"; depth:14; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903577/; classtype:trojan-activity;sid:84766677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv5l"; depth:16; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903578/; classtype:trojan-activity;sid:84766678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv6l"; depth:16; endswith; nocase; http.host; content:"176.65.139.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903575/; classtype:trojan-activity;sid:84766675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c1"; depth:3; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903572/; classtype:trojan-activity;sid:84766672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c2"; depth:3; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903573/; classtype:trojan-activity;sid:84766673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903574/; classtype:trojan-activity;sid:84766674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903567/; classtype:trojan-activity;sid:84766667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i686"; depth:10; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903568/; classtype:trojan-activity;sid:84766668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903569/; classtype:trojan-activity;sid:84766669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903570/; classtype:trojan-activity;sid:84766670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903571/; classtype:trojan-activity;sid:84766671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903566/; classtype:trojan-activity;sid:84766666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903563/; classtype:trojan-activity;sid:84766663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d.sh"; depth:5; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903564/; classtype:trojan-activity;sid:84766664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903565/; classtype:trojan-activity;sid:84766665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903558/; classtype:trojan-activity;sid:84766658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903559/; classtype:trojan-activity;sid:84766659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903560/; classtype:trojan-activity;sid:84766660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903561/; classtype:trojan-activity;sid:84766661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dbg"; depth:9; endswith; nocase; http.host; content:"176.65.139.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903562/; classtype:trojan-activity;sid:84766662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom_bins/phantom.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903557/; classtype:trojan-activity;sid:84766657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom_bins/phantom.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903556/; classtype:trojan-activity;sid:84766656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom_bash.sh"; depth:16; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903555/; classtype:trojan-activity;sid:84766655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom_bins/phantom.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903554/; classtype:trojan-activity;sid:84766654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.191.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903553/; classtype:trojan-activity;sid:84766653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.11.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903552/; classtype:trojan-activity;sid:84766652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/givingbesthingsforbetterforme.hta"; depth:37; endswith; nocase; http.host; content:"209.54.103.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903551/; classtype:trojan-activity;sid:84766651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"144.48.123.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903550/; classtype:trojan-activity;sid:84766650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.mpsl"; depth:11; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903549/; classtype:trojan-activity;sid:84766649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.11.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903548/; classtype:trojan-activity;sid:84766648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.155.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903547/; classtype:trojan-activity;sid:84766647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.120.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903546/; classtype:trojan-activity;sid:84766646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.120.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903545/; classtype:trojan-activity;sid:84766645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.194.25.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903544/; classtype:trojan-activity;sid:84766644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.194.25.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903543/; classtype:trojan-activity;sid:84766643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.115.36.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903542/; classtype:trojan-activity;sid:84766642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.160.130.168"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903541/; classtype:trojan-activity;sid:84766641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1903e1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903529/; classtype:trojan-activity;sid:84766629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/320b53"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903530/; classtype:trojan-activity;sid:84766630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8413a4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903531/; classtype:trojan-activity;sid:84766631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eb77a9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903532/; classtype:trojan-activity;sid:84766632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/671030"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903533/; classtype:trojan-activity;sid:84766633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c99e43"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903534/; classtype:trojan-activity;sid:84766634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60f898"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903535/; classtype:trojan-activity;sid:84766635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/657b82"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903536/; classtype:trojan-activity;sid:84766636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70d8b3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903537/; classtype:trojan-activity;sid:84766637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8bf1cf"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903538/; classtype:trojan-activity;sid:84766638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/828087"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903539/; classtype:trojan-activity;sid:84766639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/90cb09"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903540/; classtype:trojan-activity;sid:84766640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oj0sd4fl/image/upload/v1786666071/img_200726.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903528/; classtype:trojan-activity;sid:84766628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/30/wegivingbestsolutionforbestthings.hta"; depth:41; endswith; nocase; http.host; content:"204.77.9.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903526/; classtype:trojan-activity;sid:84766626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_081951.png"; depth:19; endswith; nocase; http.host; content:"204.77.9.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903527/; classtype:trojan-activity;sid:84766627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7a276a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903517/; classtype:trojan-activity;sid:84766617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6d0d44"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903518/; classtype:trojan-activity;sid:84766618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44066b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903519/; classtype:trojan-activity;sid:84766619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/035755"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903520/; classtype:trojan-activity;sid:84766620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e44028"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903521/; classtype:trojan-activity;sid:84766621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fff372"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903522/; classtype:trojan-activity;sid:84766622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00d054"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903523/; classtype:trojan-activity;sid:84766623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/748306"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903524/; classtype:trojan-activity;sid:84766624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/28d4d8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903525/; classtype:trojan-activity;sid:84766625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/174cb4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903501/; classtype:trojan-activity;sid:84766601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3a2ee0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903502/; classtype:trojan-activity;sid:84766602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ff1781"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903503/; classtype:trojan-activity;sid:84766603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aecb15"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903504/; classtype:trojan-activity;sid:84766604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/171868"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903505/; classtype:trojan-activity;sid:84766605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c5d620"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903506/; classtype:trojan-activity;sid:84766606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e2ee47"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903507/; classtype:trojan-activity;sid:84766607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45cbd5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903508/; classtype:trojan-activity;sid:84766608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6a2daa"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903509/; classtype:trojan-activity;sid:84766609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d3a258"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903510/; classtype:trojan-activity;sid:84766610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ca6953"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903511/; classtype:trojan-activity;sid:84766611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/51fc22"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903512/; classtype:trojan-activity;sid:84766612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/powerpc"; depth:8; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903513/; classtype:trojan-activity;sid:84766613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3cf53c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903514/; classtype:trojan-activity;sid:84766614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3abc4d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903515/; classtype:trojan-activity;sid:84766615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/537b66"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903516/; classtype:trojan-activity;sid:84766616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cd5c35"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903489/; classtype:trojan-activity;sid:84766589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/61d4b3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903490/; classtype:trojan-activity;sid:84766590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c8bc3c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903491/; classtype:trojan-activity;sid:84766591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8cf703"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903492/; classtype:trojan-activity;sid:84766592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/98953a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903493/; classtype:trojan-activity;sid:84766593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/03ab36"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903494/; classtype:trojan-activity;sid:84766594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e1bf38"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903495/; classtype:trojan-activity;sid:84766595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1b9ac2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903496/; classtype:trojan-activity;sid:84766596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c3106e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903497/; classtype:trojan-activity;sid:84766597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/61f089"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903498/; classtype:trojan-activity;sid:84766598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dcdd69"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903499/; classtype:trojan-activity;sid:84766599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1d49dd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903500/; classtype:trojan-activity;sid:84766600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.252.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903488/; classtype:trojan-activity;sid:84766588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.ppc"; depth:10; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903487/; classtype:trojan-activity;sid:84766587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update/exe"; depth:11; endswith; nocase; http.host; content:"nodemetrics3379.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903486/; classtype:trojan-activity;sid:84766586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.x86_64"; depth:13; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903483/; classtype:trojan-activity;sid:84766583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.spc"; depth:10; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903484/; classtype:trojan-activity;sid:84766584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.arm7"; depth:11; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903485/; classtype:trojan-activity;sid:84766585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.arm5"; depth:11; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903481/; classtype:trojan-activity;sid:84766581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.i586"; depth:11; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903482/; classtype:trojan-activity;sid:84766582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.sh4"; depth:10; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903478/; classtype:trojan-activity;sid:84766578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.m68k"; depth:11; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903479/; classtype:trojan-activity;sid:84766579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.mips"; depth:11; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903480/; classtype:trojan-activity;sid:84766580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/old/msi_pro.png"; depth:16; endswith; nocase; http.host; content:"seasquadshipping.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903476/; classtype:trojan-activity;sid:84766576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/old/img_155944.png"; depth:19; endswith; nocase; http.host; content:"seasquadshipping.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903477/; classtype:trojan-activity;sid:84766577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.arm"; depth:10; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903475/; classtype:trojan-activity;sid:84766575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/setup.rar"; depth:10; endswith; nocase; http.host; content:"smmnet.store"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903474/; classtype:trojan-activity;sid:84766574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.104.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903473/; classtype:trojan-activity;sid:84766573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.104.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903472/; classtype:trojan-activity;sid:84766572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/7hp56yj650o4slrllg4xj/chilloutvrmod.exe|3f|rlkey=s69vdpczdpalbo26alwo0u13o|7c|26|7c|st=f5mgwsxk|7c|26|7c|dl=1"; depth:117; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903471/; classtype:trojan-activity;sid:84766571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/otfakqkze127a701il1zh/vrmod_setup.exe|3f|rlkey=deryztzard7w3n2btuqo7ivvd|7c|26|7c|st=48dlc6qm|7c|26|7c|dl=1"; depth:115; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903470/; classtype:trojan-activity;sid:84766570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"36.70.68.244"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903469/; classtype:trojan-activity;sid:84766569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg11"; depth:5; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903468/; classtype:trojan-activity;sid:84766568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_2f5216405eb2fec9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903467/; classtype:trojan-activity;sid:84766567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/test.bef_fri"; depth:18; endswith; nocase; http.host; content:"217.60.36.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903466/; classtype:trojan-activity;sid:84766566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_7cba58e6cdbbfa7e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903461/; classtype:trojan-activity;sid:84766561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/william/wi.txt"; depth:15; endswith; nocase; http.host; content:"217.60.36.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903462/; classtype:trojan-activity;sid:84766562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/p.txt"; depth:11; endswith; nocase; http.host; content:"217.60.36.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903463/; classtype:trojan-activity;sid:84766563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/t.php"; depth:11; endswith; nocase; http.host; content:"217.60.36.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903464/; classtype:trojan-activity;sid:84766564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/william/mort.php"; depth:17; endswith; nocase; http.host; content:"217.60.36.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903465/; classtype:trojan-activity;sid:84766565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ftpget"; depth:7; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903458/; classtype:trojan-activity;sid:84766558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_583f8856851a870c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903459/; classtype:trojan-activity;sid:84766559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_529348465823b047.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903460/; classtype:trojan-activity;sid:84766560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.252.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903457/; classtype:trojan-activity;sid:84766557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t"; depth:2; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903456/; classtype:trojan-activity;sid:84766556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.217.97.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903454/; classtype:trojan-activity;sid:84766554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.217.97.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903455/; classtype:trojan-activity;sid:84766555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tbk_stage1.sh"; depth:14; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903453/; classtype:trojan-activity;sid:84766553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.70.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903452/; classtype:trojan-activity;sid:84766552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903451/; classtype:trojan-activity;sid:84766551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903450/; classtype:trojan-activity;sid:84766550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svchost.exe"; depth:12; endswith; nocase; http.host; content:"217.60.241.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903449/; classtype:trojan-activity;sid:84766549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_arm7"; depth:11; endswith; nocase; http.host; content:"144.31.30.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903443/; classtype:trojan-activity;sid:84766543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_arm64"; depth:12; endswith; nocase; http.host; content:"144.31.30.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903444/; classtype:trojan-activity;sid:84766544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_mips"; depth:11; endswith; nocase; http.host; content:"144.31.30.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903445/; classtype:trojan-activity;sid:84766545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_mips64"; depth:13; endswith; nocase; http.host; content:"144.31.30.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903446/; classtype:trojan-activity;sid:84766546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_arm5"; depth:11; endswith; nocase; http.host; content:"144.31.30.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903447/; classtype:trojan-activity;sid:84766547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_amd64"; depth:12; endswith; nocase; http.host; content:"144.31.30.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903448/; classtype:trojan-activity;sid:84766548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.x86_64"; depth:15; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903442/; classtype:trojan-activity;sid:84766542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903440/; classtype:trojan-activity;sid:84766540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903441/; classtype:trojan-activity;sid:84766541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.sh4"; depth:12; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903425/; classtype:trojan-activity;sid:84766525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903426/; classtype:trojan-activity;sid:84766526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.mips"; depth:13; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903427/; classtype:trojan-activity;sid:84766527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dbg"; depth:9; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903428/; classtype:trojan-activity;sid:84766528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903429/; classtype:trojan-activity;sid:84766529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903430/; classtype:trojan-activity;sid:84766530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903431/; classtype:trojan-activity;sid:84766531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.i686"; depth:13; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903432/; classtype:trojan-activity;sid:84766532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903433/; classtype:trojan-activity;sid:84766533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903434/; classtype:trojan-activity;sid:84766534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903435/; classtype:trojan-activity;sid:84766535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.m68k"; depth:13; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903436/; classtype:trojan-activity;sid:84766536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i686"; depth:10; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903437/; classtype:trojan-activity;sid:84766537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903438/; classtype:trojan-activity;sid:84766538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"2.26.81.46"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903439/; classtype:trojan-activity;sid:84766539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"2.26.81.123"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903424/; classtype:trojan-activity;sid:84766524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; depth:32; endswith; nocase; http.host; content:"2.26.81.123"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903423/; classtype:trojan-activity;sid:84766523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.231.100.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903422/; classtype:trojan-activity;sid:84766522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.32.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903421/; classtype:trojan-activity;sid:84766521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.32.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903420/; classtype:trojan-activity;sid:84766520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv6l"; depth:7; endswith; nocase; http.host; content:"31.76.20.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903418/; classtype:trojan-activity;sid:84766518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"31.76.20.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903419/; classtype:trojan-activity;sid:84766519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"31.76.20.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903412/; classtype:trojan-activity;sid:84766512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"31.76.20.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903413/; classtype:trojan-activity;sid:84766513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"31.76.20.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903414/; classtype:trojan-activity;sid:84766514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"31.76.20.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903415/; classtype:trojan-activity;sid:84766515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc64"; depth:6; endswith; nocase; http.host; content:"31.76.20.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903416/; classtype:trojan-activity;sid:84766516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv5l"; depth:7; endswith; nocase; http.host; content:"31.76.20.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903417/; classtype:trojan-activity;sid:84766517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.154.98.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903411/; classtype:trojan-activity;sid:84766511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.231.100.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903410/; classtype:trojan-activity;sid:84766510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.154.98.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903409/; classtype:trojan-activity;sid:84766509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.1.247.58"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903408/; classtype:trojan-activity;sid:84766508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.156.239"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903407/; classtype:trojan-activity;sid:84766507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.64.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903406/; classtype:trojan-activity;sid:84766506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.191.195"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903405/; classtype:trojan-activity;sid:84766505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.188.75.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903404/; classtype:trojan-activity;sid:84766504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.167.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903403/; classtype:trojan-activity;sid:84766503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.188.75.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903402/; classtype:trojan-activity;sid:84766502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.118.241.30"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903401/; classtype:trojan-activity;sid:84766501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.167.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903400/; classtype:trojan-activity;sid:84766500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.174.107.238"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903399/; classtype:trojan-activity;sid:84766499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.191.195"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903398/; classtype:trojan-activity;sid:84766498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.101.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903397/; classtype:trojan-activity;sid:84766497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.186.231.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903396/; classtype:trojan-activity;sid:84766496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.199.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903395/; classtype:trojan-activity;sid:84766495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.186.231.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903394/; classtype:trojan-activity;sid:84766494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.113.190"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903393/; classtype:trojan-activity;sid:84766493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.0.112.226"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903392/; classtype:trojan-activity;sid:84766492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.40.8"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903391/; classtype:trojan-activity;sid:84766491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.79.136.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903390/; classtype:trojan-activity;sid:84766490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.232.182"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903389/; classtype:trojan-activity;sid:84766489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.165.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903388/; classtype:trojan-activity;sid:84766488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.6.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903387/; classtype:trojan-activity;sid:84766487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.1.26.69"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903386/; classtype:trojan-activity;sid:84766486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.104.54"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903385/; classtype:trojan-activity;sid:84766485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.165.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903384/; classtype:trojan-activity;sid:84766484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.111.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903383/; classtype:trojan-activity;sid:84766483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.6.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903382/; classtype:trojan-activity;sid:84766482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.172.186.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903381/; classtype:trojan-activity;sid:84766481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.76.206.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903380/; classtype:trojan-activity;sid:84766480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.0.112.226"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903379/; classtype:trojan-activity;sid:84766479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.113.190"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903378/; classtype:trojan-activity;sid:84766478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.140.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903377/; classtype:trojan-activity;sid:84766477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.111.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903376/; classtype:trojan-activity;sid:84766476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.172.186.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903375/; classtype:trojan-activity;sid:84766475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.228.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903374/; classtype:trojan-activity;sid:84766474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telegram_v12.8.3.apk"; depth:21; endswith; nocase; http.host; content:"down.unicron-cdn.click"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903373/; classtype:trojan-activity;sid:84766473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.231.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903372/; classtype:trojan-activity;sid:84766472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.223.141.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903371/; classtype:trojan-activity;sid:84766471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.228.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903370/; classtype:trojan-activity;sid:84766470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.mips"; depth:10; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903366/; classtype:trojan-activity;sid:84766466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm7"; depth:10; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903367/; classtype:trojan-activity;sid:84766467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.sh4"; depth:9; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903368/; classtype:trojan-activity;sid:84766468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.x86"; depth:9; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903369/; classtype:trojan-activity;sid:84766469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.i686"; depth:10; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903365/; classtype:trojan-activity;sid:84766465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm5"; depth:10; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903364/; classtype:trojan-activity;sid:84766464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.i486"; depth:10; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903362/; classtype:trojan-activity;sid:84766462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.x86"; depth:9; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903363/; classtype:trojan-activity;sid:84766463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.ppc"; depth:9; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903357/; classtype:trojan-activity;sid:84766457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.sparc"; depth:11; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903358/; classtype:trojan-activity;sid:84766458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm6"; depth:10; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903359/; classtype:trojan-activity;sid:84766459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.m68k"; depth:10; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903360/; classtype:trojan-activity;sid:84766460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.mipsel"; depth:12; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903361/; classtype:trojan-activity;sid:84766461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.x64"; depth:9; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903355/; classtype:trojan-activity;sid:84766455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm7"; depth:10; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903356/; classtype:trojan-activity;sid:84766456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm5"; depth:10; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903354/; classtype:trojan-activity;sid:84766454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.i486"; depth:10; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903353/; classtype:trojan-activity;sid:84766453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.ppc440"; depth:12; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903345/; classtype:trojan-activity;sid:84766445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm4"; depth:10; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903346/; classtype:trojan-activity;sid:84766446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm6"; depth:10; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903347/; classtype:trojan-activity;sid:84766447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.sh4"; depth:9; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903348/; classtype:trojan-activity;sid:84766448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.sparc"; depth:11; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903349/; classtype:trojan-activity;sid:84766449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.ppc"; depth:9; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903350/; classtype:trojan-activity;sid:84766450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.mipsel"; depth:12; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903351/; classtype:trojan-activity;sid:84766451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.m68k"; depth:10; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903352/; classtype:trojan-activity;sid:84766452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.i686"; depth:10; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903339/; classtype:trojan-activity;sid:84766439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.ppc440"; depth:12; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903340/; classtype:trojan-activity;sid:84766440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.arm4"; depth:10; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903341/; classtype:trojan-activity;sid:84766441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dp.sh"; depth:6; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903342/; classtype:trojan-activity;sid:84766442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.x64"; depth:9; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903343/; classtype:trojan-activity;sid:84766443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pito.mips"; depth:10; endswith; nocase; http.host; content:"150.241.65.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903344/; classtype:trojan-activity;sid:84766444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.223.141.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903338/; classtype:trojan-activity;sid:84766438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.130.28"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903337/; classtype:trojan-activity;sid:84766437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.73.172.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903336/; classtype:trojan-activity;sid:84766436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.69.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903335/; classtype:trojan-activity;sid:84766435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.207.229.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903334/; classtype:trojan-activity;sid:84766434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypted.exe"; depth:12; endswith; nocase; http.host; content:"tarkioweb.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903333/; classtype:trojan-activity;sid:84766433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"172.104.49.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903327/; classtype:trojan-activity;sid:84766427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mipsel"; depth:11; endswith; nocase; http.host; content:"172.104.49.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903328/; classtype:trojan-activity;sid:84766428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"172.104.49.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903329/; classtype:trojan-activity;sid:84766429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.aarch64"; depth:12; endswith; nocase; http.host; content:"172.104.49.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903330/; classtype:trojan-activity;sid:84766430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"172.104.49.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903331/; classtype:trojan-activity;sid:84766431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc"; depth:8; endswith; nocase; http.host; content:"172.104.49.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903332/; classtype:trojan-activity;sid:84766432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.sh4"; depth:8; endswith; nocase; http.host; content:"172.104.49.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903326/; classtype:trojan-activity;sid:84766426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"154.90.70.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903325/; classtype:trojan-activity;sid:84766425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"172.104.49.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903323/; classtype:trojan-activity;sid:84766423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"172-104-49-49.ip.linodeusercontent.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903324/; classtype:trojan-activity;sid:84766424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.197.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903322/; classtype:trojan-activity;sid:84766422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.197.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903321/; classtype:trojan-activity;sid:84766421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/tbk"; depth:7; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903320/; classtype:trojan-activity;sid:84766420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.138.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903319/; classtype:trojan-activity;sid:84766419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86_64"; depth:10; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903318/; classtype:trojan-activity;sid:84766418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/aarch64"; depth:11; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903316/; classtype:trojan-activity;sid:84766416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/sh4"; depth:7; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903317/; classtype:trojan-activity;sid:84766417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86"; depth:7; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903308/; classtype:trojan-activity;sid:84766408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv4l"; depth:10; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903309/; classtype:trojan-activity;sid:84766409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv5l"; depth:10; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903310/; classtype:trojan-activity;sid:84766410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv6l"; depth:10; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903311/; classtype:trojan-activity;sid:84766411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv7l"; depth:10; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903312/; classtype:trojan-activity;sid:84766412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/m68k"; depth:8; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903313/; classtype:trojan-activity;sid:84766413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/sparc"; depth:9; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903314/; classtype:trojan-activity;sid:84766414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/ppc"; depth:7; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903315/; classtype:trojan-activity;sid:84766415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"144.31.167.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903307/; classtype:trojan-activity;sid:84766407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p"; depth:2; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903296/; classtype:trojan-activity;sid:84766396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s"; depth:2; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903297/; classtype:trojan-activity;sid:84766397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903298/; classtype:trojan-activity;sid:84766398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/j"; depth:2; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903299/; classtype:trojan-activity;sid:84766399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tp"; depth:3; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903300/; classtype:trojan-activity;sid:84766400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gs"; depth:3; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903301/; classtype:trojan-activity;sid:84766401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m"; depth:2; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903302/; classtype:trojan-activity;sid:84766402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mp"; depth:3; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903303/; classtype:trojan-activity;sid:84766403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/u"; depth:2; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903304/; classtype:trojan-activity;sid:84766404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tr"; depth:3; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903305/; classtype:trojan-activity;sid:84766405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g"; depth:2; endswith; nocase; http.host; content:"144.31.147.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903306/; classtype:trojan-activity;sid:84766406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mips"; depth:8; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903295/; classtype:trojan-activity;sid:84766395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mpsl"; depth:8; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903293/; classtype:trojan-activity;sid:84766393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/lterouter"; depth:13; endswith; nocase; http.host; content:"160.119.71.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903294/; classtype:trojan-activity;sid:84766394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/123"; depth:4; endswith; nocase; http.host; content:"38.76.206.4"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903292/; classtype:trojan-activity;sid:84766392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linpeas.sh"; depth:11; endswith; nocase; http.host; content:"209.141.53.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903291/; classtype:trojan-activity;sid:84766391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dns"; depth:4; endswith; nocase; http.host; content:"209.141.51.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903290/; classtype:trojan-activity;sid:84766390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"124.198.131.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903289/; classtype:trojan-activity;sid:84766389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"124.198.131.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903288/; classtype:trojan-activity;sid:84766388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"45.83.31.84"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903287/; classtype:trojan-activity;sid:84766387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"45.83.31.84"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903286/; classtype:trojan-activity;sid:84766386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903283/; classtype:trojan-activity;sid:84766383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903284/; classtype:trojan-activity;sid:84766384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903285/; classtype:trojan-activity;sid:84766385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903281/; classtype:trojan-activity;sid:84766381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903282/; classtype:trojan-activity;sid:84766382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903278/; classtype:trojan-activity;sid:84766378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903279/; classtype:trojan-activity;sid:84766379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903280/; classtype:trojan-activity;sid:84766380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903276/; classtype:trojan-activity;sid:84766376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903277/; classtype:trojan-activity;sid:84766377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903275/; classtype:trojan-activity;sid:84766375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903274/; classtype:trojan-activity;sid:84766374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64nosl"; depth:17; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903273/; classtype:trojan-activity;sid:84766373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.186.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903272/; classtype:trojan-activity;sid:84766372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.186.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903271/; classtype:trojan-activity;sid:84766371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/5917492177/o0kqsez.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903270/; classtype:trojan-activity;sid:84766370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.210.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903269/; classtype:trojan-activity;sid:84766369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/praise/agent%20hype.bin"; depth:24; endswith; nocase; http.host; content:"sumiko.vu"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903268/; classtype:trojan-activity;sid:84766368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego/stego_7mpp3kpd10.png"; depth:27; endswith; nocase; http.host; content:"aeplled.cfd"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903267/; classtype:trojan-activity;sid:84766367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hypeeaugustbless2026.exe"; depth:25; endswith; nocase; http.host; content:"midle-eastcompany.com"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903266/; classtype:trojan-activity;sid:84766366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/super%20agent.exe"; depth:18; endswith; nocase; http.host; content:"totalfitting.com.au"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903265/; classtype:trojan-activity;sid:84766365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_005219.png"; depth:15; endswith; nocase; http.host; content:"suppliers.lovestoblog.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903263/; classtype:trojan-activity;sid:84766363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neoky"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903262/; classtype:trojan-activity;sid:84766362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bagcorn.png"; depth:12; endswith; nocase; http.host; content:"pub-8ce03602555a436b80dbe377ce6f81de.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903261/; classtype:trojan-activity;sid:84766361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aphelope.hta"; depth:13; endswith; nocase; http.host; content:"pub-7bb797b9d5664a109b755165099495ac.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903260/; classtype:trojan-activity;sid:84766360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drumwork.png"; depth:13; endswith; nocase; http.host; content:"pub-8ce03602555a436b80dbe377ce6f81de.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903259/; classtype:trojan-activity;sid:84766359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5483b5101365b3ed.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903258/; classtype:trojan-activity;sid:84766358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.203.138.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903257/; classtype:trojan-activity;sid:84766357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5ff61cd0b7de191e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903256/; classtype:trojan-activity;sid:84766356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.mipsel"; depth:15; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903255/; classtype:trojan-activity;sid:84766355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv7l"; depth:15; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903254/; classtype:trojan-activity;sid:84766354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.i586"; depth:13; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903253/; classtype:trojan-activity;sid:84766353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv6l"; depth:15; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903250/; classtype:trojan-activity;sid:84766350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv4l"; depth:15; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903251/; classtype:trojan-activity;sid:84766351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.armv5l"; depth:15; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903252/; classtype:trojan-activity;sid:84766352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.sh4"; depth:12; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903245/; classtype:trojan-activity;sid:84766345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.powerpc"; depth:16; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903246/; classtype:trojan-activity;sid:84766346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.m68k"; depth:13; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903247/; classtype:trojan-activity;sid:84766347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.i686"; depth:13; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903248/; classtype:trojan-activity;sid:84766348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.mips"; depth:13; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903249/; classtype:trojan-activity;sid:84766349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.x86_64"; depth:28; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903244/; classtype:trojan-activity;sid:84766344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.mips"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903242/; classtype:trojan-activity;sid:84766342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/pryznet.arm"; depth:25; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903243/; classtype:trojan-activity;sid:84766343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"138.204.196.136"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903241/; classtype:trojan-activity;sid:84766341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_02013378a7416297.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903240/; classtype:trojan-activity;sid:84766340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/weneedbestthingsfromtheheartforbest.js"; depth:42; endswith; nocase; http.host; content:"209.54.103.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903239/; classtype:trojan-activity;sid:84766339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/40/jsload.hta"; depth:14; endswith; nocase; http.host; content:"209.54.103.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903238/; classtype:trojan-activity;sid:84766338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_014740.png"; depth:15; endswith; nocase; http.host; content:"stratagemzw.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903237/; classtype:trojan-activity;sid:84766337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/update.exe"; depth:30; endswith; nocase; http.host; content:"dasberlinerhotel.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903236/; classtype:trojan-activity;sid:84766336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikeweed2/work/refs/heads/main/rmc.exe"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903235/; classtype:trojan-activity;sid:84766335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_014220.png"; depth:15; endswith; nocase; http.host; content:"stratagemzw.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903234/; classtype:trojan-activity;sid:84766334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_pro.png"; depth:12; endswith; nocase; http.host; content:"www.stratagemzw.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903233/; classtype:trojan-activity;sid:84766333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.189.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903232/; classtype:trojan-activity;sid:84766332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.mpsl"; depth:27; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903226/; classtype:trojan-activity;sid:84766326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.arm4"; depth:27; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903227/; classtype:trojan-activity;sid:84766327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.arm7"; depth:27; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903228/; classtype:trojan-activity;sid:84766328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.ppc"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903229/; classtype:trojan-activity;sid:84766329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.mips"; depth:27; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903230/; classtype:trojan-activity;sid:84766330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.arm6"; depth:27; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903231/; classtype:trojan-activity;sid:84766331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.x86"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903222/; classtype:trojan-activity;sid:84766322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.m68k"; depth:27; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903223/; classtype:trojan-activity;sid:84766323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.arm5"; depth:27; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903224/; classtype:trojan-activity;sid:84766324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389242390482/3xmytpon.sh4"; depth:26; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903225/; classtype:trojan-activity;sid:84766325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/roya/stego_4vsu6x7ai8.png"; depth:30; endswith; nocase; http.host; content:"sarafinance.in"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903221/; classtype:trojan-activity;sid:84766321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.2.151.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903220/; classtype:trojan-activity;sid:84766320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"203.2.151.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903219/; classtype:trojan-activity;sid:84766319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3xmytp.sh"; depth:10; endswith; nocase; http.host; content:"31.76.29.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903218/; classtype:trojan-activity;sid:84766318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.9.35.137"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903217/; classtype:trojan-activity;sid:84766317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flyudfg.png"; depth:12; endswith; nocase; http.host; content:"192.109.139.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903216/; classtype:trojan-activity;sid:84766316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hdgftyu.png"; depth:12; endswith; nocase; http.host; content:"192.109.139.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903214/; classtype:trojan-activity;sid:84766314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/services/img.png"; depth:17; endswith; nocase; http.host; content:"medicosantiagomarrero.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903215/; classtype:trojan-activity;sid:84766315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vehiculos/msi_pro.png"; depth:22; endswith; nocase; http.host; content:"munihuacho.gob.pe"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903213/; classtype:trojan-activity;sid:84766313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wlsah"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903212/; classtype:trojan-activity;sid:84766312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vehiculos/img_065018.png"; depth:25; endswith; nocase; http.host; content:"munihuacho.gob.pe"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903211/; classtype:trojan-activity;sid:84766311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/google.exe"; depth:11; endswith; nocase; http.host; content:"rcf.co.mz"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903210/; classtype:trojan-activity;sid:84766310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wd1337"; depth:7; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903207/; classtype:trojan-activity;sid:84766307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wd1337"; depth:7; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903208/; classtype:trojan-activity;sid:84766308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/log"; depth:4; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903209/; classtype:trojan-activity;sid:84766309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proot"; depth:6; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903203/; classtype:trojan-activity;sid:84766303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/admin/bin.exe"; depth:25; endswith; nocase; http.host; content:"glbeletronica.com.br"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903204/; classtype:trojan-activity;sid:84766304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/admin/client_20260811_035917.exe"; depth:44; endswith; nocase; http.host; content:"glbeletronica.com.br"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903205/; classtype:trojan-activity;sid:84766305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/error84"; depth:8; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903206/; classtype:trojan-activity;sid:84766306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cli"; depth:4; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903201/; classtype:trojan-activity;sid:84766301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main"; depth:5; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903202/; classtype:trojan-activity;sid:84766302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syst3md"; depth:8; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903198/; classtype:trojan-activity;sid:84766298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a/am11binupload.txt"; depth:20; endswith; nocase; http.host; content:"my-buck01.s3.cubbit.eu"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903199/; classtype:trojan-activity;sid:84766299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a/silv-rawfileupload%20(2).txt"; depth:31; endswith; nocase; http.host; content:"my-buck01.s3.cubbit.eu"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903200/; classtype:trojan-activity;sid:84766300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/forbes.exe"; depth:11; endswith; nocase; http.host; content:"rcf.co.mz"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903196/; classtype:trojan-activity;sid:84766296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/admin/teleg.exe"; depth:27; endswith; nocase; http.host; content:"glbeletronica.com.br"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903197/; classtype:trojan-activity;sid:84766297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/admin/bin44.exe"; depth:27; endswith; nocase; http.host; content:"glbeletronica.com.br"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903194/; classtype:trojan-activity;sid:84766294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cliaarch"; depth:9; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903195/; classtype:trojan-activity;sid:84766295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.57.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903191/; classtype:trojan-activity;sid:84766291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss"; depth:5; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903192/; classtype:trojan-activity;sid:84766292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldboss"; depth:8; endswith; nocase; http.host; content:"botnet.botnet.xd.67.flightleaks.xyz"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903193/; classtype:trojan-activity;sid:84766293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypted1.ps1"; depth:13; endswith; nocase; http.host; content:"malaysianpastrybakery.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903190/; classtype:trojan-activity;sid:84766290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/admin/"; depth:18; endswith; nocase; http.host; content:"glbeletronica.com.br"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903189/; classtype:trojan-activity;sid:84766289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ind8inc/crypted.ps1"; depth:20; endswith; nocase; http.host; content:"mnurlogistics.az"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903188/; classtype:trojan-activity;sid:84766288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cli"; depth:4; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903183/; classtype:trojan-activity;sid:84766283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/error84"; depth:8; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903184/; classtype:trojan-activity;sid:84766284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syst3md"; depth:8; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903185/; classtype:trojan-activity;sid:84766285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/error84"; depth:8; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903186/; classtype:trojan-activity;sid:84766286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wd1337"; depth:7; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903187/; classtype:trojan-activity;sid:84766287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main"; depth:5; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903181/; classtype:trojan-activity;sid:84766281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main"; depth:5; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903182/; classtype:trojan-activity;sid:84766282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss"; depth:5; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903175/; classtype:trojan-activity;sid:84766275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cliaarch"; depth:9; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903176/; classtype:trojan-activity;sid:84766276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proot"; depth:6; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903177/; classtype:trojan-activity;sid:84766277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss"; depth:5; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903178/; classtype:trojan-activity;sid:84766278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldboss"; depth:8; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903179/; classtype:trojan-activity;sid:84766279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cliaarch"; depth:9; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903180/; classtype:trojan-activity;sid:84766280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/log"; depth:4; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903174/; classtype:trojan-activity;sid:84766274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldboss"; depth:8; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903173/; classtype:trojan-activity;sid:84766273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proot"; depth:6; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903169/; classtype:trojan-activity;sid:84766269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cli"; depth:4; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903170/; classtype:trojan-activity;sid:84766270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syst3md"; depth:8; endswith; nocase; http.host; content:"ten.devurek.xyz"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903171/; classtype:trojan-activity;sid:84766271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/log"; depth:4; endswith; nocase; http.host; content:"u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903172/; classtype:trojan-activity;sid:84766272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ae96d08e0e89cde9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903168/; classtype:trojan-activity;sid:84766268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1qchds5jxvrnvfzzwte-lhtxkqaz4dqno"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903167/; classtype:trojan-activity;sid:84766267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/uzcrypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903165/; classtype:trojan-activity;sid:84766265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/eecrypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903166/; classtype:trojan-activity;sid:84766266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/udcrypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903163/; classtype:trojan-activity;sid:84766263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/aktcrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903164/; classtype:trojan-activity;sid:84766264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.110.211"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903162/; classtype:trojan-activity;sid:84766262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.110.211"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903161/; classtype:trojan-activity;sid:84766261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.226.6.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903160/; classtype:trojan-activity;sid:84766260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.1.225.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903158/; classtype:trojan-activity;sid:84766258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.101.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903159/; classtype:trojan-activity;sid:84766259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.211.213.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903156/; classtype:trojan-activity;sid:84766256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.211.213.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903157/; classtype:trojan-activity;sid:84766257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.168.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903154/; classtype:trojan-activity;sid:84766254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.72.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903155/; classtype:trojan-activity;sid:84766255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.162.218.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903153/; classtype:trojan-activity;sid:84766253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.91.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903152/; classtype:trojan-activity;sid:84766252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.104.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903151/; classtype:trojan-activity;sid:84766251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903132/; classtype:trojan-activity;sid:84766232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903133/; classtype:trojan-activity;sid:84766233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.58.118.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903134/; classtype:trojan-activity;sid:84766234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"82.114.181.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903135/; classtype:trojan-activity;sid:84766235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.67.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903136/; classtype:trojan-activity;sid:84766236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.72.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903137/; classtype:trojan-activity;sid:84766237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.11.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903138/; classtype:trojan-activity;sid:84766238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.226.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903139/; classtype:trojan-activity;sid:84766239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.59.226.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903140/; classtype:trojan-activity;sid:84766240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.57.201.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903141/; classtype:trojan-activity;sid:84766241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.57.201.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903142/; classtype:trojan-activity;sid:84766242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"87.202.82.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903143/; classtype:trojan-activity;sid:84766243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.114.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903144/; classtype:trojan-activity;sid:84766244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.58.42.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903145/; classtype:trojan-activity;sid:84766245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.233.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903146/; classtype:trojan-activity;sid:84766246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.83.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903147/; classtype:trojan-activity;sid:84766247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.104.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903148/; classtype:trojan-activity;sid:84766248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.91.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903149/; classtype:trojan-activity;sid:84766249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.152.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903150/; classtype:trojan-activity;sid:84766250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.60.75.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903127/; classtype:trojan-activity;sid:84766227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.228.109.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903128/; classtype:trojan-activity;sid:84766228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.60.75.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903129/; classtype:trojan-activity;sid:84766229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.228.109.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903130/; classtype:trojan-activity;sid:84766230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.193.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903131/; classtype:trojan-activity;sid:84766231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.201.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903126/; classtype:trojan-activity;sid:84766226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903125/; classtype:trojan-activity;sid:84766225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.159.154.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903123/; classtype:trojan-activity;sid:84766223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.98.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903124/; classtype:trojan-activity;sid:84766224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.216.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903122/; classtype:trojan-activity;sid:84766222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.41.107"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903117/; classtype:trojan-activity;sid:84766217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.99.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903118/; classtype:trojan-activity;sid:84766218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.10.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903119/; classtype:trojan-activity;sid:84766219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.202.24.36"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903120/; classtype:trojan-activity;sid:84766220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.117.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903121/; classtype:trojan-activity;sid:84766221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.102.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903110/; classtype:trojan-activity;sid:84766210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.196.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903111/; classtype:trojan-activity;sid:84766211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.71.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903112/; classtype:trojan-activity;sid:84766212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.249.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903113/; classtype:trojan-activity;sid:84766213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.130.28"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903114/; classtype:trojan-activity;sid:84766214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.10.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903115/; classtype:trojan-activity;sid:84766215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.158.38"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903116/; classtype:trojan-activity;sid:84766216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.44.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903107/; classtype:trojan-activity;sid:84766207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.157.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903108/; classtype:trojan-activity;sid:84766208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.196.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903109/; classtype:trojan-activity;sid:84766209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.68.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903097/; classtype:trojan-activity;sid:84766197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.99.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903098/; classtype:trojan-activity;sid:84766198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.70.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903099/; classtype:trojan-activity;sid:84766199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.183.53.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903100/; classtype:trojan-activity;sid:84766200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.88.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903101/; classtype:trojan-activity;sid:84766201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.118.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903102/; classtype:trojan-activity;sid:84766202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.158.38"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903103/; classtype:trojan-activity;sid:84766203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.234.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903104/; classtype:trojan-activity;sid:84766204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.67.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903105/; classtype:trojan-activity;sid:84766205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.12.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903106/; classtype:trojan-activity;sid:84766206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.30.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903092/; classtype:trojan-activity;sid:84766192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.239.113.122"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903093/; classtype:trojan-activity;sid:84766193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.231.9.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903094/; classtype:trojan-activity;sid:84766194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.80.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903095/; classtype:trojan-activity;sid:84766195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"37.78.176.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903096/; classtype:trojan-activity;sid:84766196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.20.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903085/; classtype:trojan-activity;sid:84766185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.88.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903086/; classtype:trojan-activity;sid:84766186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.230.81.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903087/; classtype:trojan-activity;sid:84766187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.239.113.122"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903088/; classtype:trojan-activity;sid:84766188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903089/; classtype:trojan-activity;sid:84766189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.80.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903090/; classtype:trojan-activity;sid:84766190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.227.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903091/; classtype:trojan-activity;sid:84766191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.224.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903084/; classtype:trojan-activity;sid:84766184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.104.54"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903079/; classtype:trojan-activity;sid:84766179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.241.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903080/; classtype:trojan-activity;sid:84766180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.209.244.81"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903081/; classtype:trojan-activity;sid:84766181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.198.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903082/; classtype:trojan-activity;sid:84766182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.55.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903083/; classtype:trojan-activity;sid:84766183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.123.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903078/; classtype:trojan-activity;sid:84766178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.193.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903076/; classtype:trojan-activity;sid:84766176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.234.38"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903077/; classtype:trojan-activity;sid:84766177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.11.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903072/; classtype:trojan-activity;sid:84766172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.2.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903073/; classtype:trojan-activity;sid:84766173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"176.106.241.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903074/; classtype:trojan-activity;sid:84766174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.53.209.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903075/; classtype:trojan-activity;sid:84766175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.136.5.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903068/; classtype:trojan-activity;sid:84766168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.131.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903069/; classtype:trojan-activity;sid:84766169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.184.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903070/; classtype:trojan-activity;sid:84766170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.184.6.71"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903071/; classtype:trojan-activity;sid:84766171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.159.154.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903061/; classtype:trojan-activity;sid:84766161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.65.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903062/; classtype:trojan-activity;sid:84766162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.229.171"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903063/; classtype:trojan-activity;sid:84766163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.54.168"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903064/; classtype:trojan-activity;sid:84766164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.121.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903065/; classtype:trojan-activity;sid:84766165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.80.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903066/; classtype:trojan-activity;sid:84766166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.30.67"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903067/; classtype:trojan-activity;sid:84766167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.146.92.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903056/; classtype:trojan-activity;sid:84766156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.4.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903057/; classtype:trojan-activity;sid:84766157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.48.28.98"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903058/; classtype:trojan-activity;sid:84766158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.195.40"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903059/; classtype:trojan-activity;sid:84766159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.147.248.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903060/; classtype:trojan-activity;sid:84766160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.124.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903049/; classtype:trojan-activity;sid:84766149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.69.71"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903050/; classtype:trojan-activity;sid:84766150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.93.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903051/; classtype:trojan-activity;sid:84766151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.207.247.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903052/; classtype:trojan-activity;sid:84766152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.179.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903053/; classtype:trojan-activity;sid:84766153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.4.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903054/; classtype:trojan-activity;sid:84766154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.207.247.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903055/; classtype:trojan-activity;sid:84766155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.124.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903047/; classtype:trojan-activity;sid:84766147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.93.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903048/; classtype:trojan-activity;sid:84766148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.68.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903046/; classtype:trojan-activity;sid:84766146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.189.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903044/; classtype:trojan-activity;sid:84766144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.73.44.67"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903045/; classtype:trojan-activity;sid:84766145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.98.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903041/; classtype:trojan-activity;sid:84766141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.223.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903042/; classtype:trojan-activity;sid:84766142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.223.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903043/; classtype:trojan-activity;sid:84766143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.183.53.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903035/; classtype:trojan-activity;sid:84766135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.164.138"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903036/; classtype:trojan-activity;sid:84766136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.209.244.81"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903037/; classtype:trojan-activity;sid:84766137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.24.217.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903038/; classtype:trojan-activity;sid:84766138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.164.138"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903039/; classtype:trojan-activity;sid:84766139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.147.158.185"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903040/; classtype:trojan-activity;sid:84766140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.130.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903034/; classtype:trojan-activity;sid:84766134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.234.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903030/; classtype:trojan-activity;sid:84766130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903031/; classtype:trojan-activity;sid:84766131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.173.117"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903032/; classtype:trojan-activity;sid:84766132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.93.139.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903033/; classtype:trojan-activity;sid:84766133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.211.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903020/; classtype:trojan-activity;sid:84766120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.148.216.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903021/; classtype:trojan-activity;sid:84766121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.131.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903022/; classtype:trojan-activity;sid:84766122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.230.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903023/; classtype:trojan-activity;sid:84766123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.20.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903024/; classtype:trojan-activity;sid:84766124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.71.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903025/; classtype:trojan-activity;sid:84766125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.118.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903026/; classtype:trojan-activity;sid:84766126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.55.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903027/; classtype:trojan-activity;sid:84766127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.80.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903028/; classtype:trojan-activity;sid:84766128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.130.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903029/; classtype:trojan-activity;sid:84766129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.122.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903009/; classtype:trojan-activity;sid:84766109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.138.249.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903010/; classtype:trojan-activity;sid:84766110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.70.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903011/; classtype:trojan-activity;sid:84766111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"24.95.54.96"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903012/; classtype:trojan-activity;sid:84766112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"211.158.166.117"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903013/; classtype:trojan-activity;sid:84766113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"24.95.54.96"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903014/; classtype:trojan-activity;sid:84766114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903015/; classtype:trojan-activity;sid:84766115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.117.59"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903016/; classtype:trojan-activity;sid:84766116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.117.59"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903017/; classtype:trojan-activity;sid:84766117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.115.246.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903018/; classtype:trojan-activity;sid:84766118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.107.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903019/; classtype:trojan-activity;sid:84766119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.231.9.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903008/; classtype:trojan-activity;sid:84766108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903007/; classtype:trojan-activity;sid:84766107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.156.154.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903005/; classtype:trojan-activity;sid:84766105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.156.154.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903006/; classtype:trojan-activity;sid:84766106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a3f8d2/kaizen.arm"; depth:18; endswith; nocase; http.host; content:"196.251.121.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903004/; classtype:trojan-activity;sid:84766104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.239.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902999/; classtype:trojan-activity;sid:84766099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.193.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903000/; classtype:trojan-activity;sid:84766100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.193.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903001/; classtype:trojan-activity;sid:84766101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.138.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903002/; classtype:trojan-activity;sid:84766102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.138.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903003/; classtype:trojan-activity;sid:84766103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.133.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902998/; classtype:trojan-activity;sid:84766098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.107.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902997/; classtype:trojan-activity;sid:84766097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.13.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902996/; classtype:trojan-activity;sid:84766096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tap/bbva_pdf.zip"; depth:17; endswith; nocase; http.host; content:"mbcasesores.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902995/; classtype:trojan-activity;sid:84766095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zwqbelslfazlfvdulvpacflw9splks3pv4auieuv/update.exe"; depth:52; endswith; nocase; http.host; content:"luxcar-24.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902994/; classtype:trojan-activity;sid:84766094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/1537290261195919382/1537290376740741220/vozolomis_setup_1.2.6.exe|3f|"; depth:82; endswith; nocase; http.host; content:"cdn.discordapp.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902993/; classtype:trojan-activity;sid:84766093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_888f9e1e66545fd5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902992/; classtype:trojan-activity;sid:84766092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.64.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902991/; classtype:trojan-activity;sid:84766091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.64.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902990/; classtype:trojan-activity;sid:84766090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/ojkcrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902989/; classtype:trojan-activity;sid:84766089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypted.ps1"; depth:12; endswith; nocase; http.host; content:"frtkvnpa.xyz"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902988/; classtype:trojan-activity;sid:84766088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/build_x64"; depth:12; endswith; nocase; http.host; content:"87.120.104.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902987/; classtype:trojan-activity;sid:84766087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig.exe"; depth:10; endswith; nocase; http.host; content:"15.204.176.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902986/; classtype:trojan-activity;sid:84766086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"162.246.26.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902985/; classtype:trojan-activity;sid:84766085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/935428"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902984/; classtype:trojan-activity;sid:84766084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d1832e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902972/; classtype:trojan-activity;sid:84766072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/446eba"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902973/; classtype:trojan-activity;sid:84766073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c1da29"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902974/; classtype:trojan-activity;sid:84766074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ea1763"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902975/; classtype:trojan-activity;sid:84766075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3f7598"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902976/; classtype:trojan-activity;sid:84766076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eb1880"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902977/; classtype:trojan-activity;sid:84766077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/85c412"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902978/; classtype:trojan-activity;sid:84766078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/820635"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902979/; classtype:trojan-activity;sid:84766079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ae1209"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902980/; classtype:trojan-activity;sid:84766080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e19e6a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902981/; classtype:trojan-activity;sid:84766081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2c819f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902982/; classtype:trojan-activity;sid:84766082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bd412f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902983/; classtype:trojan-activity;sid:84766083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.powerpc"; depth:14; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902971/; classtype:trojan-activity;sid:84766071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.m68k"; depth:11; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902970/; classtype:trojan-activity;sid:84766070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mipsrouter"; depth:17; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902966/; classtype:trojan-activity;sid:84766066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.sparc"; depth:12; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902967/; classtype:trojan-activity;sid:84766067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.i486"; depth:11; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902968/; classtype:trojan-activity;sid:84766068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.sh4"; depth:10; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902969/; classtype:trojan-activity;sid:84766069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/818df1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902955/; classtype:trojan-activity;sid:84766055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ced603"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902956/; classtype:trojan-activity;sid:84766056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/55a639"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902957/; classtype:trojan-activity;sid:84766057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e5e3a4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902958/; classtype:trojan-activity;sid:84766058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/83792e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902959/; classtype:trojan-activity;sid:84766059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/533721"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902960/; classtype:trojan-activity;sid:84766060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7d27e5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902961/; classtype:trojan-activity;sid:84766061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/428768"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902962/; classtype:trojan-activity;sid:84766062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/11ac33"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902963/; classtype:trojan-activity;sid:84766063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cddd60"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902964/; classtype:trojan-activity;sid:84766064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b94fb7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902965/; classtype:trojan-activity;sid:84766065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a2fa8f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902943/; classtype:trojan-activity;sid:84766043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b60846"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902944/; classtype:trojan-activity;sid:84766044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2d085b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902945/; classtype:trojan-activity;sid:84766045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a041d7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902946/; classtype:trojan-activity;sid:84766046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/340ea0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902947/; classtype:trojan-activity;sid:84766047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/989926"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902948/; classtype:trojan-activity;sid:84766048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3cea41"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902949/; classtype:trojan-activity;sid:84766049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/938392"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902950/; classtype:trojan-activity;sid:84766050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86361f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902951/; classtype:trojan-activity;sid:84766051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/140e8d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902952/; classtype:trojan-activity;sid:84766052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1cc53b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902953/; classtype:trojan-activity;sid:84766053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45fb7d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902954/; classtype:trojan-activity;sid:84766054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hrr.png"; depth:8; endswith; nocase; http.host; content:"pub-3bc1de741f8149f49bdbafa703067f24.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902941/; classtype:trojan-activity;sid:84766041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hjada.png"; depth:10; endswith; nocase; http.host; content:"pub-3bc1de741f8149f49bdbafa703067f24.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902942/; classtype:trojan-activity;sid:84766042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1/ueyasmgyetaq241.mwn"; depth:22; endswith; nocase; http.host; content:"151.241.154.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902939/; classtype:trojan-activity;sid:84766039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1/iokasg181fteasmm.nce"; depth:23; endswith; nocase; http.host; content:"151.241.154.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902940/; classtype:trojan-activity;sid:84766040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3fe5ed2d30d53a73.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902938/; classtype:trojan-activity;sid:84766038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3636b8ab0c149e71.cmd"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902935/; classtype:trojan-activity;sid:84766035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_bd1adaff26b8305d.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902936/; classtype:trojan-activity;sid:84766036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget"; depth:5; endswith; nocase; http.host; content:"185.93.89.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902937/; classtype:trojan-activity;sid:84766037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_c6d8c2a5c91fb3df.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902933/; classtype:trojan-activity;sid:84766033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3d10f3731e453661.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902934/; classtype:trojan-activity;sid:84766034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.94.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902932/; classtype:trojan-activity;sid:84766032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902931/; classtype:trojan-activity;sid:84766031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_19e674e25adc5a91.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902930/; classtype:trojan-activity;sid:84766030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.54.39"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902929/; classtype:trojan-activity;sid:84766029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rvn.exe"; depth:8; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902928/; classtype:trojan-activity;sid:84766028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.56.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902927/; classtype:trojan-activity;sid:84766027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.56.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902926/; classtype:trojan-activity;sid:84766026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p.sh"; depth:5; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902925/; classtype:trojan-activity;sid:84766025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.185.241.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902924/; classtype:trojan-activity;sid:84766024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.185.241.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902923/; classtype:trojan-activity;sid:84766023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.72.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902922/; classtype:trojan-activity;sid:84766022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902921/; classtype:trojan-activity;sid:84766021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.214.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902920/; classtype:trojan-activity;sid:84766020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"138.204.196.136"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902919/; classtype:trojan-activity;sid:84766019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.68.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902918/; classtype:trojan-activity;sid:84766018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.136.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902917/; classtype:trojan-activity;sid:84766017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/e8fjth5km9ncp252hrjq5/main.exe|3f|rlkey=mmcc5w15uphz2xehyvo3uir3k|7c|26|7c|st=o3g7rikz|7c|26|7c|dl=1"; depth:108; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902916/; classtype:trojan-activity;sid:84766016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/tpt9bauil4qjjmlp7zb67/miner.exe|3f|rlkey=uoovuvjd5i98iwns8q603dnu8|7c|26|7c|st=us1vcqua|7c|26|7c|dl=1"; depth:109; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902915/; classtype:trojan-activity;sid:84766015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.136.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902914/; classtype:trojan-activity;sid:84766014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.231.45"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902913/; classtype:trojan-activity;sid:84766013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.44.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902912/; classtype:trojan-activity;sid:84766012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.3.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902911/; classtype:trojan-activity;sid:84766011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c747be"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902909/; classtype:trojan-activity;sid:84766009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/67f55e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902910/; classtype:trojan-activity;sid:84766010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/194957"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902907/; classtype:trojan-activity;sid:84766007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eb2746"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902908/; classtype:trojan-activity;sid:84766008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"154.90.70.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902906/; classtype:trojan-activity;sid:84766006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/be1fde"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902902/; classtype:trojan-activity;sid:84766002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/33d663"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902903/; classtype:trojan-activity;sid:84766003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a8ac8a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902904/; classtype:trojan-activity;sid:84766004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b318c0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902905/; classtype:trojan-activity;sid:84766005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"154.90.70.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902900/; classtype:trojan-activity;sid:84766000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"154.90.70.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902901/; classtype:trojan-activity;sid:84766001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1096dc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902896/; classtype:trojan-activity;sid:84765996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/27f7dd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902897/; classtype:trojan-activity;sid:84765997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9b2f83"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902898/; classtype:trojan-activity;sid:84765998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b0a2e4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902899/; classtype:trojan-activity;sid:84765999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2778ce"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902895/; classtype:trojan-activity;sid:84765995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bfde3b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902891/; classtype:trojan-activity;sid:84765991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f971dc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902892/; classtype:trojan-activity;sid:84765992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/085175"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902893/; classtype:trojan-activity;sid:84765993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/341d04"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902894/; classtype:trojan-activity;sid:84765994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b59af2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902886/; classtype:trojan-activity;sid:84765986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/126678"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902887/; classtype:trojan-activity;sid:84765987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/068f87"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902888/; classtype:trojan-activity;sid:84765988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5b5f1c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902889/; classtype:trojan-activity;sid:84765989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ec54e5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902890/; classtype:trojan-activity;sid:84765990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/659716"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902884/; classtype:trojan-activity;sid:84765984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3f9c7b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902885/; classtype:trojan-activity;sid:84765985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.3.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902883/; classtype:trojan-activity;sid:84765983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.53.59.112"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902882/; classtype:trojan-activity;sid:84765982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.6.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902881/; classtype:trojan-activity;sid:84765981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.73.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902880/; classtype:trojan-activity;sid:84765980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"80.67.33.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902879/; classtype:trojan-activity;sid:84765979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.73.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902878/; classtype:trojan-activity;sid:84765978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.6.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902877/; classtype:trojan-activity;sid:84765977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.219.139"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902876/; classtype:trojan-activity;sid:84765976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.219.139"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902875/; classtype:trojan-activity;sid:84765975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8jot5vdohds0imt4"; depth:17; endswith; nocase; http.host; content:"192.162.199.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902874/; classtype:trojan-activity;sid:84765974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"207.189.4.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902873/; classtype:trojan-activity;sid:84765973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bobbin.exe"; depth:11; endswith; nocase; http.host; content:"flooriscoveringworld.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902872/; classtype:trojan-activity;sid:84765972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1vo6lm4y50k3ww0f"; depth:17; endswith; nocase; http.host; content:"192.162.199.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902870/; classtype:trojan-activity;sid:84765970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeb8cgwmkkpvu7pc"; depth:17; endswith; nocase; http.host; content:"192.162.199.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902871/; classtype:trojan-activity;sid:84765971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1edjop4tlj2d"; depth:13; endswith; nocase; http.host; content:"192.162.199.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902867/; classtype:trojan-activity;sid:84765967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8w6vq50fsu"; depth:11; endswith; nocase; http.host; content:"192.162.199.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902868/; classtype:trojan-activity;sid:84765968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ezaenul9"; depth:9; endswith; nocase; http.host; content:"192.162.199.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902869/; classtype:trojan-activity;sid:84765969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902866/; classtype:trojan-activity;sid:84765966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902865/; classtype:trojan-activity;sid:84765965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902864/; classtype:trojan-activity;sid:84765964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902863/; classtype:trojan-activity;sid:84765963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm4"; depth:10; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902862/; classtype:trojan-activity;sid:84765962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902861/; classtype:trojan-activity;sid:84765961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"154.90.70.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902860/; classtype:trojan-activity;sid:84765960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/y6b3fuzj0w6pt97e"; depth:17; endswith; nocase; http.host; content:"192.162.199.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902858/; classtype:trojan-activity;sid:84765958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tzb10mmujurn"; depth:13; endswith; nocase; http.host; content:"192.162.199.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902857/; classtype:trojan-activity;sid:84765957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_de67bd60facbd66c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902856/; classtype:trojan-activity;sid:84765956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.103.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902855/; classtype:trojan-activity;sid:84765955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7646424755/gx8992r.bat"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902854/; classtype:trojan-activity;sid:84765954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.228.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902853/; classtype:trojan-activity;sid:84765953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.228.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902852/; classtype:trojan-activity;sid:84765952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.238.178.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902851/; classtype:trojan-activity;sid:84765951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.189.111.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902850/; classtype:trojan-activity;sid:84765950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k"; depth:2; endswith; nocase; http.host; content:"joker.aec944b68370194a50.link"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902849/; classtype:trojan-activity;sid:84765949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.189.111.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902848/; classtype:trojan-activity;sid:84765948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mipsrouter"; depth:17; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902846/; classtype:trojan-activity;sid:84765946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.m68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902847/; classtype:trojan-activity;sid:84765947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/debug.dbg"; depth:16; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902840/; classtype:trojan-activity;sid:84765940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.i486"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902841/; classtype:trojan-activity;sid:84765941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.powerpc"; depth:14; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902842/; classtype:trojan-activity;sid:84765942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.sparc"; depth:12; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902843/; classtype:trojan-activity;sid:84765943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.arc"; depth:10; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902844/; classtype:trojan-activity;sid:84765944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.sh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902845/; classtype:trojan-activity;sid:84765945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/ppc"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902839/; classtype:trojan-activity;sid:84765939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/spc"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902835/; classtype:trojan-activity;sid:84765935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm5"; depth:11; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902836/; classtype:trojan-activity;sid:84765936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902837/; classtype:trojan-activity;sid:84765937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64nosl"; depth:17; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902838/; classtype:trojan-activity;sid:84765938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm6"; depth:11; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902832/; classtype:trojan-activity;sid:84765932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm7"; depth:11; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902833/; classtype:trojan-activity;sid:84765933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arc"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902834/; classtype:trojan-activity;sid:84765934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902830/; classtype:trojan-activity;sid:84765930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/m68k"; depth:11; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902831/; classtype:trojan-activity;sid:84765931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64nosl"; depth:17; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902828/; classtype:trojan-activity;sid:84765928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/debug.dbg"; depth:16; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902829/; classtype:trojan-activity;sid:84765929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/main.exe"; depth:15; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902822/; classtype:trojan-activity;sid:84765922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/sh4"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902823/; classtype:trojan-activity;sid:84765923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mips"; depth:11; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902824/; classtype:trojan-activity;sid:84765924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/debug_main.exe"; depth:21; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902825/; classtype:trojan-activity;sid:84765925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mpsl"; depth:11; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902826/; classtype:trojan-activity;sid:84765926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64"; depth:13; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902827/; classtype:trojan-activity;sid:84765927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/debug_main.exe"; depth:21; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902820/; classtype:trojan-activity;sid:84765920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/main.exe"; depth:15; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902821/; classtype:trojan-activity;sid:84765921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.6.8"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902819/; classtype:trojan-activity;sid:84765919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv4l"; depth:13; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902818/; classtype:trojan-activity;sid:84765918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/spc"; depth:10; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902816/; classtype:trojan-activity;sid:84765916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86"; depth:10; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902817/; classtype:trojan-activity;sid:84765917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svchost.exe"; depth:12; endswith; nocase; http.host; content:"217.60.241.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902815/; classtype:trojan-activity;sid:84765915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv6l"; depth:13; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902812/; classtype:trojan-activity;sid:84765912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.x86_64"; depth:13; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902813/; classtype:trojan-activity;sid:84765913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mips"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902814/; classtype:trojan-activity;sid:84765914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/ppc"; depth:10; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902806/; classtype:trojan-activity;sid:84765906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm"; depth:10; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902807/; classtype:trojan-activity;sid:84765907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64"; depth:13; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902808/; classtype:trojan-activity;sid:84765908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mips"; depth:11; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902809/; classtype:trojan-activity;sid:84765909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/sh4"; depth:10; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902810/; classtype:trojan-activity;sid:84765910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm5"; depth:11; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902811/; classtype:trojan-activity;sid:84765911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv5l"; depth:13; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902804/; classtype:trojan-activity;sid:84765904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv7l"; depth:13; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902805/; classtype:trojan-activity;sid:84765905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm6"; depth:11; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902799/; classtype:trojan-activity;sid:84765899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arc"; depth:10; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902800/; classtype:trojan-activity;sid:84765900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/m68k"; depth:11; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902801/; classtype:trojan-activity;sid:84765901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mpsl"; depth:11; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902802/; classtype:trojan-activity;sid:84765902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm7"; depth:11; endswith; nocase; http.host; content:"176.65.139.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902803/; classtype:trojan-activity;sid:84765903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902797/; classtype:trojan-activity;sid:84765897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mipsel"; depth:13; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902798/; classtype:trojan-activity;sid:84765898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902796/; classtype:trojan-activity;sid:84765896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902794/; classtype:trojan-activity;sid:84765894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902795/; classtype:trojan-activity;sid:84765895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902793/; classtype:trojan-activity;sid:84765893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902792/; classtype:trojan-activity;sid:84765892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.6.8"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902791/; classtype:trojan-activity;sid:84765891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_212250.png"; depth:15; endswith; nocase; http.host; content:"export.kesug.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902790/; classtype:trojan-activity;sid:84765890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.106.249.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902788/; classtype:trojan-activity;sid:84765888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.106.249.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902789/; classtype:trojan-activity;sid:84765889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.240.173.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902786/; classtype:trojan-activity;sid:84765886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.191.16.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902787/; classtype:trojan-activity;sid:84765887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.240.173.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902785/; classtype:trojan-activity;sid:84765885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.68.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902782/; classtype:trojan-activity;sid:84765882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quickfetch.exe"; depth:15; endswith; nocase; http.host; content:"trueinggrik.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902783/; classtype:trojan-activity;sid:84765883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.229.46.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902784/; classtype:trojan-activity;sid:84765884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.252.113.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902781/; classtype:trojan-activity;sid:84765881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.179.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902773/; classtype:trojan-activity;sid:84765873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.9.132.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902774/; classtype:trojan-activity;sid:84765874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.8.75"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902775/; classtype:trojan-activity;sid:84765875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.148.140.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902776/; classtype:trojan-activity;sid:84765876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.167.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902777/; classtype:trojan-activity;sid:84765877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.148.140.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902778/; classtype:trojan-activity;sid:84765878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.30.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902779/; classtype:trojan-activity;sid:84765879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.221.231.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902780/; classtype:trojan-activity;sid:84765880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.94.194.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902768/; classtype:trojan-activity;sid:84765868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.213.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902769/; classtype:trojan-activity;sid:84765869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.112.61.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902770/; classtype:trojan-activity;sid:84765870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"71.207.128.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902771/; classtype:trojan-activity;sid:84765871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.114.153.10"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902772/; classtype:trojan-activity;sid:84765872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.242.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902766/; classtype:trojan-activity;sid:84765866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.245.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902767/; classtype:trojan-activity;sid:84765867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.123.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902764/; classtype:trojan-activity;sid:84765864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.112.61.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902765/; classtype:trojan-activity;sid:84765865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.8.75"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902762/; classtype:trojan-activity;sid:84765862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.123.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902763/; classtype:trojan-activity;sid:84765863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.206.197.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902749/; classtype:trojan-activity;sid:84765849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.242.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902750/; classtype:trojan-activity;sid:84765850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.31.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902751/; classtype:trojan-activity;sid:84765851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902752/; classtype:trojan-activity;sid:84765852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.193.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902753/; classtype:trojan-activity;sid:84765853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.157.30"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902754/; classtype:trojan-activity;sid:84765854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.238.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902755/; classtype:trojan-activity;sid:84765855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.254.51.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902756/; classtype:trojan-activity;sid:84765856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.44.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902757/; classtype:trojan-activity;sid:84765857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.252.113.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902758/; classtype:trojan-activity;sid:84765858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.44.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902759/; classtype:trojan-activity;sid:84765859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.244.27"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902760/; classtype:trojan-activity;sid:84765860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.179.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902761/; classtype:trojan-activity;sid:84765861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.103.116.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902736/; classtype:trojan-activity;sid:84765836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.106.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902737/; classtype:trojan-activity;sid:84765837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.183.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902738/; classtype:trojan-activity;sid:84765838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.67.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902739/; classtype:trojan-activity;sid:84765839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.50.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902740/; classtype:trojan-activity;sid:84765840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.6.185.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902741/; classtype:trojan-activity;sid:84765841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"193.31.201.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902742/; classtype:trojan-activity;sid:84765842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"193.31.201.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902743/; classtype:trojan-activity;sid:84765843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.178.118.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902744/; classtype:trojan-activity;sid:84765844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.164.68.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902745/; classtype:trojan-activity;sid:84765845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.7.146.107"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902746/; classtype:trojan-activity;sid:84765846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.14.209"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902747/; classtype:trojan-activity;sid:84765847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.111.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902748/; classtype:trojan-activity;sid:84765848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.206.197.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902734/; classtype:trojan-activity;sid:84765834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"140.237.37.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902735/; classtype:trojan-activity;sid:84765835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.17.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902733/; classtype:trojan-activity;sid:84765833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.138.244.27"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902732/; classtype:trojan-activity;sid:84765832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.67.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902731/; classtype:trojan-activity;sid:84765831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.122.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902724/; classtype:trojan-activity;sid:84765824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.173.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902725/; classtype:trojan-activity;sid:84765825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.67.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902726/; classtype:trojan-activity;sid:84765826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.245.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902727/; classtype:trojan-activity;sid:84765827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"140.237.37.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902728/; classtype:trojan-activity;sid:84765828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.31.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902729/; classtype:trojan-activity;sid:84765829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.50.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902730/; classtype:trojan-activity;sid:84765830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.34.109.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902704/; classtype:trojan-activity;sid:84765804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.253.104"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902705/; classtype:trojan-activity;sid:84765805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.248.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902706/; classtype:trojan-activity;sid:84765806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.225.195"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902707/; classtype:trojan-activity;sid:84765807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902708/; classtype:trojan-activity;sid:84765808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.225.195"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902709/; classtype:trojan-activity;sid:84765809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.126.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902710/; classtype:trojan-activity;sid:84765810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.16.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902711/; classtype:trojan-activity;sid:84765811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.14.209"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902712/; classtype:trojan-activity;sid:84765812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.107.16.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902713/; classtype:trojan-activity;sid:84765813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.7.146.107"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902714/; classtype:trojan-activity;sid:84765814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.6.209.122"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902715/; classtype:trojan-activity;sid:84765815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.13.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902716/; classtype:trojan-activity;sid:84765816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.174.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902717/; classtype:trojan-activity;sid:84765817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.192.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902718/; classtype:trojan-activity;sid:84765818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.100.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902719/; classtype:trojan-activity;sid:84765819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.164.68.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902720/; classtype:trojan-activity;sid:84765820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.191.122.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902721/; classtype:trojan-activity;sid:84765821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902722/; classtype:trojan-activity;sid:84765822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.54.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902723/; classtype:trojan-activity;sid:84765823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902695/; classtype:trojan-activity;sid:84765795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.148.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902696/; classtype:trojan-activity;sid:84765796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.148.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902697/; classtype:trojan-activity;sid:84765797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.239.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902698/; classtype:trojan-activity;sid:84765798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.9.255"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902699/; classtype:trojan-activity;sid:84765799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.6.185.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902700/; classtype:trojan-activity;sid:84765800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.228.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902701/; classtype:trojan-activity;sid:84765801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.239.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902702/; classtype:trojan-activity;sid:84765802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.114.153.10"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902703/; classtype:trojan-activity;sid:84765803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.103.116.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902694/; classtype:trojan-activity;sid:84765794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.246.20.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902693/; classtype:trojan-activity;sid:84765793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.109.243.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902691/; classtype:trojan-activity;sid:84765791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.109.243.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902692/; classtype:trojan-activity;sid:84765792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.130.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902690/; classtype:trojan-activity;sid:84765790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/codu"; depth:5; endswith; nocase; http.host; content:"193.23.118.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902689/; classtype:trojan-activity;sid:84765789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902687/; classtype:trojan-activity;sid:84765787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.68.248.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902688/; classtype:trojan-activity;sid:84765788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.68.248.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902684/; classtype:trojan-activity;sid:84765784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abc.sh"; depth:7; endswith; nocase; http.host; content:"85.121.5.157"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902685/; classtype:trojan-activity;sid:84765785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.95.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902686/; classtype:trojan-activity;sid:84765786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.236.44.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902683/; classtype:trojan-activity;sid:84765783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gmt/papacrypted.ps1"; depth:20; endswith; nocase; http.host; content:"38.180.221.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902682/; classtype:trojan-activity;sid:84765782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cjbbpzfu/t1b0nrg3.png"; depth:22; endswith; nocase; http.host; content:"media-aviation.run.place"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902681/; classtype:trojan-activity;sid:84765781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kgvli"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902680/; classtype:trojan-activity;sid:84765780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agdrz"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902679/; classtype:trojan-activity;sid:84765779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saraka/agent%20hype.bin"; depth:24; endswith; nocase; http.host; content:"sumiko.vu"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902678/; classtype:trojan-activity;sid:84765778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_pro.png"; depth:12; endswith; nocase; http.host; content:"2goelectricity.co.za"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902677/; classtype:trojan-activity;sid:84765777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/75/wemadegoodthingsforbestforever.hta"; depth:38; endswith; nocase; http.host; content:"204.44.69.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902676/; classtype:trojan-activity;sid:84765776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_170232.png"; depth:15; endswith; nocase; http.host; content:"essizs.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902675/; classtype:trojan-activity;sid:84765775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qgeuk"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902672/; classtype:trojan-activity;sid:84765772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.149.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902673/; classtype:trojan-activity;sid:84765773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_051425.png"; depth:15; endswith; nocase; http.host; content:"without.kesug.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902674/; classtype:trojan-activity;sid:84765774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.148.152.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902671/; classtype:trojan-activity;sid:84765771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v0/b/julyendingapama.firebasestorage.app/o/invergrace.png|3f|alt=media|7c|26|7c|token=54ae32e9-1f20-404f-80a5-8fcc841a3c2b"; depth:123; endswith; nocase; http.host; content:"firebasestorage.googleapis.com"; depth:30; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902670/; classtype:trojan-activity;sid:84765770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/klcvzhpr18.bin"; depth:15; endswith; nocase; http.host; content:"185.29.10.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902668/; classtype:trojan-activity;sid:84765768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vekselvises.asd"; depth:16; endswith; nocase; http.host; content:"185.29.10.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902669/; classtype:trojan-activity;sid:84765769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/twvhp"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902666/; classtype:trojan-activity;sid:84765766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_071010.png"; depth:15; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902667/; classtype:trojan-activity;sid:84765767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.66.12"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902665/; classtype:trojan-activity;sid:84765765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.53.209.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902664/; classtype:trojan-activity;sid:84765764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supersensitizing.hhk"; depth:21; endswith; nocase; http.host; content:"185.29.10.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902663/; classtype:trojan-activity;sid:84765763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/afrlky223.bin"; depth:14; endswith; nocase; http.host; content:"185.29.10.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902662/; classtype:trojan-activity;sid:84765762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k"; depth:2; endswith; nocase; http.host; content:"31.77.227.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902661/; classtype:trojan-activity;sid:84765761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.3.62"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902660/; classtype:trojan-activity;sid:84765760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k"; depth:2; endswith; nocase; http.host; content:"31.56.209.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902659/; classtype:trojan-activity;sid:84765759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902658/; classtype:trojan-activity;sid:84765758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newrem.png"; depth:11; endswith; nocase; http.host; content:"archivoscrosoft.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902657/; classtype:trojan-activity;sid:84765757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/aaacrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902656/; classtype:trojan-activity;sid:84765756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/ojcrypted.ps1"; depth:17; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902653/; classtype:trojan-activity;sid:84765753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/uucrypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902654/; classtype:trojan-activity;sid:84765754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/ezcrypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902655/; classtype:trojan-activity;sid:84765755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/cryptede.ps1"; depth:16; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902643/; classtype:trojan-activity;sid:84765743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/ecrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902644/; classtype:trojan-activity;sid:84765744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/akcrypted.ps1"; depth:17; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902645/; classtype:trojan-activity;sid:84765745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/ucrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902646/; classtype:trojan-activity;sid:84765746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/u1crypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902647/; classtype:trojan-activity;sid:84765747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/ojdcrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902648/; classtype:trojan-activity;sid:84765748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http/kdcrypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902649/; classtype:trojan-activity;sid:84765749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pw/newcrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902650/; classtype:trojan-activity;sid:84765750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojak/ugcrypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902651/; classtype:trojan-activity;sid:84765751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/oojcrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902652/; classtype:trojan-activity;sid:84765752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.131.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902642/; classtype:trojan-activity;sid:84765742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/menneskevrdige.csv"; depth:19; endswith; nocase; http.host; content:"185.29.10.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902640/; classtype:trojan-activity;sid:84765740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/epsdxhp52.bin"; depth:14; endswith; nocase; http.host; content:"185.29.10.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902641/; classtype:trojan-activity;sid:84765741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a7a53e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902628/; classtype:trojan-activity;sid:84765728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1ad6dd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902629/; classtype:trojan-activity;sid:84765729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/73c8e4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902630/; classtype:trojan-activity;sid:84765730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2059d3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902631/; classtype:trojan-activity;sid:84765731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a12c22"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902632/; classtype:trojan-activity;sid:84765732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cabc7a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902633/; classtype:trojan-activity;sid:84765733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/878e23"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902634/; classtype:trojan-activity;sid:84765734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7b2a6c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902635/; classtype:trojan-activity;sid:84765735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ce4957"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902636/; classtype:trojan-activity;sid:84765736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8c2153"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902637/; classtype:trojan-activity;sid:84765737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d9fc8c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902638/; classtype:trojan-activity;sid:84765738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/df64a3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902639/; classtype:trojan-activity;sid:84765739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.168.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902627/; classtype:trojan-activity;sid:84765727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.53.3.62"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902626/; classtype:trojan-activity;sid:84765726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dip.exe"; depth:8; endswith; nocase; http.host; content:"80.253.249.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902625/; classtype:trojan-activity;sid:84765725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.66.12"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902624/; classtype:trojan-activity;sid:84765724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.125.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902623/; classtype:trojan-activity;sid:84765723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.51"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902622/; classtype:trojan-activity;sid:84765722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.130.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902621/; classtype:trojan-activity;sid:84765721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.168.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902620/; classtype:trojan-activity;sid:84765720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.149.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902619/; classtype:trojan-activity;sid:84765719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.57.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902618/; classtype:trojan-activity;sid:84765718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ok"; depth:3; endswith; nocase; http.host; content:"31.77.227.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902617/; classtype:trojan-activity;sid:84765717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ok"; depth:3; endswith; nocase; http.host; content:"31.56.209.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902616/; classtype:trojan-activity;sid:84765716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.130.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902614/; classtype:trojan-activity;sid:84765714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.58.118.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902615/; classtype:trojan-activity;sid:84765715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl|3f|%7b%22f%22%3a%22xr%22%2c%22t%22%3a%22b%22%2c%22p%22%3a%22lnx%22%2c%22a%22%3a%2264%22%2c%22e%22%3a%22aes%22%2c%22c%22%3a1%7d"; depth:130; endswith; nocase; http.host; content:"apt-update.com"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902613/; classtype:trojan-activity;sid:84765713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.57.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902612/; classtype:trojan-activity;sid:84765712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.193.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902611/; classtype:trojan-activity;sid:84765711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.193.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902610/; classtype:trojan-activity;sid:84765710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.232.72.245"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902609/; classtype:trojan-activity;sid:84765709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/110dc2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902605/; classtype:trojan-activity;sid:84765705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bba45d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902606/; classtype:trojan-activity;sid:84765706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a5f61f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902607/; classtype:trojan-activity;sid:84765707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ae64e3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902608/; classtype:trojan-activity;sid:84765708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d1882a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902592/; classtype:trojan-activity;sid:84765692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a2301d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902593/; classtype:trojan-activity;sid:84765693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1d1847"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902594/; classtype:trojan-activity;sid:84765694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1067f5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902595/; classtype:trojan-activity;sid:84765695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4c2baf"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902596/; classtype:trojan-activity;sid:84765696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/587199"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902597/; classtype:trojan-activity;sid:84765697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/531853"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902598/; classtype:trojan-activity;sid:84765698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/567d74"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902599/; classtype:trojan-activity;sid:84765699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0d650b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902600/; classtype:trojan-activity;sid:84765700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c0589f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902601/; classtype:trojan-activity;sid:84765701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/53ffdd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902602/; classtype:trojan-activity;sid:84765702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/813df0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902603/; classtype:trojan-activity;sid:84765703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c0a2c7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902604/; classtype:trojan-activity;sid:84765704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/08bac6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902585/; classtype:trojan-activity;sid:84765685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/becf65"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902586/; classtype:trojan-activity;sid:84765686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0f62ad"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902587/; classtype:trojan-activity;sid:84765687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/905d94"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902588/; classtype:trojan-activity;sid:84765688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/785c9e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902589/; classtype:trojan-activity;sid:84765689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/81d27b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902590/; classtype:trojan-activity;sid:84765690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1b2509"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902591/; classtype:trojan-activity;sid:84765691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_mipsel"; depth:11; endswith; nocase; http.host; content:"149.50.154.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902581/; classtype:trojan-activity;sid:84765681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_mips"; depth:9; endswith; nocase; http.host; content:"149.50.154.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902582/; classtype:trojan-activity;sid:84765682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_arm7"; depth:9; endswith; nocase; http.host; content:"149.50.154.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902583/; classtype:trojan-activity;sid:84765683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_arm"; depth:8; endswith; nocase; http.host; content:"149.50.154.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902584/; classtype:trojan-activity;sid:84765684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zombie_scanner.sh"; depth:18; endswith; nocase; http.host; content:"149.50.154.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902580/; classtype:trojan-activity;sid:84765680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.54.39"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902579/; classtype:trojan-activity;sid:84765679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.176.120.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902578/; classtype:trojan-activity;sid:84765678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ok"; depth:3; endswith; nocase; http.host; content:"joker.aec944b68370194a50.link"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902577/; classtype:trojan-activity;sid:84765677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_670cab8529ccb18e.cmd"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902575/; classtype:trojan-activity;sid:84765675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902576/; classtype:trojan-activity;sid:84765676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_15b107e860013c5e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902573/; classtype:trojan-activity;sid:84765673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_91b0a71f46718f87.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902574/; classtype:trojan-activity;sid:84765674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.224.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902572/; classtype:trojan-activity;sid:84765672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wellsfargo_new_obf_08.07.26.zip"; depth:32; endswith; nocase; http.host; content:"www-connect-secure-wellcfargo.sekolahkejarpaket.com"; depth:51; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902571/; classtype:trojan-activity;sid:84765671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.69.84.54"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902570/; classtype:trojan-activity;sid:84765670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.69.84.54"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902569/; classtype:trojan-activity;sid:84765669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902558/; classtype:trojan-activity;sid:84765658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902559/; classtype:trojan-activity;sid:84765659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902560/; classtype:trojan-activity;sid:84765660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902561/; classtype:trojan-activity;sid:84765661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902562/; classtype:trojan-activity;sid:84765662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902563/; classtype:trojan-activity;sid:84765663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902564/; classtype:trojan-activity;sid:84765664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902565/; classtype:trojan-activity;sid:84765665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902566/; classtype:trojan-activity;sid:84765666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902567/; classtype:trojan-activity;sid:84765667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"31.77.227.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902568/; classtype:trojan-activity;sid:84765668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.sh4"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902557/; classtype:trojan-activity;sid:84765657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.m68k"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902554/; classtype:trojan-activity;sid:84765654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.mpsl"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902555/; classtype:trojan-activity;sid:84765655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.mips"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902556/; classtype:trojan-activity;sid:84765656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902537/; classtype:trojan-activity;sid:84765637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.spc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902538/; classtype:trojan-activity;sid:84765638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902539/; classtype:trojan-activity;sid:84765639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902540/; classtype:trojan-activity;sid:84765640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.arm"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902541/; classtype:trojan-activity;sid:84765641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902542/; classtype:trojan-activity;sid:84765642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902543/; classtype:trojan-activity;sid:84765643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.i486"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902544/; classtype:trojan-activity;sid:84765644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i686"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902545/; classtype:trojan-activity;sid:84765645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.ppc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902546/; classtype:trojan-activity;sid:84765646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.sh4"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902547/; classtype:trojan-activity;sid:84765647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.i686"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902548/; classtype:trojan-activity;sid:84765648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm5"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902549/; classtype:trojan-activity;sid:84765649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.m68k"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902550/; classtype:trojan-activity;sid:84765650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.ppc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902551/; classtype:trojan-activity;sid:84765651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm7"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902552/; classtype:trojan-activity;sid:84765652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.m68k"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902553/; classtype:trojan-activity;sid:84765653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.x86_64"; depth:11; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902514/; classtype:trojan-activity;sid:84765614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.x86"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902515/; classtype:trojan-activity;sid:84765615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.arm7"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902516/; classtype:trojan-activity;sid:84765616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm5"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902517/; classtype:trojan-activity;sid:84765617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i486"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902518/; classtype:trojan-activity;sid:84765618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.ppc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902519/; classtype:trojan-activity;sid:84765619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lm"; depth:3; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902520/; classtype:trojan-activity;sid:84765620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mips"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902521/; classtype:trojan-activity;sid:84765621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.sh4"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902522/; classtype:trojan-activity;sid:84765622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.x86_64"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902523/; classtype:trojan-activity;sid:84765623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm6"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902524/; classtype:trojan-activity;sid:84765624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902525/; classtype:trojan-activity;sid:84765625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.x86"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902526/; classtype:trojan-activity;sid:84765626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902527/; classtype:trojan-activity;sid:84765627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mpsl"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902528/; classtype:trojan-activity;sid:84765628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.x86"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902529/; classtype:trojan-activity;sid:84765629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.mpsl"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902530/; classtype:trojan-activity;sid:84765630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.mips"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902531/; classtype:trojan-activity;sid:84765631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.arc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902532/; classtype:trojan-activity;sid:84765632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/link"; depth:5; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902533/; classtype:trojan-activity;sid:84765633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902534/; classtype:trojan-activity;sid:84765634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.m68k"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902535/; classtype:trojan-activity;sid:84765635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902536/; classtype:trojan-activity;sid:84765636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.spc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902505/; classtype:trojan-activity;sid:84765605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm6"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902506/; classtype:trojan-activity;sid:84765606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902507/; classtype:trojan-activity;sid:84765607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.spc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902508/; classtype:trojan-activity;sid:84765608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mpsl"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902509/; classtype:trojan-activity;sid:84765609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.spc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902510/; classtype:trojan-activity;sid:84765610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.sh4"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902511/; classtype:trojan-activity;sid:84765611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm7"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902512/; classtype:trojan-activity;sid:84765612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/script.sh"; depth:10; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902504/; classtype:trojan-activity;sid:84765604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.ppc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902502/; classtype:trojan-activity;sid:84765602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.ppc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902503/; classtype:trojan-activity;sid:84765603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.i686"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902501/; classtype:trojan-activity;sid:84765601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.spc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902468/; classtype:trojan-activity;sid:84765568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.x86"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902469/; classtype:trojan-activity;sid:84765569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.ppc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902470/; classtype:trojan-activity;sid:84765570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.arc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902471/; classtype:trojan-activity;sid:84765571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.m68k"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902472/; classtype:trojan-activity;sid:84765572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.mips"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902473/; classtype:trojan-activity;sid:84765573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.x86"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902474/; classtype:trojan-activity;sid:84765574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.sh4"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902475/; classtype:trojan-activity;sid:84765575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.arm"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902476/; classtype:trojan-activity;sid:84765576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.i486"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902477/; classtype:trojan-activity;sid:84765577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.mpsl"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902478/; classtype:trojan-activity;sid:84765578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.mpsl"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902479/; classtype:trojan-activity;sid:84765579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arm6"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902480/; classtype:trojan-activity;sid:84765580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.x86_64"; depth:18; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902481/; classtype:trojan-activity;sid:84765581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arm6"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902482/; classtype:trojan-activity;sid:84765582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.arm7"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902483/; classtype:trojan-activity;sid:84765583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.i686"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902484/; classtype:trojan-activity;sid:84765584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.x86"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902485/; classtype:trojan-activity;sid:84765585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arm7"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902486/; classtype:trojan-activity;sid:84765586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.ppc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902487/; classtype:trojan-activity;sid:84765587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902488/; classtype:trojan-activity;sid:84765588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.m68k"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902489/; classtype:trojan-activity;sid:84765589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.sh4"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902490/; classtype:trojan-activity;sid:84765590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.mips"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902491/; classtype:trojan-activity;sid:84765591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.m68k"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902492/; classtype:trojan-activity;sid:84765592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.sh4"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902493/; classtype:trojan-activity;sid:84765593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.mips"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902494/; classtype:trojan-activity;sid:84765594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.arc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902495/; classtype:trojan-activity;sid:84765595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.x86_64"; depth:18; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902496/; classtype:trojan-activity;sid:84765596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.spc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902497/; classtype:trojan-activity;sid:84765597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.sh4"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902498/; classtype:trojan-activity;sid:84765598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.m68k"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902499/; classtype:trojan-activity;sid:84765599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arm"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902500/; classtype:trojan-activity;sid:84765600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.spc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902461/; classtype:trojan-activity;sid:84765561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902462/; classtype:trojan-activity;sid:84765562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.arm7"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902463/; classtype:trojan-activity;sid:84765563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/dlr.arm"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902464/; classtype:trojan-activity;sid:84765564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.mpsl"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902465/; classtype:trojan-activity;sid:84765565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.x86"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902466/; classtype:trojan-activity;sid:84765566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arm5"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902467/; classtype:trojan-activity;sid:84765567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arm7"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902452/; classtype:trojan-activity;sid:84765552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.x86_64"; depth:18; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902453/; classtype:trojan-activity;sid:84765553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.mpsl"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902454/; classtype:trojan-activity;sid:84765554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arm5"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902455/; classtype:trojan-activity;sid:84765555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.spc"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902456/; classtype:trojan-activity;sid:84765556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.mips"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902457/; classtype:trojan-activity;sid:84765557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.i486"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902458/; classtype:trojan-activity;sid:84765558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.arm"; depth:15; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902459/; classtype:trojan-activity;sid:84765559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.x86_64"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902460/; classtype:trojan-activity;sid:84765560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902451/; classtype:trojan-activity;sid:84765551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902450/; classtype:trojan-activity;sid:84765550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/bot.x86_64"; depth:18; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902448/; classtype:trojan-activity;sid:84765548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902449/; classtype:trojan-activity;sid:84765549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.m68k"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902433/; classtype:trojan-activity;sid:84765533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902434/; classtype:trojan-activity;sid:84765534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/avtech.sh"; depth:10; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902435/; classtype:trojan-activity;sid:84765535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.x86"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902436/; classtype:trojan-activity;sid:84765536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.arm7"; depth:13; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902437/; classtype:trojan-activity;sid:84765537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i686"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902438/; classtype:trojan-activity;sid:84765538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.arm5"; depth:13; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902439/; classtype:trojan-activity;sid:84765539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.sh4"; depth:12; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902440/; classtype:trojan-activity;sid:84765540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.x86"; depth:10; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902441/; classtype:trojan-activity;sid:84765541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.m68k"; depth:13; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902442/; classtype:trojan-activity;sid:84765542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.arm7"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902443/; classtype:trojan-activity;sid:84765543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.out"; depth:6; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902444/; classtype:trojan-activity;sid:84765544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.i686"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902445/; classtype:trojan-activity;sid:84765545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.x86"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902446/; classtype:trojan-activity;sid:84765546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm7"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902447/; classtype:trojan-activity;sid:84765547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.sh4"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902425/; classtype:trojan-activity;sid:84765525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.arc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902426/; classtype:trojan-activity;sid:84765526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mpsl"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902427/; classtype:trojan-activity;sid:84765527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902428/; classtype:trojan-activity;sid:84765528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902429/; classtype:trojan-activity;sid:84765529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.spc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902430/; classtype:trojan-activity;sid:84765530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asus.sh"; depth:8; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902431/; classtype:trojan-activity;sid:84765531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lilin.sh"; depth:9; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902432/; classtype:trojan-activity;sid:84765532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.x86_64"; depth:11; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902415/; classtype:trojan-activity;sid:84765515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm7"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902416/; classtype:trojan-activity;sid:84765516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/link"; depth:5; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902417/; classtype:trojan-activity;sid:84765517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.mpsl"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902418/; classtype:trojan-activity;sid:84765518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm5"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902419/; classtype:trojan-activity;sid:84765519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.arc"; depth:12; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902420/; classtype:trojan-activity;sid:84765520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.ppc"; depth:10; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902421/; classtype:trojan-activity;sid:84765521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.m68k"; depth:11; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902422/; classtype:trojan-activity;sid:84765522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.mpsl"; depth:13; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902423/; classtype:trojan-activity;sid:84765523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm5"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902424/; classtype:trojan-activity;sid:84765524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.x86"; depth:12; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902413/; classtype:trojan-activity;sid:84765513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.spc"; depth:12; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902414/; classtype:trojan-activity;sid:84765514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.mips"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902380/; classtype:trojan-activity;sid:84765480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i486"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902381/; classtype:trojan-activity;sid:84765481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.spc"; depth:10; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902382/; classtype:trojan-activity;sid:84765482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902383/; classtype:trojan-activity;sid:84765483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm6"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902384/; classtype:trojan-activity;sid:84765484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.mpsl"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902385/; classtype:trojan-activity;sid:84765485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.m68k"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902386/; classtype:trojan-activity;sid:84765486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.i486"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902387/; classtype:trojan-activity;sid:84765487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902388/; classtype:trojan-activity;sid:84765488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.ppc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902389/; classtype:trojan-activity;sid:84765489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.m68k"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902390/; classtype:trojan-activity;sid:84765490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zy.sh"; depth:6; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902391/; classtype:trojan-activity;sid:84765491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mips"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902392/; classtype:trojan-activity;sid:84765492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902393/; classtype:trojan-activity;sid:84765493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.sh4"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902394/; classtype:trojan-activity;sid:84765494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.sh4"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902395/; classtype:trojan-activity;sid:84765495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.sh4"; depth:10; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902396/; classtype:trojan-activity;sid:84765496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boa.sh"; depth:7; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902397/; classtype:trojan-activity;sid:84765497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.m68k"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902398/; classtype:trojan-activity;sid:84765498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.spc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902399/; classtype:trojan-activity;sid:84765499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.x86_64"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902400/; classtype:trojan-activity;sid:84765500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.spc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902401/; classtype:trojan-activity;sid:84765501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.sh4"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902402/; classtype:trojan-activity;sid:84765502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mpsl"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902403/; classtype:trojan-activity;sid:84765503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/faith.sh"; depth:9; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902404/; classtype:trojan-activity;sid:84765504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hybrid.sh"; depth:10; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902405/; classtype:trojan-activity;sid:84765505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.mips"; depth:14; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902406/; classtype:trojan-activity;sid:84765506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902407/; classtype:trojan-activity;sid:84765507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.mips"; depth:13; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902408/; classtype:trojan-activity;sid:84765508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.ppc"; depth:12; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902409/; classtype:trojan-activity;sid:84765509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xvr.sh"; depth:7; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902410/; classtype:trojan-activity;sid:84765510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miraint.arm"; depth:12; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902411/; classtype:trojan-activity;sid:84765511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902412/; classtype:trojan-activity;sid:84765512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.ppc"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902375/; classtype:trojan-activity;sid:84765475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902376/; classtype:trojan-activity;sid:84765476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.x86_64"; depth:16; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902377/; classtype:trojan-activity;sid:84765477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm6"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902378/; classtype:trojan-activity;sid:84765478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.arm"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902379/; classtype:trojan-activity;sid:84765479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/script.sh"; depth:10; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902374/; classtype:trojan-activity;sid:84765474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lm"; depth:3; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902373/; classtype:trojan-activity;sid:84765473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.spc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902371/; classtype:trojan-activity;sid:84765471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dlr.ppc"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902372/; classtype:trojan-activity;sid:84765472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.224.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902370/; classtype:trojan-activity;sid:84765470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.212.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902369/; classtype:trojan-activity;sid:84765469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sysorbit.apk"; depth:13; endswith; nocase; http.host; content:"tblcxmo.duckdns.org"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902368/; classtype:trojan-activity;sid:84765468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.212.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902367/; classtype:trojan-activity;sid:84765467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.74.100.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902366/; classtype:trojan-activity;sid:84765466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.184.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902365/; classtype:trojan-activity;sid:84765465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.185.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902364/; classtype:trojan-activity;sid:84765464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.73.44.67"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902363/; classtype:trojan-activity;sid:84765463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.10.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902362/; classtype:trojan-activity;sid:84765462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.185.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902361/; classtype:trojan-activity;sid:84765461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.102.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902360/; classtype:trojan-activity;sid:84765460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.74.100.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902359/; classtype:trojan-activity;sid:84765459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.242.210"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902358/; classtype:trojan-activity;sid:84765458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.53.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902357/; classtype:trojan-activity;sid:84765457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.10.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902356/; classtype:trojan-activity;sid:84765456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.2.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902355/; classtype:trojan-activity;sid:84765455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.59.232.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902354/; classtype:trojan-activity;sid:84765454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.253.104"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902353/; classtype:trojan-activity;sid:84765453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.53.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902352/; classtype:trojan-activity;sid:84765452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.59.232.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902351/; classtype:trojan-activity;sid:84765451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.248.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902350/; classtype:trojan-activity;sid:84765450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.233.94.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902349/; classtype:trojan-activity;sid:84765449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.233.94.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902348/; classtype:trojan-activity;sid:84765448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.248.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902347/; classtype:trojan-activity;sid:84765447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902346/; classtype:trojan-activity;sid:84765446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.206.188.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902345/; classtype:trojan-activity;sid:84765445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.90.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902344/; classtype:trojan-activity;sid:84765444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"1.62.79.200"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902343/; classtype:trojan-activity;sid:84765443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.59.112"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902342/; classtype:trojan-activity;sid:84765442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.255.23"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902339/; classtype:trojan-activity;sid:84765439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.118.60"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902340/; classtype:trojan-activity;sid:84765440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.255.23"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902341/; classtype:trojan-activity;sid:84765441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.195.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902337/; classtype:trojan-activity;sid:84765437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.180.33.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902338/; classtype:trojan-activity;sid:84765438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.88.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902335/; classtype:trojan-activity;sid:84765435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.246.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902336/; classtype:trojan-activity;sid:84765436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.125.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902334/; classtype:trojan-activity;sid:84765434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.88.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902331/; classtype:trojan-activity;sid:84765431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.175.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902332/; classtype:trojan-activity;sid:84765432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.175.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902333/; classtype:trojan-activity;sid:84765433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.187.193.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902330/; classtype:trojan-activity;sid:84765430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.5.187"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902329/; classtype:trojan-activity;sid:84765429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/nels/cli.exe"; depth:19; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902328/; classtype:trojan-activity;sid:84765428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.195.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902327/; classtype:trojan-activity;sid:84765427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"1.62.79.200"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902326/; classtype:trojan-activity;sid:84765426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.219.18.191"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902325/; classtype:trojan-activity;sid:84765425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.241.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902324/; classtype:trojan-activity;sid:84765424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.219.18.191"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902323/; classtype:trojan-activity;sid:84765423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.180.33.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902322/; classtype:trojan-activity;sid:84765422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.54.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902321/; classtype:trojan-activity;sid:84765421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.150.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902320/; classtype:trojan-activity;sid:84765420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.141.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902319/; classtype:trojan-activity;sid:84765419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.178.145"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902317/; classtype:trojan-activity;sid:84765417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.138.136"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902318/; classtype:trojan-activity;sid:84765418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.141.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902316/; classtype:trojan-activity;sid:84765416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.175.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902315/; classtype:trojan-activity;sid:84765415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.138.136"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902314/; classtype:trojan-activity;sid:84765414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.93.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902313/; classtype:trojan-activity;sid:84765413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.175.7.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902312/; classtype:trojan-activity;sid:84765412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.158.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902311/; classtype:trojan-activity;sid:84765411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.93.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902310/; classtype:trojan-activity;sid:84765410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.251.225.122"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902309/; classtype:trojan-activity;sid:84765409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.148.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902308/; classtype:trojan-activity;sid:84765408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.148.158.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902307/; classtype:trojan-activity;sid:84765407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.245.198"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902306/; classtype:trojan-activity;sid:84765406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.91.206.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902305/; classtype:trojan-activity;sid:84765405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.245.198"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902304/; classtype:trojan-activity;sid:84765404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.109.228.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902303/; classtype:trojan-activity;sid:84765403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.arm7"; depth:11; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902302/; classtype:trojan-activity;sid:84765402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/20bypo9tl56golwmhkuzx/watchgoparty.exe|3f|rlkey=djyz9nidcvc5e7ojr8adaoiaf|7c|26|7c|st=9ptdt498|7c|26|7c|dl=1"; depth:116; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902301/; classtype:trojan-activity;sid:84765401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/faraza-1/chillvrmod.com/releases/download/v1.0.0/chillvrout.exe"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902300/; classtype:trojan-activity;sid:84765400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.7"; depth:7; endswith; nocase; http.host; content:"158.255.83.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902294/; classtype:trojan-activity;sid:84765394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.mpsl"; depth:11; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902295/; classtype:trojan-activity;sid:84765395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.arm"; depth:10; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902296/; classtype:trojan-activity;sid:84765396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget"; depth:5; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902297/; classtype:trojan-activity;sid:84765397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.arm5"; depth:11; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902298/; classtype:trojan-activity;sid:84765398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.mips"; depth:11; endswith; nocase; http.host; content:"77.90.185.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902299/; classtype:trojan-activity;sid:84765399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"190.109.228.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902293/; classtype:trojan-activity;sid:84765393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.165.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902292/; classtype:trojan-activity;sid:84765392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902291/; classtype:trojan-activity;sid:84765391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902290/; classtype:trojan-activity;sid:84765390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.207.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902289/; classtype:trojan-activity;sid:84765389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.207.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902288/; classtype:trojan-activity;sid:84765388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.173.53.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902287/; classtype:trojan-activity;sid:84765387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.45.230"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902286/; classtype:trojan-activity;sid:84765386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.25.123.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902285/; classtype:trojan-activity;sid:84765385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.25.123.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902284/; classtype:trojan-activity;sid:84765384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902283/; classtype:trojan-activity;sid:84765383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.45.230"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902282/; classtype:trojan-activity;sid:84765382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.173.53.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902281/; classtype:trojan-activity;sid:84765381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.228.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902280/; classtype:trojan-activity;sid:84765380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connectproagentsetup.msi"; depth:25; endswith; nocase; http.host; content:"185.241.208.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902279/; classtype:trojan-activity;sid:84765379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.236.173"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902278/; classtype:trojan-activity;sid:84765378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/us01.zoom-connect-invites.us.zip"; depth:33; endswith; nocase; http.host; content:"178.16.54.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902277/; classtype:trojan-activity;sid:84765377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"14.0.131.161"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902276/; classtype:trojan-activity;sid:84765376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.116.238.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902275/; classtype:trojan-activity;sid:84765375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.80.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902274/; classtype:trojan-activity;sid:84765374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.229.87"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902273/; classtype:trojan-activity;sid:84765373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coldcard_final.py"; depth:18; endswith; nocase; http.host; content:"144.172.96.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902272/; classtype:trojan-activity;sid:84765372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"124.198.131.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902271/; classtype:trojan-activity;sid:84765371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"124.198.131.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902270/; classtype:trojan-activity;sid:84765370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"2.58.56.151"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902269/; classtype:trojan-activity;sid:84765369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"2.58.56.151"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902268/; classtype:trojan-activity;sid:84765368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902266/; classtype:trojan-activity;sid:84765366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902267/; classtype:trojan-activity;sid:84765367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902262/; classtype:trojan-activity;sid:84765362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902263/; classtype:trojan-activity;sid:84765363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902264/; classtype:trojan-activity;sid:84765364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902265/; classtype:trojan-activity;sid:84765365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902254/; classtype:trojan-activity;sid:84765354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902255/; classtype:trojan-activity;sid:84765355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902256/; classtype:trojan-activity;sid:84765356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902257/; classtype:trojan-activity;sid:84765357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902258/; classtype:trojan-activity;sid:84765358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902259/; classtype:trojan-activity;sid:84765359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902260/; classtype:trojan-activity;sid:84765360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902261/; classtype:trojan-activity;sid:84765361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wd1337"; depth:7; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902253/; classtype:trojan-activity;sid:84765353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/log"; depth:4; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902252/; classtype:trojan-activity;sid:84765352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldboss"; depth:8; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902251/; classtype:trojan-activity;sid:84765351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syst3md"; depth:8; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902250/; classtype:trojan-activity;sid:84765350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proot"; depth:6; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902249/; classtype:trojan-activity;sid:84765349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proot"; depth:6; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902247/; classtype:trojan-activity;sid:84765347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syst3md"; depth:8; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902248/; classtype:trojan-activity;sid:84765348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wd1337"; depth:7; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902246/; classtype:trojan-activity;sid:84765346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traffaarch"; depth:11; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902244/; classtype:trojan-activity;sid:84765344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/log"; depth:4; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902245/; classtype:trojan-activity;sid:84765345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldercheck.sh"; depth:14; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902242/; classtype:trojan-activity;sid:84765342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traff"; depth:6; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902243/; classtype:trojan-activity;sid:84765343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cli"; depth:4; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902240/; classtype:trojan-activity;sid:84765340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/error84"; depth:8; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902241/; classtype:trojan-activity;sid:84765341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldboss"; depth:8; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902239/; classtype:trojan-activity;sid:84765339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main"; depth:5; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902238/; classtype:trojan-activity;sid:84765338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cliaarch"; depth:9; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902237/; classtype:trojan-activity;sid:84765337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check.sh"; depth:9; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902236/; classtype:trojan-activity;sid:84765336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/checkmacos.sh"; depth:14; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902232/; classtype:trojan-activity;sid:84765332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss"; depth:5; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902233/; classtype:trojan-activity;sid:84765333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check1.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902234/; classtype:trojan-activity;sid:84765334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvidia.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902235/; classtype:trojan-activity;sid:84765335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto1"; depth:6; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902230/; classtype:trojan-activity;sid:84765330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto"; depth:5; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902231/; classtype:trojan-activity;sid:84765331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loli"; depth:5; endswith; nocase; http.host; content:"176.65.139.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902229/; classtype:trojan-activity;sid:84765329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.108.151.84"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902228/; classtype:trojan-activity;sid:84765328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.232.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902227/; classtype:trojan-activity;sid:84765327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.233.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902226/; classtype:trojan-activity;sid:84765326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hdgftyu.png"; depth:12; endswith; nocase; http.host; content:"192.109.139.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902225/; classtype:trojan-activity;sid:84765325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/css/images/stego_oo8nser2q2.png"; depth:32; endswith; nocase; http.host; content:"mukabar.co.mz"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902224/; classtype:trojan-activity;sid:84765324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.232.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902223/; classtype:trojan-activity;sid:84765323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902222/; classtype:trojan-activity;sid:84765322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.10.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902221/; classtype:trojan-activity;sid:84765321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.106.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902220/; classtype:trojan-activity;sid:84765320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902219/; classtype:trojan-activity;sid:84765319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pw/accrypted.ps1"; depth:17; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902218/; classtype:trojan-activity;sid:84765318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ttues/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"orienttaxtile.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902217/; classtype:trojan-activity;sid:84765317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.10.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902216/; classtype:trojan-activity;sid:84765316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.47.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902213/; classtype:trojan-activity;sid:84765313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.23.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902214/; classtype:trojan-activity;sid:84765314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.189.160.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902215/; classtype:trojan-activity;sid:84765315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.47.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902212/; classtype:trojan-activity;sid:84765312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_041741.png"; depth:19; endswith; nocase; http.host; content:"107.172.172.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902211/; classtype:trojan-activity;sid:84765311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202608/11/xi178dbqgedoqhkhxtuo/image.png"; depth:41; endswith; nocase; http.host; content:"plain-wnam-prod-public.komododecks.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902210/; classtype:trojan-activity;sid:84765310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/25/weneedtogetbestthingswithbetterplacesforme.hta"; depth:50; endswith; nocase; http.host; content:"107.172.172.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902209/; classtype:trojan-activity;sid:84765309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bookwin.png"; depth:12; endswith; nocase; http.host; content:"pub-988fedd2621d406591dbb4e9358bc901.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902208/; classtype:trojan-activity;sid:84765308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.106.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902207/; classtype:trojan-activity;sid:84765307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yamfloor.hta"; depth:13; endswith; nocase; http.host; content:"pub-ebd75badb3504e77aa1924be8dbce949.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902206/; classtype:trojan-activity;sid:84765306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mostdon.png"; depth:12; endswith; nocase; http.host; content:"pub-988fedd2621d406591dbb4e9358bc901.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902205/; classtype:trojan-activity;sid:84765305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/29/goodthingsforbestpersonforme.hta"; depth:36; endswith; nocase; http.host; content:"144.172.107.214"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902204/; classtype:trojan-activity;sid:84765304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/80/goodthingsforbestfeelingsweformegood.hta"; depth:44; endswith; nocase; http.host; content:"38.240.55.107"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902203/; classtype:trojan-activity;sid:84765303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sntxc"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902202/; classtype:trojan-activity;sid:84765302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hypeman/agent.bin"; depth:18; endswith; nocase; http.host; content:"sumiko.vu"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902201/; classtype:trojan-activity;sid:84765301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peak.sh"; depth:8; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902199/; classtype:trojan-activity;sid:84765299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o.xml"; depth:6; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902200/; classtype:trojan-activity;sid:84765300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oytyusbd/image/upload/v1786325859/img_213650.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902198/; classtype:trojan-activity;sid:84765298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pprvn"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902197/; classtype:trojan-activity;sid:84765297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.4.25.120"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902196/; classtype:trojan-activity;sid:84765296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.23.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902195/; classtype:trojan-activity;sid:84765295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meow.sh"; depth:8; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902194/; classtype:trojan-activity;sid:84765294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/83c238"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902182/; classtype:trojan-activity;sid:84765282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/76341d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902183/; classtype:trojan-activity;sid:84765283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b4efc0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902184/; classtype:trojan-activity;sid:84765284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7e44c2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902185/; classtype:trojan-activity;sid:84765285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/110181"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902186/; classtype:trojan-activity;sid:84765286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2d7d14"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902187/; classtype:trojan-activity;sid:84765287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6337f1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902188/; classtype:trojan-activity;sid:84765288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e7addc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902189/; classtype:trojan-activity;sid:84765289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7f80fa"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902190/; classtype:trojan-activity;sid:84765290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0b3b49"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902191/; classtype:trojan-activity;sid:84765291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9da0b2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902192/; classtype:trojan-activity;sid:84765292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d2aaed"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902193/; classtype:trojan-activity;sid:84765293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902181/; classtype:trojan-activity;sid:84765281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.sparc"; depth:10; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902179/; classtype:trojan-activity;sid:84765279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.i686"; depth:9; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902180/; classtype:trojan-activity;sid:84765280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902174/; classtype:trojan-activity;sid:84765274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.arm6"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902175/; classtype:trojan-activity;sid:84765275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.arm"; depth:10; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902176/; classtype:trojan-activity;sid:84765276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm"; depth:8; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902177/; classtype:trojan-activity;sid:84765277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.sh4"; depth:8; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902178/; classtype:trojan-activity;sid:84765278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.m68k"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902173/; classtype:trojan-activity;sid:84765273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm6"; depth:9; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902172/; classtype:trojan-activity;sid:84765272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902164/; classtype:trojan-activity;sid:84765264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.mpsl"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902165/; classtype:trojan-activity;sid:84765265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ass"; depth:4; endswith; nocase; http.host; content:"72.56.52.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902166/; classtype:trojan-activity;sid:84765266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.m68k"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902167/; classtype:trojan-activity;sid:84765267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.x86"; depth:10; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902168/; classtype:trojan-activity;sid:84765268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.x86_64"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902169/; classtype:trojan-activity;sid:84765269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mips64"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902170/; classtype:trojan-activity;sid:84765270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.arm5"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902171/; classtype:trojan-activity;sid:84765271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.m68k"; depth:9; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902161/; classtype:trojan-activity;sid:84765261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.aarch64"; depth:14; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902162/; classtype:trojan-activity;sid:84765262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gpon443"; depth:8; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902163/; classtype:trojan-activity;sid:84765263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.sh4"; depth:8; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902160/; classtype:trojan-activity;sid:84765260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; depth:30; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902157/; classtype:trojan-activity;sid:84765257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.mips"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902158/; classtype:trojan-activity;sid:84765258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc"; depth:8; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902159/; classtype:trojan-activity;sid:84765259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.sh4"; depth:10; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902152/; classtype:trojan-activity;sid:84765252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm6"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902153/; classtype:trojan-activity;sid:84765253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902154/; classtype:trojan-activity;sid:84765254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.i686"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902155/; classtype:trojan-activity;sid:84765255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wow"; depth:4; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902156/; classtype:trojan-activity;sid:84765256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mpsl"; depth:9; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902150/; classtype:trojan-activity;sid:84765250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thinkphp"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902151/; classtype:trojan-activity;sid:84765251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.ppc"; depth:10; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902145/; classtype:trojan-activity;sid:84765245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; depth:33; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902146/; classtype:trojan-activity;sid:84765246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.ppc"; depth:8; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902147/; classtype:trojan-activity;sid:84765247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips2"; depth:6; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902148/; classtype:trojan-activity;sid:84765248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm5"; depth:9; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902149/; classtype:trojan-activity;sid:84765249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aws"; depth:4; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902140/; classtype:trojan-activity;sid:84765240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902141/; classtype:trojan-activity;sid:84765241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902142/; classtype:trojan-activity;sid:84765242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; depth:33; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902143/; classtype:trojan-activity;sid:84765243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; depth:37; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902144/; classtype:trojan-activity;sid:84765244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902135/; classtype:trojan-activity;sid:84765235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg/proxy.mipsel"; depth:16; endswith; nocase; http.host; content:"72.56.52.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902136/; classtype:trojan-activity;sid:84765236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg/proxy.mips"; depth:14; endswith; nocase; http.host; content:"72.56.52.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902137/; classtype:trojan-activity;sid:84765237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc440"; depth:7; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902138/; classtype:trojan-activity;sid:84765238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902139/; classtype:trojan-activity;sid:84765239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; depth:29; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902134/; classtype:trojan-activity;sid:84765234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; depth:32; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902129/; classtype:trojan-activity;sid:84765229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; depth:36; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902130/; classtype:trojan-activity;sid:84765230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; depth:30; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902131/; classtype:trojan-activity;sid:84765231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; depth:30; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902132/; classtype:trojan-activity;sid:84765232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; depth:33; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902133/; classtype:trojan-activity;sid:84765233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.x86_64"; depth:13; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902121/; classtype:trojan-activity;sid:84765221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys64.arm7"; depth:11; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902122/; classtype:trojan-activity;sid:84765222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm5"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902123/; classtype:trojan-activity;sid:84765223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mips"; depth:9; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902124/; classtype:trojan-activity;sid:84765224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dmpsl"; depth:6; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902125/; classtype:trojan-activity;sid:84765225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lg"; depth:3; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902126/; classtype:trojan-activity;sid:84765226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mpsl"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902127/; classtype:trojan-activity;sid:84765227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902128/; classtype:trojan-activity;sid:84765228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902120/; classtype:trojan-activity;sid:84765220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902118/; classtype:trojan-activity;sid:84765218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902119/; classtype:trojan-activity;sid:84765219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg/proxy.armv5l"; depth:16; endswith; nocase; http.host; content:"72.56.52.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902117/; classtype:trojan-activity;sid:84765217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; depth:30; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902114/; classtype:trojan-activity;sid:84765214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; depth:29; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902115/; classtype:trojan-activity;sid:84765215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; depth:33; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902116/; classtype:trojan-activity;sid:84765216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"91.92.40.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902113/; classtype:trojan-activity;sid:84765213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.29.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902110/; classtype:trojan-activity;sid:84765210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hnap"; depth:5; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902111/; classtype:trojan-activity;sid:84765211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek"; depth:8; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902112/; classtype:trojan-activity;sid:84765212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huawei"; depth:7; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902102/; classtype:trojan-activity;sid:84765202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zte"; depth:4; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902103/; classtype:trojan-activity;sid:84765203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pulse"; depth:6; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902104/; classtype:trojan-activity;sid:84765204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x"; depth:2; endswith; nocase; http.host; content:"72.56.52.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902105/; classtype:trojan-activity;sid:84765205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zyxel"; depth:6; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902106/; classtype:trojan-activity;sid:84765206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/goahead"; depth:8; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902107/; classtype:trojan-activity;sid:84765207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o.sh"; depth:5; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902108/; classtype:trojan-activity;sid:84765208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yarn"; depth:5; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902109/; classtype:trojan-activity;sid:84765209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test.sh"; depth:8; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902100/; classtype:trojan-activity;sid:84765200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adb.sh"; depth:7; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902101/; classtype:trojan-activity;sid:84765201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902099/; classtype:trojan-activity;sid:84765199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/mipsel"; depth:17; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902098/; classtype:trojan-activity;sid:84765198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proxy/mipsel"; depth:13; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902094/; classtype:trojan-activity;sid:84765194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/aarch64"; depth:18; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902095/; classtype:trojan-activity;sid:84765195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/i586"; depth:7; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902096/; classtype:trojan-activity;sid:84765196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nigger/arm5"; depth:12; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902097/; classtype:trojan-activity;sid:84765197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/arm5"; depth:7; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902085/; classtype:trojan-activity;sid:84765185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/arm"; depth:6; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902086/; classtype:trojan-activity;sid:84765186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mipsel"; depth:9; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902087/; classtype:trojan-activity;sid:84765187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/aarch64"; depth:10; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902088/; classtype:trojan-activity;sid:84765188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/arm7"; depth:7; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902089/; classtype:trojan-activity;sid:84765189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/coke.sh"; depth:10; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902090/; classtype:trojan-activity;sid:84765190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/sharp.sh"; depth:11; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902091/; classtype:trojan-activity;sid:84765191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/toto.sh"; depth:10; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902092/; classtype:trojan-activity;sid:84765192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/jaws.sh"; depth:10; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902093/; classtype:trojan-activity;sid:84765193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sgsa"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902082/; classtype:trojan-activity;sid:84765182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fsegv"; depth:6; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902083/; classtype:trojan-activity;sid:84765183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sgsa"; depth:5; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902084/; classtype:trojan-activity;sid:84765184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fsegv"; depth:6; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902079/; classtype:trojan-activity;sid:84765179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fsegv"; depth:6; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902080/; classtype:trojan-activity;sid:84765180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sgsa"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902081/; classtype:trojan-activity;sid:84765181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adb.sh"; depth:7; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902074/; classtype:trojan-activity;sid:84765174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adb.sh"; depth:7; endswith; nocase; http.host; content:"94.154.43.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902075/; classtype:trojan-activity;sid:84765175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sgsa"; depth:5; endswith; nocase; http.host; content:"94.154.43.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902076/; classtype:trojan-activity;sid:84765176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fsegv"; depth:6; endswith; nocase; http.host; content:"94.154.43.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902077/; classtype:trojan-activity;sid:84765177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adb.sh"; depth:7; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902078/; classtype:trojan-activity;sid:84765178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adb.sh"; depth:7; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902073/; classtype:trojan-activity;sid:84765173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.124.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902072/; classtype:trojan-activity;sid:84765172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.185.91.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902071/; classtype:trojan-activity;sid:84765171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.124.6"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902070/; classtype:trojan-activity;sid:84765170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.33.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902069/; classtype:trojan-activity;sid:84765169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv4l"; depth:7; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902066/; classtype:trojan-activity;sid:84765166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv5l"; depth:7; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902067/; classtype:trojan-activity;sid:84765167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902068/; classtype:trojan-activity;sid:84765168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902065/; classtype:trojan-activity;sid:84765165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902064/; classtype:trojan-activity;sid:84765164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.33.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902063/; classtype:trojan-activity;sid:84765163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"176.65.139.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902062/; classtype:trojan-activity;sid:84765162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.161.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902061/; classtype:trojan-activity;sid:84765161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"106.13.23.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902060/; classtype:trojan-activity;sid:84765160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.245.111.51"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902059/; classtype:trojan-activity;sid:84765159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"114.67.87.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902057/; classtype:trojan-activity;sid:84765157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"222.213.23.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902058/; classtype:trojan-activity;sid:84765158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.222.247.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902044/; classtype:trojan-activity;sid:84765144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.237.124.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902045/; classtype:trojan-activity;sid:84765145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.237.127.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902046/; classtype:trojan-activity;sid:84765146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.237.167.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902047/; classtype:trojan-activity;sid:84765147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.236.180.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902048/; classtype:trojan-activity;sid:84765148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.219.241.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902049/; classtype:trojan-activity;sid:84765149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.219.210.218"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902050/; classtype:trojan-activity;sid:84765150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.219.69.227"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902051/; classtype:trojan-activity;sid:84765151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.219.169.170"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902052/; classtype:trojan-activity;sid:84765152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.236.70.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902053/; classtype:trojan-activity;sid:84765153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.236.122.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902054/; classtype:trojan-activity;sid:84765154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.219.62.229"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902055/; classtype:trojan-activity;sid:84765155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.222.179.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902056/; classtype:trojan-activity;sid:84765156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.219.155.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902043/; classtype:trojan-activity;sid:84765143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"64.226.68.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902042/; classtype:trojan-activity;sid:84765142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.245.84.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902037/; classtype:trojan-activity;sid:84765137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.236.28.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902038/; classtype:trojan-activity;sid:84765138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.236.146.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902039/; classtype:trojan-activity;sid:84765139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"49.235.101.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902040/; classtype:trojan-activity;sid:84765140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.219.85.120"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902041/; classtype:trojan-activity;sid:84765141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.236.172.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902036/; classtype:trojan-activity;sid:84765136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"18.175.166.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902035/; classtype:trojan-activity;sid:84765135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.mips"; depth:18; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902028/; classtype:trojan-activity;sid:84765128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.ppc"; depth:17; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902029/; classtype:trojan-activity;sid:84765129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dddd.sh"; depth:8; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902030/; classtype:trojan-activity;sid:84765130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.x86"; depth:17; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902031/; classtype:trojan-activity;sid:84765131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.m68k"; depth:18; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902032/; classtype:trojan-activity;sid:84765132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.spc"; depth:17; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902033/; classtype:trojan-activity;sid:84765133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arm5"; depth:18; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902034/; classtype:trojan-activity;sid:84765134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.mpsl"; depth:18; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902026/; classtype:trojan-activity;sid:84765126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva.sh"; depth:7; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902027/; classtype:trojan-activity;sid:84765127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arm6"; depth:18; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902021/; classtype:trojan-activity;sid:84765121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arm7"; depth:18; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902022/; classtype:trojan-activity;sid:84765122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arc"; depth:17; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902023/; classtype:trojan-activity;sid:84765123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arm"; depth:17; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902024/; classtype:trojan-activity;sid:84765124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.sh4"; depth:17; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902025/; classtype:trojan-activity;sid:84765125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.161.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902020/; classtype:trojan-activity;sid:84765120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.47.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902019/; classtype:trojan-activity;sid:84765119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vsoonlfluzpdmiw.exe"; depth:20; endswith; nocase; http.host; content:"alphalkenya.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902012/; classtype:trojan-activity;sid:84765112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arm5"; depth:18; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902011/; classtype:trojan-activity;sid:84765111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.x86"; depth:17; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902010/; classtype:trojan-activity;sid:84765110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cli"; depth:4; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902007/; classtype:trojan-activity;sid:84765107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/error84"; depth:8; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902008/; classtype:trojan-activity;sid:84765108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cliaarch"; depth:9; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902004/; classtype:trojan-activity;sid:84765104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss"; depth:5; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902005/; classtype:trojan-activity;sid:84765105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main"; depth:5; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902006/; classtype:trojan-activity;sid:84765106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.spc"; depth:17; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901999/; classtype:trojan-activity;sid:84765099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.mips"; depth:18; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902000/; classtype:trojan-activity;sid:84765100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arc"; depth:17; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902001/; classtype:trojan-activity;sid:84765101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.sh4"; depth:17; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902002/; classtype:trojan-activity;sid:84765102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arm6"; depth:18; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902003/; classtype:trojan-activity;sid:84765103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.x86_64"; depth:15; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901995/; classtype:trojan-activity;sid:84765095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.i686"; depth:18; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901996/; classtype:trojan-activity;sid:84765096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901998/; classtype:trojan-activity;sid:84765098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.ppc"; depth:17; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901990/; classtype:trojan-activity;sid:84765090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.m68k"; depth:18; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901991/; classtype:trojan-activity;sid:84765091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arm7"; depth:18; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901992/; classtype:trojan-activity;sid:84765092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.arm"; depth:17; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901993/; classtype:trojan-activity;sid:84765093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/watcher-script-aarch"; depth:21; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901994/; classtype:trojan-activity;sid:84765094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.mpsl"; depth:18; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901987/; classtype:trojan-activity;sid:84765087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.x86_64"; depth:20; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901988/; classtype:trojan-activity;sid:84765088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva_bins/rva.i468"; depth:18; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901989/; classtype:trojan-activity;sid:84765089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nuts/poop"; depth:10; endswith; nocase; http.host; content:"216.9.226.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901986/; classtype:trojan-activity;sid:84765086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901985/; classtype:trojan-activity;sid:84765085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1"; depth:2; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901984/; classtype:trojan-activity;sid:84765084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901982/; classtype:trojan-activity;sid:84765082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901983/; classtype:trojan-activity;sid:84765083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901974/; classtype:trojan-activity;sid:84765074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901975/; classtype:trojan-activity;sid:84765075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901976/; classtype:trojan-activity;sid:84765076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arc"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901977/; classtype:trojan-activity;sid:84765077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901978/; classtype:trojan-activity;sid:84765078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901979/; classtype:trojan-activity;sid:84765079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901980/; classtype:trojan-activity;sid:84765080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traffaarch"; depth:11; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901981/; classtype:trojan-activity;sid:84765081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nuts/bolts"; depth:11; endswith; nocase; http.host; content:"216.9.226.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901971/; classtype:trojan-activity;sid:84765071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901972/; classtype:trojan-activity;sid:84765072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loli"; depth:5; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901973/; classtype:trojan-activity;sid:84765073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/sh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901955/; classtype:trojan-activity;sid:84765055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901956/; classtype:trojan-activity;sid:84765056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mpsl"; depth:11; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901957/; classtype:trojan-activity;sid:84765057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901958/; classtype:trojan-activity;sid:84765058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901959/; classtype:trojan-activity;sid:84765059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64"; depth:13; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901960/; classtype:trojan-activity;sid:84765060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvidia.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901961/; classtype:trojan-activity;sid:84765061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901962/; classtype:trojan-activity;sid:84765062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901963/; classtype:trojan-activity;sid:84765063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901964/; classtype:trojan-activity;sid:84765064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901965/; classtype:trojan-activity;sid:84765065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traff"; depth:6; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901966/; classtype:trojan-activity;sid:84765066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901967/; classtype:trojan-activity;sid:84765067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901968/; classtype:trojan-activity;sid:84765068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm7"; depth:11; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901969/; classtype:trojan-activity;sid:84765069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901970/; classtype:trojan-activity;sid:84765070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901942/; classtype:trojan-activity;sid:84765042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901943/; classtype:trojan-activity;sid:84765043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/m68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901944/; classtype:trojan-activity;sid:84765044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901945/; classtype:trojan-activity;sid:84765045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901946/; classtype:trojan-activity;sid:84765046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901947/; classtype:trojan-activity;sid:84765047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm5"; depth:11; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901948/; classtype:trojan-activity;sid:84765048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901949/; classtype:trojan-activity;sid:84765049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/ppc"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901950/; classtype:trojan-activity;sid:84765050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901951/; classtype:trojan-activity;sid:84765051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mips"; depth:11; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901952/; classtype:trojan-activity;sid:84765052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901953/; classtype:trojan-activity;sid:84765053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901954/; classtype:trojan-activity;sid:84765054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901939/; classtype:trojan-activity;sid:84765039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901940/; classtype:trojan-activity;sid:84765040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901941/; classtype:trojan-activity;sid:84765041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/checkmacos.sh"; depth:14; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901938/; classtype:trojan-activity;sid:84765038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto"; depth:5; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901936/; classtype:trojan-activity;sid:84765036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dddd.sh"; depth:8; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901937/; classtype:trojan-activity;sid:84765037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901935/; classtype:trojan-activity;sid:84765035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901927/; classtype:trojan-activity;sid:84765027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm6"; depth:11; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901928/; classtype:trojan-activity;sid:84765028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901929/; classtype:trojan-activity;sid:84765029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901930/; classtype:trojan-activity;sid:84765030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901931/; classtype:trojan-activity;sid:84765031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901932/; classtype:trojan-activity;sid:84765032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901933/; classtype:trojan-activity;sid:84765033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901934/; classtype:trojan-activity;sid:84765034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldercheck.sh"; depth:14; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901926/; classtype:trojan-activity;sid:84765026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rva.sh"; depth:7; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901921/; classtype:trojan-activity;sid:84765021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901922/; classtype:trojan-activity;sid:84765022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto1"; depth:6; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901923/; classtype:trojan-activity;sid:84765023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check.sh"; depth:9; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901924/; classtype:trojan-activity;sid:84765024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check1.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901925/; classtype:trojan-activity;sid:84765025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/spc"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901917/; classtype:trojan-activity;sid:84765017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901918/; classtype:trojan-activity;sid:84765018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901919/; classtype:trojan-activity;sid:84765019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901920/; classtype:trojan-activity;sid:84765020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901912/; classtype:trojan-activity;sid:84765012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901913/; classtype:trojan-activity;sid:84765013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901914/; classtype:trojan-activity;sid:84765014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901915/; classtype:trojan-activity;sid:84765015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901916/; classtype:trojan-activity;sid:84765016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mb/crypted.ps1"; depth:15; endswith; nocase; http.host; content:"217.60.241.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901911/; classtype:trojan-activity;sid:84765011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_213534.png"; depth:15; endswith; nocase; http.host; content:"2goelectricity.co.za"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901910/; classtype:trojan-activity;sid:84765010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/text/fxuqicg/qvbudog/bstwneo/oo/crypted.ps1"; depth:56; endswith; nocase; http.host; content:"suavasua.vn"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901909/; classtype:trojan-activity;sid:84765009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3bdfe634dff70206.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901908/; classtype:trojan-activity;sid:84765008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_809ebb7e1f93e6cb.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901907/; classtype:trojan-activity;sid:84765007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.179.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901906/; classtype:trojan-activity;sid:84765006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"176.65.139.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901903/; classtype:trojan-activity;sid:84765003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"176.65.139.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901904/; classtype:trojan-activity;sid:84765004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"176.65.139.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901905/; classtype:trojan-activity;sid:84765005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901884/; classtype:trojan-activity;sid:84764984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901885/; classtype:trojan-activity;sid:84764985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901886/; classtype:trojan-activity;sid:84764986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901887/; classtype:trojan-activity;sid:84764987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901888/; classtype:trojan-activity;sid:84764988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsrouter"; depth:16; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901889/; classtype:trojan-activity;sid:84764989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901890/; classtype:trojan-activity;sid:84764990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telnet.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901891/; classtype:trojan-activity;sid:84764991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901892/; classtype:trojan-activity;sid:84764992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901893/; classtype:trojan-activity;sid:84764993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901894/; classtype:trojan-activity;sid:84764994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901895/; classtype:trojan-activity;sid:84764995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901896/; classtype:trojan-activity;sid:84764996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901897/; classtype:trojan-activity;sid:84764997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901898/; classtype:trojan-activity;sid:84764998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901899/; classtype:trojan-activity;sid:84764999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"176.65.139.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901900/; classtype:trojan-activity;sid:84765000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telnet.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901901/; classtype:trojan-activity;sid:84765001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"176.65.139.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901902/; classtype:trojan-activity;sid:84765002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901873/; classtype:trojan-activity;sid:84764973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901874/; classtype:trojan-activity;sid:84764974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901875/; classtype:trojan-activity;sid:84764975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901876/; classtype:trojan-activity;sid:84764976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901877/; classtype:trojan-activity;sid:84764977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901878/; classtype:trojan-activity;sid:84764978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901879/; classtype:trojan-activity;sid:84764979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901880/; classtype:trojan-activity;sid:84764980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901881/; classtype:trojan-activity;sid:84764981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901882/; classtype:trojan-activity;sid:84764982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"176.65.139.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901883/; classtype:trojan-activity;sid:84764983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.arm5"; depth:13; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901869/; classtype:trojan-activity;sid:84764969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.m68k"; depth:13; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901870/; classtype:trojan-activity;sid:84764970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.arm7"; depth:13; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901871/; classtype:trojan-activity;sid:84764971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.mpsl"; depth:13; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901872/; classtype:trojan-activity;sid:84764972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tplink.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901862/; classtype:trojan-activity;sid:84764962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.x86"; depth:12; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901863/; classtype:trojan-activity;sid:84764963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.sh4"; depth:12; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901864/; classtype:trojan-activity;sid:84764964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.arm"; depth:12; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901865/; classtype:trojan-activity;sid:84764965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.ppc"; depth:12; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901866/; classtype:trojan-activity;sid:84764966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.arm6"; depth:13; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901867/; classtype:trojan-activity;sid:84764967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebirth.mips"; depth:13; endswith; nocase; http.host; content:"176.65.139.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901868/; classtype:trojan-activity;sid:84764968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901861/; classtype:trojan-activity;sid:84764961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901847/; classtype:trojan-activity;sid:84764947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901848/; classtype:trojan-activity;sid:84764948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901849/; classtype:trojan-activity;sid:84764949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901850/; classtype:trojan-activity;sid:84764950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901851/; classtype:trojan-activity;sid:84764951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901852/; classtype:trojan-activity;sid:84764952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901853/; classtype:trojan-activity;sid:84764953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901854/; classtype:trojan-activity;sid:84764954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901855/; classtype:trojan-activity;sid:84764955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901856/; classtype:trojan-activity;sid:84764956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901857/; classtype:trojan-activity;sid:84764957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901858/; classtype:trojan-activity;sid:84764958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901859/; classtype:trojan-activity;sid:84764959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901860/; classtype:trojan-activity;sid:84764960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901836/; classtype:trojan-activity;sid:84764936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901837/; classtype:trojan-activity;sid:84764937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901838/; classtype:trojan-activity;sid:84764938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901839/; classtype:trojan-activity;sid:84764939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901840/; classtype:trojan-activity;sid:84764940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901841/; classtype:trojan-activity;sid:84764941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901842/; classtype:trojan-activity;sid:84764942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901843/; classtype:trojan-activity;sid:84764943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901844/; classtype:trojan-activity;sid:84764944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901845/; classtype:trojan-activity;sid:84764945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901846/; classtype:trojan-activity;sid:84764946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901833/; classtype:trojan-activity;sid:84764933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901834/; classtype:trojan-activity;sid:84764934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901835/; classtype:trojan-activity;sid:84764935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901828/; classtype:trojan-activity;sid:84764928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901829/; classtype:trojan-activity;sid:84764929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901830/; classtype:trojan-activity;sid:84764930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901831/; classtype:trojan-activity;sid:84764931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.53.25"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901832/; classtype:trojan-activity;sid:84764932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901819/; classtype:trojan-activity;sid:84764919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901820/; classtype:trojan-activity;sid:84764920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901821/; classtype:trojan-activity;sid:84764921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901822/; classtype:trojan-activity;sid:84764922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901823/; classtype:trojan-activity;sid:84764923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901824/; classtype:trojan-activity;sid:84764924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901825/; classtype:trojan-activity;sid:84764925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901826/; classtype:trojan-activity;sid:84764926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901827/; classtype:trojan-activity;sid:84764927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901818/; classtype:trojan-activity;sid:84764918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901817/; classtype:trojan-activity;sid:84764917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901808/; classtype:trojan-activity;sid:84764908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901809/; classtype:trojan-activity;sid:84764909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901810/; classtype:trojan-activity;sid:84764910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901811/; classtype:trojan-activity;sid:84764911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901812/; classtype:trojan-activity;sid:84764912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901813/; classtype:trojan-activity;sid:84764913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901814/; classtype:trojan-activity;sid:84764914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901815/; classtype:trojan-activity;sid:84764915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901816/; classtype:trojan-activity;sid:84764916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901800/; classtype:trojan-activity;sid:84764900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901801/; classtype:trojan-activity;sid:84764901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901802/; classtype:trojan-activity;sid:84764902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901803/; classtype:trojan-activity;sid:84764903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901804/; classtype:trojan-activity;sid:84764904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901805/; classtype:trojan-activity;sid:84764905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901806/; classtype:trojan-activity;sid:84764906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901807/; classtype:trojan-activity;sid:84764907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901796/; classtype:trojan-activity;sid:84764896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901797/; classtype:trojan-activity;sid:84764897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901798/; classtype:trojan-activity;sid:84764898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901799/; classtype:trojan-activity;sid:84764899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901794/; classtype:trojan-activity;sid:84764894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901795/; classtype:trojan-activity;sid:84764895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"89.189.181.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901792/; classtype:trojan-activity;sid:84764892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901793/; classtype:trojan-activity;sid:84764893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901790/; classtype:trojan-activity;sid:84764890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"176.65.139.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901791/; classtype:trojan-activity;sid:84764891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.178.118.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901789/; classtype:trojan-activity;sid:84764889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901788/; classtype:trojan-activity;sid:84764888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901787/; classtype:trojan-activity;sid:84764887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901781/; classtype:trojan-activity;sid:84764881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901782/; classtype:trojan-activity;sid:84764882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901783/; classtype:trojan-activity;sid:84764883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901784/; classtype:trojan-activity;sid:84764884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901785/; classtype:trojan-activity;sid:84764885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm5"; depth:6; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901786/; classtype:trojan-activity;sid:84764886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901772/; classtype:trojan-activity;sid:84764872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901773/; classtype:trojan-activity;sid:84764873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901774/; classtype:trojan-activity;sid:84764874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901775/; classtype:trojan-activity;sid:84764875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901776/; classtype:trojan-activity;sid:84764876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901777/; classtype:trojan-activity;sid:84764877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm7"; depth:6; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901778/; classtype:trojan-activity;sid:84764878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901779/; classtype:trojan-activity;sid:84764879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901780/; classtype:trojan-activity;sid:84764880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901771/; classtype:trojan-activity;sid:84764871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901770/; classtype:trojan-activity;sid:84764870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901758/; classtype:trojan-activity;sid:84764858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901759/; classtype:trojan-activity;sid:84764859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901760/; classtype:trojan-activity;sid:84764860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901761/; classtype:trojan-activity;sid:84764861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901762/; classtype:trojan-activity;sid:84764862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kla.sh"; depth:12; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901763/; classtype:trojan-activity;sid:84764863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kla.sh"; depth:7; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901764/; classtype:trojan-activity;sid:84764864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901765/; classtype:trojan-activity;sid:84764865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901766/; classtype:trojan-activity;sid:84764866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901767/; classtype:trojan-activity;sid:84764867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pmips"; depth:6; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901768/; classtype:trojan-activity;sid:84764868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901769/; classtype:trojan-activity;sid:84764869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901756/; classtype:trojan-activity;sid:84764856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901757/; classtype:trojan-activity;sid:84764857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm6"; depth:6; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901755/; classtype:trojan-activity;sid:84764855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psh4"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901749/; classtype:trojan-activity;sid:84764849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pppc"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901750/; classtype:trojan-activity;sid:84764850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901751/; classtype:trojan-activity;sid:84764851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901752/; classtype:trojan-activity;sid:84764852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pm68k"; depth:6; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901753/; classtype:trojan-activity;sid:84764853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/px86"; depth:5; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901754/; classtype:trojan-activity;sid:84764854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pmpsl"; depth:6; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901748/; classtype:trojan-activity;sid:84764848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"176.65.139.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901747/; classtype:trojan-activity;sid:84764847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.179.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901746/; classtype:trojan-activity;sid:84764846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.178.118.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901745/; classtype:trojan-activity;sid:84764845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901744/; classtype:trojan-activity;sid:84764844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.35.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901743/; classtype:trojan-activity;sid:84764843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/volcano9.exe"; depth:13; endswith; nocase; http.host; content:"rcf.co.mz"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901742/; classtype:trojan-activity;sid:84764842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppk/rawfiles.exe"; depth:17; endswith; nocase; http.host; content:"seniorsushi.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901741/; classtype:trojan-activity;sid:84764841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tuess/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"orienttaxtile.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901740/; classtype:trojan-activity;sid:84764840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"121.5.26.199"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901739/; classtype:trojan-activity;sid:84764839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm7"; depth:13; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901737/; classtype:trojan-activity;sid:84764837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/ppc"; depth:12; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901738/; classtype:trojan-activity;sid:84764838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"api.mineblack.lol"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901736/; classtype:trojan-activity;sid:84764836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm7"; depth:13; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901733/; classtype:trojan-activity;sid:84764833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/x86_32"; depth:15; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901734/; classtype:trojan-activity;sid:84764834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/m68k"; depth:13; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901735/; classtype:trojan-activity;sid:84764835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.204.233.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901732/; classtype:trojan-activity;sid:84764832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.4.25.20"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901730/; classtype:trojan-activity;sid:84764830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.52.204.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901731/; classtype:trojan-activity;sid:84764831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901728/; classtype:trojan-activity;sid:84764828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901729/; classtype:trojan-activity;sid:84764829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.4.25.20"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901727/; classtype:trojan-activity;sid:84764827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.192.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901726/; classtype:trojan-activity;sid:84764826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm6"; depth:13; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901724/; classtype:trojan-activity;sid:84764824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/x86_64"; depth:15; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901725/; classtype:trojan-activity;sid:84764825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/mips"; depth:13; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901722/; classtype:trojan-activity;sid:84764822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/mipsel"; depth:11; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901723/; classtype:trojan-activity;sid:84764823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86"; depth:8; endswith; nocase; http.host; content:"api.mineblack.lol"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901720/; classtype:trojan-activity;sid:84764820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.43.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901721/; classtype:trojan-activity;sid:84764821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/aarch64"; depth:16; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901714/; classtype:trojan-activity;sid:84764814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901715/; classtype:trojan-activity;sid:84764815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901716/; classtype:trojan-activity;sid:84764816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/x86"; depth:12; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901717/; classtype:trojan-activity;sid:84764817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901718/; classtype:trojan-activity;sid:84764818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.187.193.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901719/; classtype:trojan-activity;sid:84764819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.166.194.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901709/; classtype:trojan-activity;sid:84764809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.252.159.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901710/; classtype:trojan-activity;sid:84764810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.44.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901711/; classtype:trojan-activity;sid:84764811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.110.61.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901712/; classtype:trojan-activity;sid:84764812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/ppc440"; depth:15; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901713/; classtype:trojan-activity;sid:84764813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.154.181.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901708/; classtype:trojan-activity;sid:84764808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.149.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901706/; classtype:trojan-activity;sid:84764806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.195.182"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901707/; classtype:trojan-activity;sid:84764807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.52.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901688/; classtype:trojan-activity;sid:84764788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"136.60.32.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901689/; classtype:trojan-activity;sid:84764789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm"; depth:12; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901690/; classtype:trojan-activity;sid:84764790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.201.103"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901691/; classtype:trojan-activity;sid:84764791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/aarch64"; depth:16; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901692/; classtype:trojan-activity;sid:84764792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.254.223"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901693/; classtype:trojan-activity;sid:84764793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_32"; depth:7; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901694/; classtype:trojan-activity;sid:84764794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/mpsl"; depth:13; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901695/; classtype:trojan-activity;sid:84764795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/sh4"; depth:12; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901696/; classtype:trojan-activity;sid:84764796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.1.226.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901697/; classtype:trojan-activity;sid:84764797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.127.154.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901698/; classtype:trojan-activity;sid:84764798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.249.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901699/; classtype:trojan-activity;sid:84764799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.149.19.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901700/; classtype:trojan-activity;sid:84764800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/mips"; depth:13; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901701/; classtype:trojan-activity;sid:84764801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.198.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901702/; classtype:trojan-activity;sid:84764802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901703/; classtype:trojan-activity;sid:84764803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.110.61.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901704/; classtype:trojan-activity;sid:84764804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaws"; depth:5; endswith; nocase; http.host; content:"api.mineblack.lol"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901705/; classtype:trojan-activity;sid:84764805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/debug.dbg"; depth:15; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901687/; classtype:trojan-activity;sid:84764787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.52.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901686/; classtype:trojan-activity;sid:84764786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm5"; depth:13; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901680/; classtype:trojan-activity;sid:84764780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/mpsl"; depth:13; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901681/; classtype:trojan-activity;sid:84764781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.109.140.49"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901682/; classtype:trojan-activity;sid:84764782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.150.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901683/; classtype:trojan-activity;sid:84764783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901684/; classtype:trojan-activity;sid:84764784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64nosl"; depth:16; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901685/; classtype:trojan-activity;sid:84764785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.148.236.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901676/; classtype:trojan-activity;sid:84764776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.148.236.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901677/; classtype:trojan-activity;sid:84764777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.173.78.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901678/; classtype:trojan-activity;sid:84764778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901679/; classtype:trojan-activity;sid:84764779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.174.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901669/; classtype:trojan-activity;sid:84764769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.215.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901670/; classtype:trojan-activity;sid:84764770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.126.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901671/; classtype:trojan-activity;sid:84764771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.249.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901672/; classtype:trojan-activity;sid:84764772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.246.222"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901673/; classtype:trojan-activity;sid:84764773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901674/; classtype:trojan-activity;sid:84764774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.80.60.21"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901675/; classtype:trojan-activity;sid:84764775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.75.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901668/; classtype:trojan-activity;sid:84764768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.42.71.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901666/; classtype:trojan-activity;sid:84764766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/ppc"; depth:12; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901667/; classtype:trojan-activity;sid:84764767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.86.172.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901659/; classtype:trojan-activity;sid:84764759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.166.194.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901660/; classtype:trojan-activity;sid:84764760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/ppc440"; depth:15; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901661/; classtype:trojan-activity;sid:84764761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.131.65"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901662/; classtype:trojan-activity;sid:84764762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.40.36"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901663/; classtype:trojan-activity;sid:84764763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.54.158.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901664/; classtype:trojan-activity;sid:84764764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.204.233.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901665/; classtype:trojan-activity;sid:84764765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.98.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901651/; classtype:trojan-activity;sid:84764751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901652/; classtype:trojan-activity;sid:84764752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/x86_32"; depth:15; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901653/; classtype:trojan-activity;sid:84764753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.226.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901654/; classtype:trojan-activity;sid:84764754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.197.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901655/; classtype:trojan-activity;sid:84764755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.216.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901656/; classtype:trojan-activity;sid:84764756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.193.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901657/; classtype:trojan-activity;sid:84764757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.127.220.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901658/; classtype:trojan-activity;sid:84764758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.30.36"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901645/; classtype:trojan-activity;sid:84764745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.167.85.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901646/; classtype:trojan-activity;sid:84764746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.93.138.83"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901647/; classtype:trojan-activity;sid:84764747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.194.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901648/; classtype:trojan-activity;sid:84764748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.201.103"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901649/; classtype:trojan-activity;sid:84764749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.230.81.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901650/; classtype:trojan-activity;sid:84764750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.202.17.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901644/; classtype:trojan-activity;sid:84764744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.146.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901643/; classtype:trojan-activity;sid:84764743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/i586"; depth:9; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901639/; classtype:trojan-activity;sid:84764739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.203.62.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901640/; classtype:trojan-activity;sid:84764740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.154.181.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901641/; classtype:trojan-activity;sid:84764741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.114.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901642/; classtype:trojan-activity;sid:84764742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901626/; classtype:trojan-activity;sid:84764726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.40.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901627/; classtype:trojan-activity;sid:84764727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"86.98.154.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901628/; classtype:trojan-activity;sid:84764728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.21.31.81"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901629/; classtype:trojan-activity;sid:84764729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.254.223"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901630/; classtype:trojan-activity;sid:84764730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901631/; classtype:trojan-activity;sid:84764731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.90.59"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901632/; classtype:trojan-activity;sid:84764732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/debug_main.exe"; depth:20; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901633/; classtype:trojan-activity;sid:84764733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/m68k"; depth:13; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901634/; classtype:trojan-activity;sid:84764734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.238.30"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901635/; classtype:trojan-activity;sid:84764735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.106.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901636/; classtype:trojan-activity;sid:84764736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.107.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901637/; classtype:trojan-activity;sid:84764737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.159.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901638/; classtype:trojan-activity;sid:84764738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.52.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901621/; classtype:trojan-activity;sid:84764721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/x86"; depth:12; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901622/; classtype:trojan-activity;sid:84764722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/duza"; depth:5; endswith; nocase; http.host; content:"193.23.118.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901623/; classtype:trojan-activity;sid:84764723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/x86_64"; depth:15; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901624/; classtype:trojan-activity;sid:84764724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901625/; classtype:trojan-activity;sid:84764725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.219.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901620/; classtype:trojan-activity;sid:84764720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.154.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901616/; classtype:trojan-activity;sid:84764716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.167.85.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901617/; classtype:trojan-activity;sid:84764717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.180.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901618/; classtype:trojan-activity;sid:84764718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.40.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901619/; classtype:trojan-activity;sid:84764719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.213.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901608/; classtype:trojan-activity;sid:84764708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.180.66.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901609/; classtype:trojan-activity;sid:84764709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.214.37"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901610/; classtype:trojan-activity;sid:84764710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.106.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901611/; classtype:trojan-activity;sid:84764711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.220.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901612/; classtype:trojan-activity;sid:84764712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.175.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901613/; classtype:trojan-activity;sid:84764713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.233.65.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901614/; classtype:trojan-activity;sid:84764714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.202.17.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901615/; classtype:trojan-activity;sid:84764715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.1.226.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901602/; classtype:trojan-activity;sid:84764702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.116.39.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901603/; classtype:trojan-activity;sid:84764703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.92.80.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901604/; classtype:trojan-activity;sid:84764704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.176.120.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901605/; classtype:trojan-activity;sid:84764705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901606/; classtype:trojan-activity;sid:84764706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"1.20.91.236"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901607/; classtype:trojan-activity;sid:84764707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.189.160.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901601/; classtype:trojan-activity;sid:84764701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm5"; depth:13; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901600/; classtype:trojan-activity;sid:84764700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.44.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901585/; classtype:trojan-activity;sid:84764685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.44.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901586/; classtype:trojan-activity;sid:84764686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.246.222"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901587/; classtype:trojan-activity;sid:84764687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.95.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901588/; classtype:trojan-activity;sid:84764688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.90.59"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901589/; classtype:trojan-activity;sid:84764689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.236.61"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901590/; classtype:trojan-activity;sid:84764690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.106.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901591/; classtype:trojan-activity;sid:84764691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm6"; depth:13; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901592/; classtype:trojan-activity;sid:84764692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/sh4"; depth:12; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901593/; classtype:trojan-activity;sid:84764693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.44.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901594/; classtype:trojan-activity;sid:84764694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.159.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901595/; classtype:trojan-activity;sid:84764695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"140.237.6.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901596/; classtype:trojan-activity;sid:84764696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/main.exe"; depth:14; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901597/; classtype:trojan-activity;sid:84764697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.158.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901598/; classtype:trojan-activity;sid:84764698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http/k1crypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901599/; classtype:trojan-activity;sid:84764699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"213.66.220.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901574/; classtype:trojan-activity;sid:84764674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.158.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901575/; classtype:trojan-activity;sid:84764675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.226.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901576/; classtype:trojan-activity;sid:84764676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.106.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901577/; classtype:trojan-activity;sid:84764677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.116.39.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901578/; classtype:trojan-activity;sid:84764678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"140.237.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901579/; classtype:trojan-activity;sid:84764679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.50.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901580/; classtype:trojan-activity;sid:84764680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.52.247.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901581/; classtype:trojan-activity;sid:84764681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm"; depth:12; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901582/; classtype:trojan-activity;sid:84764682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.233.65.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901583/; classtype:trojan-activity;sid:84764683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.21.31.81"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901584/; classtype:trojan-activity;sid:84764684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exploit.sh"; depth:11; endswith; nocase; http.host; content:"voltagec2.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901571/; classtype:trojan-activity;sid:84764671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.106.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901572/; classtype:trojan-activity;sid:84764672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.98.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901573/; classtype:trojan-activity;sid:84764673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"213.66.220.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901570/; classtype:trojan-activity;sid:84764670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http/kk2crypted.ps1"; depth:20; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901569/; classtype:trojan-activity;sid:84764669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arc"; depth:9; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901568/; classtype:trojan-activity;sid:84764668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901567/; classtype:trojan-activity;sid:84764667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901564/; classtype:trojan-activity;sid:84764664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901565/; classtype:trojan-activity;sid:84764665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901566/; classtype:trojan-activity;sid:84764666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901559/; classtype:trojan-activity;sid:84764659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901560/; classtype:trojan-activity;sid:84764660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901561/; classtype:trojan-activity;sid:84764661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"manbipll.duckdns.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901562/; classtype:trojan-activity;sid:84764662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901563/; classtype:trojan-activity;sid:84764663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901557/; classtype:trojan-activity;sid:84764657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901558/; classtype:trojan-activity;sid:84764658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64nosl"; depth:16; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901548/; classtype:trojan-activity;sid:84764648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901549/; classtype:trojan-activity;sid:84764649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901550/; classtype:trojan-activity;sid:84764650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901551/; classtype:trojan-activity;sid:84764651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901552/; classtype:trojan-activity;sid:84764652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arc"; depth:9; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901553/; classtype:trojan-activity;sid:84764653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/main.exe"; depth:14; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901554/; classtype:trojan-activity;sid:84764654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/debug_main.exe"; depth:20; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901555/; classtype:trojan-activity;sid:84764655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.spc"; depth:21; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901556/; classtype:trojan-activity;sid:84764656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.i686"; depth:22; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901547/; classtype:trojan-activity;sid:84764647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-r.m-5.sakura"; depth:15; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901545/; classtype:trojan-activity;sid:84764645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.mips64"; depth:24; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901546/; classtype:trojan-activity;sid:84764646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mpsl"; depth:7; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901544/; classtype:trojan-activity;sid:84764644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s-h.4-.sakura"; depth:14; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901543/; classtype:trojan-activity;sid:84764643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.arm6"; depth:22; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901542/; classtype:trojan-activity;sid:84764642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.mips"; depth:22; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901540/; classtype:trojan-activity;sid:84764640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86_64"; depth:25; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901541/; classtype:trojan-activity;sid:84764641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_ppc"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901539/; classtype:trojan-activity;sid:84764639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.mpsl"; depth:22; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901538/; classtype:trojan-activity;sid:84764638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.arc"; depth:21; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901537/; classtype:trojan-activity;sid:84764637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mips"; depth:10; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901531/; classtype:trojan-activity;sid:84764631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.arm5"; depth:22; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901532/; classtype:trojan-activity;sid:84764632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.sh4"; depth:21; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901533/; classtype:trojan-activity;sid:84764633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.arm"; depth:21; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901534/; classtype:trojan-activity;sid:84764634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-5.8-6.sakura"; depth:15; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901535/; classtype:trojan-activity;sid:84764635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m-p.s-l.sakura"; depth:15; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901536/; classtype:trojan-activity;sid:84764636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm5"; depth:11; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901520/; classtype:trojan-activity;sid:84764620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/ppc"; depth:10; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901521/; classtype:trojan-activity;sid:84764621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m-6.8-k.sakura"; depth:15; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901522/; classtype:trojan-activity;sid:84764622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p-p.c-.sakura"; depth:14; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901523/; classtype:trojan-activity;sid:84764623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mips"; depth:11; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901524/; classtype:trojan-activity;sid:84764624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.arm7"; depth:22; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901525/; classtype:trojan-activity;sid:84764625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.x86"; depth:21; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901526/; classtype:trojan-activity;sid:84764626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.m68k"; depth:22; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901527/; classtype:trojan-activity;sid:84764627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mpsl"; depth:11; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901528/; classtype:trojan-activity;sid:84764628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-r.m-4.sakura"; depth:15; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901529/; classtype:trojan-activity;sid:84764629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m-i.p-s.sakura"; depth:15; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901530/; classtype:trojan-activity;sid:84764630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm7"; depth:10; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901516/; classtype:trojan-activity;sid:84764616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/m68k"; depth:11; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901517/; classtype:trojan-activity;sid:84764617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86"; depth:10; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901518/; classtype:trojan-activity;sid:84764618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm"; depth:10; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901519/; classtype:trojan-activity;sid:84764619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i468"; depth:23; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901512/; classtype:trojan-activity;sid:84764612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/spc"; depth:10; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901513/; classtype:trojan-activity;sid:84764613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i686"; depth:23; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901514/; classtype:trojan-activity;sid:84764614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64"; depth:13; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901515/; classtype:trojan-activity;sid:84764615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-r.m-6.sakura"; depth:15; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901511/; classtype:trojan-activity;sid:84764611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.sparc"; depth:23; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901510/; classtype:trojan-activity;sid:84764610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_sh4"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901506/; classtype:trojan-activity;sid:84764606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm6"; depth:10; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901507/; classtype:trojan-activity;sid:84764607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_m68k"; depth:10; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901508/; classtype:trojan-activity;sid:84764608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arc"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901509/; classtype:trojan-activity;sid:84764609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mpsl"; depth:10; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901504/; classtype:trojan-activity;sid:84764604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm5"; depth:10; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901505/; classtype:trojan-activity;sid:84764605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.x86_64"; depth:24; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901503/; classtype:trojan-activity;sid:84764603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm7"; depth:11; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901500/; classtype:trojan-activity;sid:84764600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm6"; depth:11; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901501/; classtype:trojan-activity;sid:84764601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arc"; depth:10; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901502/; classtype:trojan-activity;sid:84764602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_spc"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901498/; classtype:trojan-activity;sid:84764598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_i686"; depth:10; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901499/; classtype:trojan-activity;sid:84764599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/mystic.ppc"; depth:21; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901497/; classtype:trojan-activity;sid:84764597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/sh4"; depth:10; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901495/; classtype:trojan-activity;sid:84764595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mips"; depth:7; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901496/; classtype:trojan-activity;sid:84764596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x86"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901493/; classtype:trojan-activity;sid:84764593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901494/; classtype:trojan-activity;sid:84764594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sqpiq"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901490/; classtype:trojan-activity;sid:84764590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t"; depth:2; endswith; nocase; http.host; content:"93.114.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901489/; classtype:trojan-activity;sid:84764589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.sh"; depth:5; endswith; nocase; http.host; content:"181.214.136.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901488/; classtype:trojan-activity;sid:84764588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0x83911d24fx.sh"; depth:16; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901478/; classtype:trojan-activity;sid:84764578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"176.65.139.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901479/; classtype:trojan-activity;sid:84764579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d"; depth:2; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901480/; classtype:trojan-activity;sid:84764580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaws"; depth:5; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901481/; classtype:trojan-activity;sid:84764581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901483/; classtype:trojan-activity;sid:84764583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901487/; classtype:trojan-activity;sid:84764587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sakura.sh"; depth:10; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901477/; classtype:trojan-activity;sid:84764577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-r.m-7.sakura"; depth:15; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901472/; classtype:trojan-activity;sid:84764572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901473/; classtype:trojan-activity;sid:84764573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901455/; classtype:trojan-activity;sid:84764555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901456/; classtype:trojan-activity;sid:84764556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901457/; classtype:trojan-activity;sid:84764557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901458/; classtype:trojan-activity;sid:84764558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/debug.dbg"; depth:15; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901459/; classtype:trojan-activity;sid:84764559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901460/; classtype:trojan-activity;sid:84764560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901461/; classtype:trojan-activity;sid:84764561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_32"; depth:7; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901462/; classtype:trojan-activity;sid:84764562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901463/; classtype:trojan-activity;sid:84764563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901464/; classtype:trojan-activity;sid:84764564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901465/; classtype:trojan-activity;sid:84764565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"64.118.132.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901466/; classtype:trojan-activity;sid:84764566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.x86"; depth:8; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901467/; classtype:trojan-activity;sid:84764567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x-8.6-.sakura"; depth:14; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901468/; classtype:trojan-activity;sid:84764568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm7"; depth:9; endswith; nocase; http.host; content:"62.84.172.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901469/; classtype:trojan-activity;sid:84764569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x-3.2-.sakura"; depth:14; endswith; nocase; http.host; content:"23.251.34.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901470/; classtype:trojan-activity;sid:84764570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86"; depth:8; endswith; nocase; http.host; content:"36.255.97.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901471/; classtype:trojan-activity;sid:84764571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kxyzn"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901454/; classtype:trojan-activity;sid:84764554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update.exe"; depth:11; endswith; nocase; http.host; content:"ubua.duckdns.org"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901453/; classtype:trojan-activity;sid:84764553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cavqvkkzwjwiglmjzfsinzx194.bin"; depth:31; endswith; nocase; http.host; content:"www.huttprimax.partners"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901452/; classtype:trojan-activity;sid:84764552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/1.jpg"; depth:10; endswith; nocase; http.host; content:"107.173.143.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901451/; classtype:trojan-activity;sid:84764551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.204.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901450/; classtype:trojan-activity;sid:84764550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.204.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901449/; classtype:trojan-activity;sid:84764549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kizzy/1.jpg"; depth:12; endswith; nocase; http.host; content:"signageinsignia.co.za"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901448/; classtype:trojan-activity;sid:84764548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oytyusbd/image/upload/v1786407066/img_201045.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901447/; classtype:trojan-activity;sid:84764547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/admin/msi_pro.png"; depth:18; endswith; nocase; http.host; content:"verdiva.life"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901446/; classtype:trojan-activity;sid:84764546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_050827.png"; depth:19; endswith; nocase; http.host; content:"107.172.172.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901445/; classtype:trojan-activity;sid:84764545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22/goodthingswithbestwayforbetterplacescomingforme.hta"; depth:55; endswith; nocase; http.host; content:"107.172.172.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901444/; classtype:trojan-activity;sid:84764544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/akocrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901443/; classtype:trojan-activity;sid:84764543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jyvna"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901442/; classtype:trojan-activity;sid:84764542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rdfg.png"; depth:9; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901441/; classtype:trojan-activity;sid:84764541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_164159.png"; depth:15; endswith; nocase; http.host; content:"pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901439/; classtype:trojan-activity;sid:84764539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pin.png"; depth:8; endswith; nocase; http.host; content:"pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901440/; classtype:trojan-activity;sid:84764540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lhwek"; depth:6; endswith; nocase; http.host; content:"long-wildflower-b4f5.gustavosoftware.workers.dev"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901438/; classtype:trojan-activity;sid:84764538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/text/fxuqicg/qvbudog/bstwneo/vv/cryptted.ps1"; depth:57; endswith; nocase; http.host; content:"suavasua.vn"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901437/; classtype:trojan-activity;sid:84764537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/office365com.dat"; depth:21; endswith; nocase; http.host; content:"wp.ameyiando.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901436/; classtype:trojan-activity;sid:84764536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mnuuovukjaufyr227.bin"; depth:22; endswith; nocase; http.host; content:"185.29.9.101"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901434/; classtype:trojan-activity;sid:84764534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vsmlokx110.bin"; depth:15; endswith; nocase; http.host; content:"185.29.9.101"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901435/; classtype:trojan-activity;sid:84764535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/standardpakke.toc"; depth:18; endswith; nocase; http.host; content:"185.29.9.101"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901433/; classtype:trojan-activity;sid:84764533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/poubkgvzyebct11.bin"; depth:20; endswith; nocase; http.host; content:"185.29.9.101"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901431/; classtype:trojan-activity;sid:84764531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nhxfirwksyh79.bin"; depth:18; endswith; nocase; http.host; content:"185.29.9.101"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901432/; classtype:trojan-activity;sid:84764532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.102.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901430/; classtype:trojan-activity;sid:84764530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvgxugsv49.bin"; depth:15; endswith; nocase; http.host; content:"185.29.9.108"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901429/; classtype:trojan-activity;sid:84764529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hcesvrijhtjscygevvvh35.bin"; depth:27; endswith; nocase; http.host; content:"185.29.9.108"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901427/; classtype:trojan-activity;sid:84764527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mistakeful.pfb"; depth:15; endswith; nocase; http.host; content:"185.29.9.108"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901428/; classtype:trojan-activity;sid:84764528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yurumpmonday.png"; depth:17; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901426/; classtype:trojan-activity;sid:84764526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.25.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901425/; classtype:trojan-activity;sid:84764525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.25.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901424/; classtype:trojan-activity;sid:84764524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oytyusbd/image/upload/v1786408317/img_203143.jpg"; depth:49; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901423/; classtype:trojan-activity;sid:84764523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44/ecw/wennedsometingbetterfeaturesfrom.js"; depth:43; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901421/; classtype:trojan-activity;sid:84764521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44/ecw/wennedsometingbetterfeaturesfrom.js"; depth:43; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901422/; classtype:trojan-activity;sid:84764522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_220049.png"; depth:19; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901418/; classtype:trojan-activity;sid:84764518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_185156.png"; depth:19; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901419/; classtype:trojan-activity;sid:84764519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/img_193544.png"; depth:18; endswith; nocase; http.host; content:"216.9.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901420/; classtype:trojan-activity;sid:84764520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_005200.png"; depth:19; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901416/; classtype:trojan-activity;sid:84764516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202608/09/xqah941ojbxnprqka4zi/image.png"; depth:41; endswith; nocase; http.host; content:"plain-wnam-prod-public.komododecks.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901417/; classtype:trojan-activity;sid:84764517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202608/11/pfsgtk8ijlkodtyvcp9u/image.png"; depth:41; endswith; nocase; http.host; content:"plain-wnam-prod-public.komododecks.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901415/; classtype:trojan-activity;sid:84764515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/1.jpg"; depth:10; endswith; nocase; http.host; content:"192.255.195.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901410/; classtype:trojan-activity;sid:84764510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/33/img_190847.png"; depth:18; endswith; nocase; http.host; content:"216.9.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901411/; classtype:trojan-activity;sid:84764511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/125/img_000358.png"; depth:19; endswith; nocase; http.host; content:"107.172.172.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901412/; classtype:trojan-activity;sid:84764512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/2.jpg"; depth:10; endswith; nocase; http.host; content:"107.173.9.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901413/; classtype:trojan-activity;sid:84764513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/1.jpg"; depth:10; endswith; nocase; http.host; content:"192.255.195.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901414/; classtype:trojan-activity;sid:84764514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/46/img_210045.png"; depth:18; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901409/; classtype:trojan-activity;sid:84764509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c76cc8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901397/; classtype:trojan-activity;sid:84764497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1a6fb8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901398/; classtype:trojan-activity;sid:84764498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b848da"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901399/; classtype:trojan-activity;sid:84764499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3b1f5e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901400/; classtype:trojan-activity;sid:84764500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e77c7d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901401/; classtype:trojan-activity;sid:84764501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/539df1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901402/; classtype:trojan-activity;sid:84764502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/422255"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901403/; classtype:trojan-activity;sid:84764503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/285a62"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901404/; classtype:trojan-activity;sid:84764504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c15cf0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901405/; classtype:trojan-activity;sid:84764505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6e9b28"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901406/; classtype:trojan-activity;sid:84764506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a3cf9f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901407/; classtype:trojan-activity;sid:84764507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e87b93"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901408/; classtype:trojan-activity;sid:84764508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/img_193544.png"; depth:18; endswith; nocase; http.host; content:"216.9.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901396/; classtype:trojan-activity;sid:84764496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_005200.png"; depth:19; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901393/; classtype:trojan-activity;sid:84764493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_185156.png"; depth:19; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901394/; classtype:trojan-activity;sid:84764494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202608/11/pfsgtk8ijlkodtyvcp9u/image.png"; depth:41; endswith; nocase; http.host; content:"plain-wnam-prod-public.komododecks.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901395/; classtype:trojan-activity;sid:84764495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_220049.png"; depth:19; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901392/; classtype:trojan-activity;sid:84764492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.102.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901391/; classtype:trojan-activity;sid:84764491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/245/wemadebestthingsforthebestpeoplescomingfromthelife.hta"; depth:59; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901390/; classtype:trojan-activity;sid:84764490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23/uks.exe"; depth:11; endswith; nocase; http.host; content:"107.172.238.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901382/; classtype:trojan-activity;sid:84764482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8/ssn.exe"; depth:10; endswith; nocase; http.host; content:"107.172.238.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901383/; classtype:trojan-activity;sid:84764483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/42/dmw.exe"; depth:11; endswith; nocase; http.host; content:"107.172.238.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901384/; classtype:trojan-activity;sid:84764484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23/uks.exe"; depth:11; endswith; nocase; http.host; content:"107.172.238.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901385/; classtype:trojan-activity;sid:84764485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/42/dmw.exe"; depth:11; endswith; nocase; http.host; content:"107.172.238.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901386/; classtype:trojan-activity;sid:84764486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8/ssn.exe"; depth:10; endswith; nocase; http.host; content:"107.172.238.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901387/; classtype:trojan-activity;sid:84764487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/46/weneedbesththingswithbetterplacecomingforme.hta"; depth:51; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901388/; classtype:trojan-activity;sid:84764488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/223/nicepeopelscarecomngfrobestthingstobebestform.hta"; depth:54; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901389/; classtype:trojan-activity;sid:84764489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/42/image_picture_003202490905495093459034.jpg/bestthingswithbestthingswithbetterthings.hta"; depth:91; endswith; nocase; http.host; content:"107.172.238.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901379/; classtype:trojan-activity;sid:84764479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/245/wemadebestthingsforthebestpeoplescomingfromthelife.hta"; depth:59; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901380/; classtype:trojan-activity;sid:84764480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/222/goodthingswithbestmagicalthingscomingforme.hta"; depth:51; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901381/; classtype:trojan-activity;sid:84764481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/211/goodthingsforbestfeelingsarecomingformybest.hta"; depth:52; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901375/; classtype:trojan-activity;sid:84764475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23/ecv/sccsq.hta"; depth:17; endswith; nocase; http.host; content:"107.172.238.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901376/; classtype:trojan-activity;sid:84764476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8/ccr/melvetrakingsbestformebestthignscomingfrom.hta"; depth:53; endswith; nocase; http.host; content:"107.172.238.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901377/; classtype:trojan-activity;sid:84764477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44/goodthingswithbestnationalwithbestfeelings.hta"; depth:50; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901378/; classtype:trojan-activity;sid:84764478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/verygoodthingsforbestpersonenterigninside.hta"; depth:49; endswith; nocase; http.host; content:"216.9.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901372/; classtype:trojan-activity;sid:84764472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/33/weneedbestmagicalapproachforbesthings.hta"; depth:45; endswith; nocase; http.host; content:"216.9.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901373/; classtype:trojan-activity;sid:84764473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/125/givingbesththignsfrobetterplaces.hta"; depth:41; endswith; nocase; http.host; content:"107.172.172.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901374/; classtype:trojan-activity;sid:84764474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44/goodthingswithbestnationalwithbestfeelings.hta"; depth:50; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901370/; classtype:trojan-activity;sid:84764470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8/ccr/melvetrakingsbestformebestthignscomingfrom.hta"; depth:53; endswith; nocase; http.host; content:"107.172.238.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901371/; classtype:trojan-activity;sid:84764471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/222/goodthingswithbestmagicalthingscomingforme.hta"; depth:51; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901368/; classtype:trojan-activity;sid:84764468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/223/nicepeopelscarecomngfrobestthingstobebestform.hta"; depth:54; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901369/; classtype:trojan-activity;sid:84764469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23/ecv/sccsq.hta"; depth:17; endswith; nocase; http.host; content:"107.172.238.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901366/; classtype:trojan-activity;sid:84764466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/42/image_picture_003202490905495093459034.jpg/bestthingswithbestthingswithbetterthings.hta"; depth:91; endswith; nocase; http.host; content:"107.172.238.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901367/; classtype:trojan-activity;sid:84764467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/211/goodthingsforbestfeelingsarecomingformybest.hta"; depth:52; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901365/; classtype:trojan-activity;sid:84764465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/verygoodthingsforbestpersonenterigninside.hta"; depth:49; endswith; nocase; http.host; content:"216.9.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901364/; classtype:trojan-activity;sid:84764464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"140.237.37.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901363/; classtype:trojan-activity;sid:84764463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sergioo92/cesadasd/refs/heads/main/cjifmdi.txt"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901360/; classtype:trojan-activity;sid:84764460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/211/iieomib.txt"; depth:16; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901361/; classtype:trojan-activity;sid:84764461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/211/iieomib.txt"; depth:16; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901362/; classtype:trojan-activity;sid:84764462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kizzy/1.jpg"; depth:12; endswith; nocase; http.host; content:"signageinsignia.co.za"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901359/; classtype:trojan-activity;sid:84764459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sergioo92/fdghhhf/refs/heads/main/obhpmri.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901358/; classtype:trojan-activity;sid:84764458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/goodthingswithbestnaturealthingsforme.hta"; depth:45; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901351/; classtype:trojan-activity;sid:84764451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/goodthingswithbestnaturealthingsforme.hta"; depth:45; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901350/; classtype:trojan-activity;sid:84764450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naew8m"; depth:7; endswith; nocase; http.host; content:"sh.classera.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901349/; classtype:trojan-activity;sid:84764449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"140.237.37.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901348/; classtype:trojan-activity;sid:84764448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/46/weneedbesththingswithbetterplacecomingforme.hta"; depth:51; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901347/; classtype:trojan-activity;sid:84764447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/46/img_210045.png"; depth:18; endswith; nocase; http.host; content:"155.103.69.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901346/; classtype:trojan-activity;sid:84764446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/125/img_000358.png"; depth:19; endswith; nocase; http.host; content:"107.172.172.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901345/; classtype:trojan-activity;sid:84764445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/125/givingbesththignsfrobetterplaces.hta"; depth:41; endswith; nocase; http.host; content:"107.172.172.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901344/; classtype:trojan-activity;sid:84764444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22/img_172149.png"; depth:18; endswith; nocase; http.host; content:"107.173.47.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901343/; classtype:trojan-activity;sid:84764443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22/goodthingsforbestfutureforme.hta"; depth:36; endswith; nocase; http.host; content:"107.173.47.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901342/; classtype:trojan-activity;sid:84764442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install.sh"; depth:11; endswith; nocase; http.host; content:"del.sou.pp.ua"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901340/; classtype:trojan-activity;sid:84764440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install_tm.sh"; depth:14; endswith; nocase; http.host; content:"del.sou.pp.ua"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901341/; classtype:trojan-activity;sid:84764441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"94.156.166.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901339/; classtype:trojan-activity;sid:84764439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.255.40.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901338/; classtype:trojan-activity;sid:84764438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.108.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901337/; classtype:trojan-activity;sid:84764437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00/newmsi_pro.png"; depth:18; endswith; nocase; http.host; content:"duct-master.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901336/; classtype:trojan-activity;sid:84764436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/ojscrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901335/; classtype:trojan-activity;sid:84764435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_220749.png"; depth:19; endswith; nocase; http.host; content:"147.182.181.241"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901334/; classtype:trojan-activity;sid:84764434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/26/weneedsomethingseriouslyforhittargets.hta"; depth:45; endswith; nocase; http.host; content:"147.182.181.241"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901333/; classtype:trojan-activity;sid:84764433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amka/random.exe"; depth:16; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901331/; classtype:trojan-activity;sid:84764431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/gold/random.exe"; depth:22; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901332/; classtype:trojan-activity;sid:84764432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ale123.exe"; depth:11; endswith; nocase; http.host; content:"pub-90177fa65de34e95abc6e25ef90c545b.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901330/; classtype:trojan-activity;sid:84764430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.203.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901329/; classtype:trojan-activity;sid:84764429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.192.88.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901328/; classtype:trojan-activity;sid:84764428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/microsoftverify.msi"; depth:20; endswith; nocase; http.host; content:"ownnewstoday.live"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901327/; classtype:trojan-activity;sid:84764427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gwb.dat"; depth:8; endswith; nocase; http.host; content:"bapak178.org"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901326/; classtype:trojan-activity;sid:84764426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/get_verify|3f|i=27407"; depth:22; endswith; nocase; http.host; content:"admetricslab.org"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901325/; classtype:trojan-activity;sid:84764425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efd.dat"; depth:8; endswith; nocase; http.host; content:"bapak178.org"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901324/; classtype:trojan-activity;sid:84764424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pinmsi.png"; depth:11; endswith; nocase; http.host; content:"64.224.17.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901323/; classtype:trojan-activity;sid:84764423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pin_img.png"; depth:12; endswith; nocase; http.host; content:"64.224.17.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901322/; classtype:trojan-activity;sid:84764422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm"; depth:22; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901321/; classtype:trojan-activity;sid:84764421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mips"; depth:23; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901310/; classtype:trojan-activity;sid:84764410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.m68k"; depth:23; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901311/; classtype:trojan-activity;sid:84764411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86"; depth:22; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901312/; classtype:trojan-activity;sid:84764412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i468"; depth:23; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901313/; classtype:trojan-activity;sid:84764413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i686"; depth:23; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901314/; classtype:trojan-activity;sid:84764414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm7"; depth:23; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901315/; classtype:trojan-activity;sid:84764415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.ppc"; depth:22; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901316/; classtype:trojan-activity;sid:84764416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.spc"; depth:22; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901317/; classtype:trojan-activity;sid:84764417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86_64"; depth:25; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901318/; classtype:trojan-activity;sid:84764418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm5"; depth:23; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901319/; classtype:trojan-activity;sid:84764419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mpsl"; depth:23; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901320/; classtype:trojan-activity;sid:84764420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.sh4"; depth:22; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901309/; classtype:trojan-activity;sid:84764409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901308/; classtype:trojan-activity;sid:84764408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901307/; classtype:trojan-activity;sid:84764407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901306/; classtype:trojan-activity;sid:84764406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fytv"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901301/; classtype:trojan-activity;sid:84764401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1spm"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901302/; classtype:trojan-activity;sid:84764402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4yn"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901303/; classtype:trojan-activity;sid:84764403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1gk"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901304/; classtype:trojan-activity;sid:84764404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzcx"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901305/; classtype:trojan-activity;sid:84764405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/05f7c6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901299/; classtype:trojan-activity;sid:84764399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9aaf74"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901300/; classtype:trojan-activity;sid:84764400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/63ab9c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901292/; classtype:trojan-activity;sid:84764392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f2um"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901293/; classtype:trojan-activity;sid:84764393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/968def"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901294/; classtype:trojan-activity;sid:84764394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ozdb"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901295/; classtype:trojan-activity;sid:84764395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/30e00c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901296/; classtype:trojan-activity;sid:84764396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oaf"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901297/; classtype:trojan-activity;sid:84764397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cf3066"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901298/; classtype:trojan-activity;sid:84764398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2020be"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901284/; classtype:trojan-activity;sid:84764384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b73206"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901285/; classtype:trojan-activity;sid:84764385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vkz"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901286/; classtype:trojan-activity;sid:84764386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e748fa"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901287/; classtype:trojan-activity;sid:84764387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zzz"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901288/; classtype:trojan-activity;sid:84764388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/81ee8a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901289/; classtype:trojan-activity;sid:84764389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bf39af"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901290/; classtype:trojan-activity;sid:84764390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ac8c9f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901291/; classtype:trojan-activity;sid:84764391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.203.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901283/; classtype:trojan-activity;sid:84764383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.192.88.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901282/; classtype:trojan-activity;sid:84764382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.loong64"; depth:12; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901281/; classtype:trojan-activity;sid:84764381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.sh"; depth:11; endswith; nocase; http.host; content:"149.50.154.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901280/; classtype:trojan-activity;sid:84764380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901278/; classtype:trojan-activity;sid:84764378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901279/; classtype:trojan-activity;sid:84764379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2/"; depth:3; endswith; nocase; http.host; content:"yogasitesdev.wpengine.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901277/; classtype:trojan-activity;sid:84764377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901276/; classtype:trojan-activity;sid:84764376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.235.243.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901275/; classtype:trojan-activity;sid:84764375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901273/; classtype:trojan-activity;sid:84764373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901274/; classtype:trojan-activity;sid:84764374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mipsel"; depth:12; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901272/; classtype:trojan-activity;sid:84764372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x32"; depth:9; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901271/; classtype:trojan-activity;sid:84764371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901269/; classtype:trojan-activity;sid:84764369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm6"; depth:23; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901270/; classtype:trojan-activity;sid:84764370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arc"; depth:22; endswith; nocase; http.host; content:"209.141.44.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901268/; classtype:trojan-activity;sid:84764368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901267/; classtype:trojan-activity;sid:84764367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901265/; classtype:trojan-activity;sid:84764365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.sh"; depth:10; endswith; nocase; http.host; content:"176.65.139.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901266/; classtype:trojan-activity;sid:84764366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_f63b7e69efeb725b.cmd"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901261/; classtype:trojan-activity;sid:84764361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a5c4d0900e07c7c4.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901262/; classtype:trojan-activity;sid:84764362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_563d9411d8da8c10.cmd"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901263/; classtype:trojan-activity;sid:84764363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_908baa13e195f0df.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901264/; classtype:trojan-activity;sid:84764364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.178.145"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901260/; classtype:trojan-activity;sid:84764360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.131.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901259/; classtype:trojan-activity;sid:84764359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.19.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901258/; classtype:trojan-activity;sid:84764358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.173.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901257/; classtype:trojan-activity;sid:84764357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"server.servermsn.life"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901256/; classtype:trojan-activity;sid:84764356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i/pdf-ticket/download.php"; depth:26; endswith; nocase; http.host; content:"myissuereport.live"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901255/; classtype:trojan-activity;sid:84764355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"140.237.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901254/; classtype:trojan-activity;sid:84764354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.86.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901253/; classtype:trojan-activity;sid:84764353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.19.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901252/; classtype:trojan-activity;sid:84764352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.195.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901251/; classtype:trojan-activity;sid:84764351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.54.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901250/; classtype:trojan-activity;sid:84764350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.217.13"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901249/; classtype:trojan-activity;sid:84764349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.223.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901248/; classtype:trojan-activity;sid:84764348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.108.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901247/; classtype:trojan-activity;sid:84764347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.37.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901246/; classtype:trojan-activity;sid:84764346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.54.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901245/; classtype:trojan-activity;sid:84764345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.217.13"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901244/; classtype:trojan-activity;sid:84764344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.195.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901243/; classtype:trojan-activity;sid:84764343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.229.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901242/; classtype:trojan-activity;sid:84764342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_57593b4d53209e53.cmd"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901241/; classtype:trojan-activity;sid:84764341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.223.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901240/; classtype:trojan-activity;sid:84764340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"160.176.25.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901239/; classtype:trojan-activity;sid:84764339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.234.156.10"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901238/; classtype:trojan-activity;sid:84764338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.98.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901237/; classtype:trojan-activity;sid:84764337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"71.207.128.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901236/; classtype:trojan-activity;sid:84764336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"211.158.166.117"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901235/; classtype:trojan-activity;sid:84764335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.25.149.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901234/; classtype:trojan-activity;sid:84764334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.94.69"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901233/; classtype:trojan-activity;sid:84764333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901232/; classtype:trojan-activity;sid:84764332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.147.159.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901231/; classtype:trojan-activity;sid:84764331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.180.15.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901230/; classtype:trojan-activity;sid:84764330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.202.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901229/; classtype:trojan-activity;sid:84764329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"38.43.193.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901228/; classtype:trojan-activity;sid:84764328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901227/; classtype:trojan-activity;sid:84764327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.172.13.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901226/; classtype:trojan-activity;sid:84764326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"38.43.193.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901225/; classtype:trojan-activity;sid:84764325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.94.69"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901224/; classtype:trojan-activity;sid:84764324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.92.80.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901223/; classtype:trojan-activity;sid:84764323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901222/; classtype:trojan-activity;sid:84764322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.173.101.27"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901221/; classtype:trojan-activity;sid:84764321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.173.101.27"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901220/; classtype:trojan-activity;sid:84764320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.64.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901219/; classtype:trojan-activity;sid:84764319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.64.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901218/; classtype:trojan-activity;sid:84764318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.138.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901217/; classtype:trojan-activity;sid:84764317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.x86_64"; depth:14; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901210/; classtype:trojan-activity;sid:84764310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.mpsl"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901211/; classtype:trojan-activity;sid:84764311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.53.51.109"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901212/; classtype:trojan-activity;sid:84764312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.mips"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901213/; classtype:trojan-activity;sid:84764313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.arm64"; depth:13; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901214/; classtype:trojan-activity;sid:84764314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.x86"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901215/; classtype:trojan-activity;sid:84764315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mini.arm7"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901216/; classtype:trojan-activity;sid:84764316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.94.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901208/; classtype:trojan-activity;sid:84764308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.94.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901209/; classtype:trojan-activity;sid:84764309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"66.8.135.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901207/; classtype:trojan-activity;sid:84764307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.138.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901206/; classtype:trojan-activity;sid:84764306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.90.13"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901205/; classtype:trojan-activity;sid:84764305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"66.8.135.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901204/; classtype:trojan-activity;sid:84764304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.103.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901203/; classtype:trojan-activity;sid:84764303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.177.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901202/; classtype:trojan-activity;sid:84764302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.193.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901201/; classtype:trojan-activity;sid:84764301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"112.198.193.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901198/; classtype:trojan-activity;sid:84764298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.193.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901199/; classtype:trojan-activity;sid:84764299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"112.198.193.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901200/; classtype:trojan-activity;sid:84764300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg11"; depth:5; endswith; nocase; http.host; content:"waf.proxytunnel.co"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901197/; classtype:trojan-activity;sid:84764297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.205.10.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901196/; classtype:trojan-activity;sid:84764296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.105.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901195/; classtype:trojan-activity;sid:84764295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.77.117.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901194/; classtype:trojan-activity;sid:84764294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.18.11.118"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901193/; classtype:trojan-activity;sid:84764293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.205.10.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901192/; classtype:trojan-activity;sid:84764292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.68.164"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901191/; classtype:trojan-activity;sid:84764291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.235.239.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901190/; classtype:trojan-activity;sid:84764290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.209.29"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901189/; classtype:trojan-activity;sid:84764289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.77.117.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901188/; classtype:trojan-activity;sid:84764288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.31.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901187/; classtype:trojan-activity;sid:84764287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.174.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901186/; classtype:trojan-activity;sid:84764286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.57.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901185/; classtype:trojan-activity;sid:84764285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.48.28.98"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901184/; classtype:trojan-activity;sid:84764284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.235.239.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901183/; classtype:trojan-activity;sid:84764283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.166.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901182/; classtype:trojan-activity;sid:84764282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.11.118"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901181/; classtype:trojan-activity;sid:84764281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.116.20.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901180/; classtype:trojan-activity;sid:84764280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.116.20.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901179/; classtype:trojan-activity;sid:84764279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.153.126.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901178/; classtype:trojan-activity;sid:84764278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.177.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901177/; classtype:trojan-activity;sid:84764277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.247.84.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901176/; classtype:trojan-activity;sid:84764276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b6eb436102b82c86.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901174/; classtype:trojan-activity;sid:84764274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3481d91a938ab342.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901175/; classtype:trojan-activity;sid:84764275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_fa7d2d7d3c7be176.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901167/; classtype:trojan-activity;sid:84764267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.11.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901168/; classtype:trojan-activity;sid:84764268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4270dd8330a6acbc.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901169/; classtype:trojan-activity;sid:84764269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4d1070b391f2b07d.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901170/; classtype:trojan-activity;sid:84764270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_8a1ac3d8be0488af.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901171/; classtype:trojan-activity;sid:84764271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_065966cf70492303.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901172/; classtype:trojan-activity;sid:84764272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_e1854d916cb8bd04.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901173/; classtype:trojan-activity;sid:84764273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fallen.arm7"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901166/; classtype:trojan-activity;sid:84764266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6501cd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901164/; classtype:trojan-activity;sid:84764264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d72242"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901165/; classtype:trojan-activity;sid:84764265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/84e985"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901144/; classtype:trojan-activity;sid:84764244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/76e8cc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901145/; classtype:trojan-activity;sid:84764245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9cb1d9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901146/; classtype:trojan-activity;sid:84764246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7ba4cb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901147/; classtype:trojan-activity;sid:84764247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8f41cf"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901148/; classtype:trojan-activity;sid:84764248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f41d69"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901149/; classtype:trojan-activity;sid:84764249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9e14a1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901150/; classtype:trojan-activity;sid:84764250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f4403a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901151/; classtype:trojan-activity;sid:84764251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c1e2ea"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901152/; classtype:trojan-activity;sid:84764252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6441d0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901153/; classtype:trojan-activity;sid:84764253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4a200f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901154/; classtype:trojan-activity;sid:84764254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ea4b38"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901155/; classtype:trojan-activity;sid:84764255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d69405"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901156/; classtype:trojan-activity;sid:84764256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dca7ad"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901157/; classtype:trojan-activity;sid:84764257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0654cb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901158/; classtype:trojan-activity;sid:84764258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/05416a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901159/; classtype:trojan-activity;sid:84764259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9ea4b7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901160/; classtype:trojan-activity;sid:84764260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fallen.arm4"; depth:12; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901161/; classtype:trojan-activity;sid:84764261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/17949b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901162/; classtype:trojan-activity;sid:84764262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e40c97"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901163/; classtype:trojan-activity;sid:84764263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/894fc5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901129/; classtype:trojan-activity;sid:84764229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/650040"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901130/; classtype:trojan-activity;sid:84764230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e00f60"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901131/; classtype:trojan-activity;sid:84764231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bd9da7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901132/; classtype:trojan-activity;sid:84764232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/def5c2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901133/; classtype:trojan-activity;sid:84764233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/498482"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901134/; classtype:trojan-activity;sid:84764234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ad704a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901135/; classtype:trojan-activity;sid:84764235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45d538"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901136/; classtype:trojan-activity;sid:84764236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e26c93"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901137/; classtype:trojan-activity;sid:84764237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3e070d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901138/; classtype:trojan-activity;sid:84764238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2150fc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901139/; classtype:trojan-activity;sid:84764239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5490a4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901140/; classtype:trojan-activity;sid:84764240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ff5279"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901141/; classtype:trojan-activity;sid:84764241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4850bd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901142/; classtype:trojan-activity;sid:84764242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7d8668"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901143/; classtype:trojan-activity;sid:84764243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.136.97.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901128/; classtype:trojan-activity;sid:84764228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.51.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901127/; classtype:trojan-activity;sid:84764227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unifi.bak.20260810122841"; depth:25; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901126/; classtype:trojan-activity;sid:84764226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.136.97.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901125/; classtype:trojan-activity;sid:84764225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.147.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901124/; classtype:trojan-activity;sid:84764224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.41.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901123/; classtype:trojan-activity;sid:84764223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.25.149.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901122/; classtype:trojan-activity;sid:84764222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.41.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901121/; classtype:trojan-activity;sid:84764221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.145.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901120/; classtype:trojan-activity;sid:84764220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86_64"; depth:21; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901119/; classtype:trojan-activity;sid:84764219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.106.46"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901118/; classtype:trojan-activity;sid:84764218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901116/; classtype:trojan-activity;sid:84764216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901117/; classtype:trojan-activity;sid:84764217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901114/; classtype:trojan-activity;sid:84764214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.60.241.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901115/; classtype:trojan-activity;sid:84764215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.60.241.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901113/; classtype:trojan-activity;sid:84764213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc"; depth:8; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901111/; classtype:trojan-activity;sid:84764211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.aarch64"; depth:12; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901112/; classtype:trojan-activity;sid:84764212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.26.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901110/; classtype:trojan-activity;sid:84764210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mipsel"; depth:21; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901109/; classtype:trojan-activity;sid:84764209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901094/; classtype:trojan-activity;sid:84764194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.x86_64"; depth:16; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901095/; classtype:trojan-activity;sid:84764195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.sh4"; depth:8; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901096/; classtype:trojan-activity;sid:84764196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901097/; classtype:trojan-activity;sid:84764197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901098/; classtype:trojan-activity;sid:84764198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i686"; depth:9; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901099/; classtype:trojan-activity;sid:84764199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901100/; classtype:trojan-activity;sid:84764200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k.sh"; depth:5; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901101/; classtype:trojan-activity;sid:84764201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901102/; classtype:trojan-activity;sid:84764202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86_64"; depth:21; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901103/; classtype:trojan-activity;sid:84764203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm4"; depth:19; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901104/; classtype:trojan-activity;sid:84764204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mips"; depth:19; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901105/; classtype:trojan-activity;sid:84764205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k.sh"; depth:5; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901106/; classtype:trojan-activity;sid:84764206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901107/; classtype:trojan-activity;sid:84764207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86"; depth:18; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901108/; classtype:trojan-activity;sid:84764208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901085/; classtype:trojan-activity;sid:84764185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.aarch64"; depth:22; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901086/; classtype:trojan-activity;sid:84764186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm4"; depth:19; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901087/; classtype:trojan-activity;sid:84764187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.x86_64"; depth:16; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901088/; classtype:trojan-activity;sid:84764188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901089/; classtype:trojan-activity;sid:84764189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901090/; classtype:trojan-activity;sid:84764190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k.sh"; depth:5; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901091/; classtype:trojan-activity;sid:84764191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mips"; depth:19; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901092/; classtype:trojan-activity;sid:84764192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86"; depth:18; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901093/; classtype:trojan-activity;sid:84764193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mipsel"; depth:21; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901083/; classtype:trojan-activity;sid:84764183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901084/; classtype:trojan-activity;sid:84764184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mipsel"; depth:11; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901082/; classtype:trojan-activity;sid:84764182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901069/; classtype:trojan-activity;sid:84764169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901070/; classtype:trojan-activity;sid:84764170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901071/; classtype:trojan-activity;sid:84764171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mips"; depth:19; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901072/; classtype:trojan-activity;sid:84764172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"136.60.32.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901073/; classtype:trojan-activity;sid:84764173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901074/; classtype:trojan-activity;sid:84764174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901075/; classtype:trojan-activity;sid:84764175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901076/; classtype:trojan-activity;sid:84764176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mipsel"; depth:21; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901077/; classtype:trojan-activity;sid:84764177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.aarch64"; depth:22; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901078/; classtype:trojan-activity;sid:84764178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901079/; classtype:trojan-activity;sid:84764179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901080/; classtype:trojan-activity;sid:84764180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901081/; classtype:trojan-activity;sid:84764181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm7"; depth:19; endswith; nocase; http.host; content:"mail.quietsurfwi.help"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901067/; classtype:trojan-activity;sid:84764167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm7"; depth:19; endswith; nocase; http.host; content:"iloveboats.st"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901068/; classtype:trojan-activity;sid:84764168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"176.65.139.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901066/; classtype:trojan-activity;sid:84764166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.109.219.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901065/; classtype:trojan-activity;sid:84764165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86"; depth:18; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901054/; classtype:trojan-activity;sid:84764154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.aarch64"; depth:22; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901055/; classtype:trojan-activity;sid:84764155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.x86_64"; depth:16; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901056/; classtype:trojan-activity;sid:84764156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901057/; classtype:trojan-activity;sid:84764157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901058/; classtype:trojan-activity;sid:84764158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86_64"; depth:21; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901059/; classtype:trojan-activity;sid:84764159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm4"; depth:19; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901060/; classtype:trojan-activity;sid:84764160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901061/; classtype:trojan-activity;sid:84764161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm7"; depth:19; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901062/; classtype:trojan-activity;sid:84764162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901063/; classtype:trojan-activity;sid:84764163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"quietsurfwi.help"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901064/; classtype:trojan-activity;sid:84764164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.247.84.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901053/; classtype:trojan-activity;sid:84764153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901050/; classtype:trojan-activity;sid:84764150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.x86_64"; depth:16; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901051/; classtype:trojan-activity;sid:84764151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901052/; classtype:trojan-activity;sid:84764152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mipsel"; depth:21; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901049/; classtype:trojan-activity;sid:84764149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901037/; classtype:trojan-activity;sid:84764137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901038/; classtype:trojan-activity;sid:84764138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm7"; depth:19; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901039/; classtype:trojan-activity;sid:84764139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86_64"; depth:21; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901040/; classtype:trojan-activity;sid:84764140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901041/; classtype:trojan-activity;sid:84764141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mips"; depth:19; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901042/; classtype:trojan-activity;sid:84764142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901043/; classtype:trojan-activity;sid:84764143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901044/; classtype:trojan-activity;sid:84764144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.aarch64"; depth:22; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901045/; classtype:trojan-activity;sid:84764145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901046/; classtype:trojan-activity;sid:84764146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86"; depth:18; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901047/; classtype:trojan-activity;sid:84764147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm4"; depth:19; endswith; nocase; http.host; content:"94.154.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901048/; classtype:trojan-activity;sid:84764148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.113.164"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901036/; classtype:trojan-activity;sid:84764136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_d16ae09e5eae4115.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901035/; classtype:trojan-activity;sid:84764135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.26.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901034/; classtype:trojan-activity;sid:84764134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.98.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901033/; classtype:trojan-activity;sid:84764133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.203.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901032/; classtype:trojan-activity;sid:84764132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.229.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901031/; classtype:trojan-activity;sid:84764131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.96.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901030/; classtype:trojan-activity;sid:84764130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.192.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901029/; classtype:trojan-activity;sid:84764129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.64.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901028/; classtype:trojan-activity;sid:84764128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.179.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901027/; classtype:trojan-activity;sid:84764127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.64.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901026/; classtype:trojan-activity;sid:84764126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackin.png"; depth:11; endswith; nocase; http.host; content:"192.109.139.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901024/; classtype:trojan-activity;sid:84764124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xsvvfgrj.png"; depth:13; endswith; nocase; http.host; content:"192.109.139.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901025/; classtype:trojan-activity;sid:84764125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hdgftyu.png"; depth:12; endswith; nocase; http.host; content:"192.109.139.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901023/; classtype:trojan-activity;sid:84764123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.69.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901022/; classtype:trojan-activity;sid:84764122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.167.183.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901021/; classtype:trojan-activity;sid:84764121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/033fd6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901020/; classtype:trojan-activity;sid:84764120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/18c0e1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901009/; classtype:trojan-activity;sid:84764109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e34be1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901010/; classtype:trojan-activity;sid:84764110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/16f2c2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901011/; classtype:trojan-activity;sid:84764111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/923a9e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901012/; classtype:trojan-activity;sid:84764112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a0d95b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901013/; classtype:trojan-activity;sid:84764113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/78acf3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901014/; classtype:trojan-activity;sid:84764114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/56db7c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901015/; classtype:trojan-activity;sid:84764115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/410ae5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901016/; classtype:trojan-activity;sid:84764116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/340ab3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901017/; classtype:trojan-activity;sid:84764117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c60df5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901018/; classtype:trojan-activity;sid:84764118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/177395"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901019/; classtype:trojan-activity;sid:84764119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.179.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901008/; classtype:trojan-activity;sid:84764108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.1.153"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901007/; classtype:trojan-activity;sid:84764107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.5.94.63"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901006/; classtype:trojan-activity;sid:84764106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blink.sh"; depth:9; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901005/; classtype:trojan-activity;sid:84764105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.167.183.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901004/; classtype:trojan-activity;sid:84764104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.97.97"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901003/; classtype:trojan-activity;sid:84764103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.37.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901002/; classtype:trojan-activity;sid:84764102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.203.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901001/; classtype:trojan-activity;sid:84764101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.193.35.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3901000/; classtype:trojan-activity;sid:84764100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.219.74.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900999/; classtype:trojan-activity;sid:84764099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.37.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900998/; classtype:trojan-activity;sid:84764098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23/img_185335.png"; depth:18; endswith; nocase; http.host; content:"107.175.88.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900997/; classtype:trojan-activity;sid:84764097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23/wegivenebestthignswithbetterplaces.hta"; depth:42; endswith; nocase; http.host; content:"107.175.88.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900996/; classtype:trojan-activity;sid:84764096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202608/09/xqah941ojbxnprqka4zi/image.png"; depth:41; endswith; nocase; http.host; content:"plain-wnam-prod-public.komododecks.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900994/; classtype:trojan-activity;sid:84764094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35/img_190431.png"; depth:18; endswith; nocase; http.host; content:"172.245.195.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900995/; classtype:trojan-activity;sid:84764095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35/wegivenebstthingswithbetterplaces.hta"; depth:41; endswith; nocase; http.host; content:"172.245.195.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900993/; classtype:trojan-activity;sid:84764093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/godabeg1.exe"; depth:13; endswith; nocase; http.host; content:"rcf.co.mz"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900992/; classtype:trojan-activity;sid:84764092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agent.ashx"; depth:11; endswith; nocase; http.host; content:"sysupdate.online"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900991/; classtype:trojan-activity;sid:84764091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.234.156.10"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900990/; classtype:trojan-activity;sid:84764090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt.sh"; depth:7; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900989/; classtype:trojan-activity;sid:84764089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvr.sh"; depth:7; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900988/; classtype:trojan-activity;sid:84764088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900987/; classtype:trojan-activity;sid:84764087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.143.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900986/; classtype:trojan-activity;sid:84764086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.60.75.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900985/; classtype:trojan-activity;sid:84764085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.233.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900984/; classtype:trojan-activity;sid:84764084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.45.111"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900982/; classtype:trojan-activity;sid:84764082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.45.111"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900983/; classtype:trojan-activity;sid:84764083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.60.75.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900981/; classtype:trojan-activity;sid:84764081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.4.125"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900980/; classtype:trojan-activity;sid:84764080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.79.249.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900979/; classtype:trojan-activity;sid:84764079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.22.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900978/; classtype:trojan-activity;sid:84764078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.79.249.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900977/; classtype:trojan-activity;sid:84764077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.88.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900976/; classtype:trojan-activity;sid:84764076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.88.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900975/; classtype:trojan-activity;sid:84764075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm"; depth:10; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900968/; classtype:trojan-activity;sid:84764068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64"; depth:13; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900969/; classtype:trojan-activity;sid:84764069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86"; depth:10; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900970/; classtype:trojan-activity;sid:84764070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm5"; depth:11; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900971/; classtype:trojan-activity;sid:84764071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.137.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900972/; classtype:trojan-activity;sid:84764072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.10.7"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900973/; classtype:trojan-activity;sid:84764073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm6"; depth:11; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900974/; classtype:trojan-activity;sid:84764074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900966/; classtype:trojan-activity;sid:84764066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/spc"; depth:10; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900967/; classtype:trojan-activity;sid:84764067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0x83911d24fx.sh"; depth:16; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900965/; classtype:trojan-activity;sid:84764065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.100.78"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900964/; classtype:trojan-activity;sid:84764064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mips"; depth:11; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900957/; classtype:trojan-activity;sid:84764057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/ppc"; depth:10; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900958/; classtype:trojan-activity;sid:84764058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mpsl"; depth:11; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900959/; classtype:trojan-activity;sid:84764059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/sh4"; depth:10; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900960/; classtype:trojan-activity;sid:84764060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/m68k"; depth:11; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900961/; classtype:trojan-activity;sid:84764061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm7"; depth:11; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900962/; classtype:trojan-activity;sid:84764062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arc"; depth:10; endswith; nocase; http.host; content:"privrawmirai.privnetwork.tech"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900963/; classtype:trojan-activity;sid:84764063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.193.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900956/; classtype:trojan-activity;sid:84764056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chromesetupwindows.exe"; depth:23; endswith; nocase; http.host; content:"chrome-windows.ru"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900955/; classtype:trojan-activity;sid:84764055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlink.sh"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900954/; classtype:trojan-activity;sid:84764054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.78.176.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900953/; classtype:trojan-activity;sid:84764053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_e8219df7a9a21088.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900952/; classtype:trojan-activity;sid:84764052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.236.46.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900951/; classtype:trojan-activity;sid:84764051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.231.139.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900950/; classtype:trojan-activity;sid:84764050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.22.18.152"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900949/; classtype:trojan-activity;sid:84764049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.242.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900948/; classtype:trojan-activity;sid:84764048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.236.46.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900947/; classtype:trojan-activity;sid:84764047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.179.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900946/; classtype:trojan-activity;sid:84764046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.22.18.152"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900945/; classtype:trojan-activity;sid:84764045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.192.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900944/; classtype:trojan-activity;sid:84764044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.134.41.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900943/; classtype:trojan-activity;sid:84764043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"194.26.192.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900941/; classtype:trojan-activity;sid:84764041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"194.26.192.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900942/; classtype:trojan-activity;sid:84764042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm5"; depth:11; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900940/; classtype:trojan-activity;sid:84764040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"91.92.243.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900939/; classtype:trojan-activity;sid:84764039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"91.92.243.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900938/; classtype:trojan-activity;sid:84764038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm6"; depth:11; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900937/; classtype:trojan-activity;sid:84764037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/sh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900934/; classtype:trojan-activity;sid:84764034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64"; depth:13; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900935/; classtype:trojan-activity;sid:84764035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm"; depth:10; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900936/; classtype:trojan-activity;sid:84764036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900931/; classtype:trojan-activity;sid:84764031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0x83911d24fx.sh"; depth:16; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900932/; classtype:trojan-activity;sid:84764032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mpsl"; depth:11; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900933/; classtype:trojan-activity;sid:84764033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/spc"; depth:10; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900925/; classtype:trojan-activity;sid:84764025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arc"; depth:10; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900926/; classtype:trojan-activity;sid:84764026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/m68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900927/; classtype:trojan-activity;sid:84764027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/ppc"; depth:10; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900928/; classtype:trojan-activity;sid:84764028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mips"; depth:11; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900929/; classtype:trojan-activity;sid:84764029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm6"; depth:11; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900930/; classtype:trojan-activity;sid:84764030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm7"; depth:11; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900923/; classtype:trojan-activity;sid:84764023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86"; depth:10; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900924/; classtype:trojan-activity;sid:84764024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/m68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900922/; classtype:trojan-activity;sid:84764022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arc"; depth:10; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900909/; classtype:trojan-activity;sid:84764009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/sh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900910/; classtype:trojan-activity;sid:84764010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900911/; classtype:trojan-activity;sid:84764011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm"; depth:10; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900912/; classtype:trojan-activity;sid:84764012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm5"; depth:11; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900913/; classtype:trojan-activity;sid:84764013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0x83911d24fx.sh"; depth:16; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900914/; classtype:trojan-activity;sid:84764014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm7"; depth:11; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900915/; classtype:trojan-activity;sid:84764015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64"; depth:13; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900916/; classtype:trojan-activity;sid:84764016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/ppc"; depth:10; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900917/; classtype:trojan-activity;sid:84764017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mips"; depth:11; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900918/; classtype:trojan-activity;sid:84764018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/spc"; depth:10; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900919/; classtype:trojan-activity;sid:84764019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86"; depth:10; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900920/; classtype:trojan-activity;sid:84764020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mpsl"; depth:11; endswith; nocase; http.host; content:"94.154.43.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900921/; classtype:trojan-activity;sid:84764021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.134.41.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900908/; classtype:trojan-activity;sid:84764008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"130.12.209.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900907/; classtype:trojan-activity;sid:84764007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.224.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900905/; classtype:trojan-activity;sid:84764005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.204.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900906/; classtype:trojan-activity;sid:84764006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.41.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900904/; classtype:trojan-activity;sid:84764004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.204.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900903/; classtype:trojan-activity;sid:84764003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.84.190.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900898/; classtype:trojan-activity;sid:84763998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"119.23.55.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900899/; classtype:trojan-activity;sid:84763999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"96.245.232.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900900/; classtype:trojan-activity;sid:84764000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.174.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900901/; classtype:trojan-activity;sid:84764001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.213.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900902/; classtype:trojan-activity;sid:84764002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.80.57.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900877/; classtype:trojan-activity;sid:84763977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.180.11.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900878/; classtype:trojan-activity;sid:84763978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.157.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900879/; classtype:trojan-activity;sid:84763979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.211.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900880/; classtype:trojan-activity;sid:84763980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.116.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900881/; classtype:trojan-activity;sid:84763981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.148.29.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900882/; classtype:trojan-activity;sid:84763982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.185.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900883/; classtype:trojan-activity;sid:84763983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.181.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900884/; classtype:trojan-activity;sid:84763984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.94.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900885/; classtype:trojan-activity;sid:84763985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.91.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900886/; classtype:trojan-activity;sid:84763986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.149.193"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900887/; classtype:trojan-activity;sid:84763987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.116.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900888/; classtype:trojan-activity;sid:84763988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.58.131.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900889/; classtype:trojan-activity;sid:84763989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.13.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900890/; classtype:trojan-activity;sid:84763990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.23.139.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900891/; classtype:trojan-activity;sid:84763991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.104.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900892/; classtype:trojan-activity;sid:84763992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.226.103"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900893/; classtype:trojan-activity;sid:84763993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.51"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900894/; classtype:trojan-activity;sid:84763994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.184.163.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900895/; classtype:trojan-activity;sid:84763995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.192.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900896/; classtype:trojan-activity;sid:84763996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.64.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900897/; classtype:trojan-activity;sid:84763997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.184.163.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900871/; classtype:trojan-activity;sid:84763971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.135.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900872/; classtype:trojan-activity;sid:84763972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"216.249.4.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900873/; classtype:trojan-activity;sid:84763973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.170.224.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900874/; classtype:trojan-activity;sid:84763974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.86.136.138"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900875/; classtype:trojan-activity;sid:84763975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.115.68.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900876/; classtype:trojan-activity;sid:84763976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.180.15.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900870/; classtype:trojan-activity;sid:84763970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.119.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900869/; classtype:trojan-activity;sid:84763969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.126.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900868/; classtype:trojan-activity;sid:84763968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.196.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900865/; classtype:trojan-activity;sid:84763965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.126.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900866/; classtype:trojan-activity;sid:84763966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.196.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900867/; classtype:trojan-activity;sid:84763967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"193.31.201.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900860/; classtype:trojan-activity;sid:84763960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.55.212.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900861/; classtype:trojan-activity;sid:84763961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.139.13.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900862/; classtype:trojan-activity;sid:84763962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.145.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900863/; classtype:trojan-activity;sid:84763963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.139.13.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900864/; classtype:trojan-activity;sid:84763964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.170.224.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900845/; classtype:trojan-activity;sid:84763945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.156.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900846/; classtype:trojan-activity;sid:84763946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.33.100"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900847/; classtype:trojan-activity;sid:84763947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.137.177.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900848/; classtype:trojan-activity;sid:84763948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.106.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900849/; classtype:trojan-activity;sid:84763949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.41.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900850/; classtype:trojan-activity;sid:84763950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.148.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900851/; classtype:trojan-activity;sid:84763951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900852/; classtype:trojan-activity;sid:84763952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.91.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900853/; classtype:trojan-activity;sid:84763953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.31.205"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900854/; classtype:trojan-activity;sid:84763954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.52.204.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900855/; classtype:trojan-activity;sid:84763955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.200.107.56"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900856/; classtype:trojan-activity;sid:84763956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900857/; classtype:trojan-activity;sid:84763957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.33.201"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900858/; classtype:trojan-activity;sid:84763958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.192.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900859/; classtype:trojan-activity;sid:84763959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.10.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900839/; classtype:trojan-activity;sid:84763939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.137.177.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900840/; classtype:trojan-activity;sid:84763940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.18.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900841/; classtype:trojan-activity;sid:84763941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"106.40.240.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900842/; classtype:trojan-activity;sid:84763942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.80.57.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900843/; classtype:trojan-activity;sid:84763943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.160.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900844/; classtype:trojan-activity;sid:84763944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.211.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900837/; classtype:trojan-activity;sid:84763937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.33.201"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900838/; classtype:trojan-activity;sid:84763938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.190.20.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900836/; classtype:trojan-activity;sid:84763936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"193.31.201.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900833/; classtype:trojan-activity;sid:84763933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.12.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900834/; classtype:trojan-activity;sid:84763934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.72.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900835/; classtype:trojan-activity;sid:84763935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rondo"; depth:6; endswith; nocase; http.host; content:"194.26.192.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900832/; classtype:trojan-activity;sid:84763932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.147.159.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900829/; classtype:trojan-activity;sid:84763929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.13.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900830/; classtype:trojan-activity;sid:84763930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.68.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900831/; classtype:trojan-activity;sid:84763931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900807/; classtype:trojan-activity;sid:84763907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.182.123.61"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900808/; classtype:trojan-activity;sid:84763908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.101.187.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900809/; classtype:trojan-activity;sid:84763909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.23.139.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900810/; classtype:trojan-activity;sid:84763910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.86.136.138"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900811/; classtype:trojan-activity;sid:84763911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.160.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900812/; classtype:trojan-activity;sid:84763912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.33.100"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900813/; classtype:trojan-activity;sid:84763913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.144.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900814/; classtype:trojan-activity;sid:84763914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.78.176.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900815/; classtype:trojan-activity;sid:84763915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.218.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900816/; classtype:trojan-activity;sid:84763916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.130.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900817/; classtype:trojan-activity;sid:84763917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.77.172.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900818/; classtype:trojan-activity;sid:84763918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.116.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900819/; classtype:trojan-activity;sid:84763919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.58.42.82"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900820/; classtype:trojan-activity;sid:84763920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.189.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900821/; classtype:trojan-activity;sid:84763921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.116.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900822/; classtype:trojan-activity;sid:84763922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.58.131.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900823/; classtype:trojan-activity;sid:84763923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.1.153"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900824/; classtype:trojan-activity;sid:84763924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.147.220.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900825/; classtype:trojan-activity;sid:84763925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.190.20.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900826/; classtype:trojan-activity;sid:84763926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"1.20.91.236"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900827/; classtype:trojan-activity;sid:84763927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.147.220.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900828/; classtype:trojan-activity;sid:84763928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"93.157.253.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900795/; classtype:trojan-activity;sid:84763895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.231.229.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900796/; classtype:trojan-activity;sid:84763896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"93.157.253.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900797/; classtype:trojan-activity;sid:84763897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.68.249.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900798/; classtype:trojan-activity;sid:84763898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.43.5"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900799/; classtype:trojan-activity;sid:84763899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.40.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900800/; classtype:trojan-activity;sid:84763900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.182.123.61"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900801/; classtype:trojan-activity;sid:84763901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.43.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900802/; classtype:trojan-activity;sid:84763902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.61.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900803/; classtype:trojan-activity;sid:84763903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.114.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900804/; classtype:trojan-activity;sid:84763904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.104.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900805/; classtype:trojan-activity;sid:84763905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.132.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900806/; classtype:trojan-activity;sid:84763906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900794/; classtype:trojan-activity;sid:84763894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.93.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900793/; classtype:trojan-activity;sid:84763893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.53.25"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900792/; classtype:trojan-activity;sid:84763892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.213.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900791/; classtype:trojan-activity;sid:84763891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tools/grab.cmd"; depth:15; endswith; nocase; http.host; content:"sysupdate.online"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900790/; classtype:trojan-activity;sid:84763890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.26.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900788/; classtype:trojan-activity;sid:84763888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.39.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900787/; classtype:trojan-activity;sid:84763887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.103.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900786/; classtype:trojan-activity;sid:84763886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dc7ecc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900785/; classtype:trojan-activity;sid:84763885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c55677"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900774/; classtype:trojan-activity;sid:84763874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a34888"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900775/; classtype:trojan-activity;sid:84763875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0d5aa8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900776/; classtype:trojan-activity;sid:84763876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ed422a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900777/; classtype:trojan-activity;sid:84763877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12cd43"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900778/; classtype:trojan-activity;sid:84763878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b62738"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900779/; classtype:trojan-activity;sid:84763879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3ee62b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900780/; classtype:trojan-activity;sid:84763880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f48b45"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900781/; classtype:trojan-activity;sid:84763881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e0758e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900782/; classtype:trojan-activity;sid:84763882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1eb5ef"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900783/; classtype:trojan-activity;sid:84763883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/775af1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900784/; classtype:trojan-activity;sid:84763884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.218.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900773/; classtype:trojan-activity;sid:84763873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.39.67"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900772/; classtype:trojan-activity;sid:84763872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/virginalling.asi"; depth:17; endswith; nocase; http.host; content:"185.29.9.108"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900771/; classtype:trojan-activity;sid:84763871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gchldnman179.bin"; depth:17; endswith; nocase; http.host; content:"185.29.9.108"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900770/; classtype:trojan-activity;sid:84763870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.26.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900769/; classtype:trojan-activity;sid:84763869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"106.40.240.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900768/; classtype:trojan-activity;sid:84763868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.150.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900767/; classtype:trojan-activity;sid:84763867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x32"; depth:9; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900766/; classtype:trojan-activity;sid:84763866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900765/; classtype:trojan-activity;sid:84763865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900764/; classtype:trojan-activity;sid:84763864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900757/; classtype:trojan-activity;sid:84763857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900758/; classtype:trojan-activity;sid:84763858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900759/; classtype:trojan-activity;sid:84763859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900760/; classtype:trojan-activity;sid:84763860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900761/; classtype:trojan-activity;sid:84763861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mipsel"; depth:12; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900762/; classtype:trojan-activity;sid:84763862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm4"; depth:10; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900763/; classtype:trojan-activity;sid:84763863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.24.12.180"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900756/; classtype:trojan-activity;sid:84763856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.103.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900755/; classtype:trojan-activity;sid:84763855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.234.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900754/; classtype:trojan-activity;sid:84763854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.205.38.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900753/; classtype:trojan-activity;sid:84763853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900752/; classtype:trojan-activity;sid:84763852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.24.12.180"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900751/; classtype:trojan-activity;sid:84763851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.144.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900750/; classtype:trojan-activity;sid:84763850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900749/; classtype:trojan-activity;sid:84763849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.61.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900748/; classtype:trojan-activity;sid:84763848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"178.205.38.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900747/; classtype:trojan-activity;sid:84763847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.67.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900745/; classtype:trojan-activity;sid:84763845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"157.66.146.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900746/; classtype:trojan-activity;sid:84763846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900742/; classtype:trojan-activity;sid:84763842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.i468"; depth:22; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900743/; classtype:trojan-activity;sid:84763843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.spc"; depth:21; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900744/; classtype:trojan-activity;sid:84763844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.67.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900741/; classtype:trojan-activity;sid:84763841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.armv7l"; depth:22; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900737/; classtype:trojan-activity;sid:84763837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.x86_64"; depth:22; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900738/; classtype:trojan-activity;sid:84763838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.armv5l"; depth:22; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900739/; classtype:trojan-activity;sid:84763839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.powerpc"; depth:23; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900740/; classtype:trojan-activity;sid:84763840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.arc"; depth:19; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900727/; classtype:trojan-activity;sid:84763827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.mipsel"; depth:22; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900728/; classtype:trojan-activity;sid:84763828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.i486"; depth:20; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900729/; classtype:trojan-activity;sid:84763829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.m68k"; depth:20; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900730/; classtype:trojan-activity;sid:84763830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.sparc"; depth:21; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900731/; classtype:trojan-activity;sid:84763831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.armv4l"; depth:22; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900732/; classtype:trojan-activity;sid:84763832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.sh4"; depth:19; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900733/; classtype:trojan-activity;sid:84763833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.mips"; depth:20; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900734/; classtype:trojan-activity;sid:84763834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.armv6l"; depth:22; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900735/; classtype:trojan-activity;sid:84763835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bins/chud.aarch64"; depth:23; endswith; nocase; http.host; content:"167.86.99.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900736/; classtype:trojan-activity;sid:84763836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4c1687"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900706/; classtype:trojan-activity;sid:84763806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9b9d62"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900707/; classtype:trojan-activity;sid:84763807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ff9728"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900708/; classtype:trojan-activity;sid:84763808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/688c63"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900709/; classtype:trojan-activity;sid:84763809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6be5c4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900710/; classtype:trojan-activity;sid:84763810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8fedf4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900711/; classtype:trojan-activity;sid:84763811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0cda73"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900712/; classtype:trojan-activity;sid:84763812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a05a88"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900713/; classtype:trojan-activity;sid:84763813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e89cd9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900714/; classtype:trojan-activity;sid:84763814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yter"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900715/; classtype:trojan-activity;sid:84763815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d687aa"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900716/; classtype:trojan-activity;sid:84763816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4501"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900717/; classtype:trojan-activity;sid:84763817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nf1"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900718/; classtype:trojan-activity;sid:84763818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vho"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900719/; classtype:trojan-activity;sid:84763819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e5da97"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900720/; classtype:trojan-activity;sid:84763820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/07038c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900721/; classtype:trojan-activity;sid:84763821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cdb475"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900722/; classtype:trojan-activity;sid:84763822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d4a3c0"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900723/; classtype:trojan-activity;sid:84763823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/29d455"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900724/; classtype:trojan-activity;sid:84763824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/59a197"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900725/; classtype:trojan-activity;sid:84763825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2af6fb"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900726/; classtype:trojan-activity;sid:84763826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntb"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900693/; classtype:trojan-activity;sid:84763793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seb3"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900694/; classtype:trojan-activity;sid:84763794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3tp"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900695/; classtype:trojan-activity;sid:84763795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aeecec"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900696/; classtype:trojan-activity;sid:84763796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k7m"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900697/; classtype:trojan-activity;sid:84763797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/748a90"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900698/; classtype:trojan-activity;sid:84763798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9wh"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900699/; classtype:trojan-activity;sid:84763799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/q0v"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900700/; classtype:trojan-activity;sid:84763800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50435a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900701/; classtype:trojan-activity;sid:84763801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3020e1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900702/; classtype:trojan-activity;sid:84763802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7866d1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900703/; classtype:trojan-activity;sid:84763803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/485150"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900704/; classtype:trojan-activity;sid:84763804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brci"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900705/; classtype:trojan-activity;sid:84763805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.224.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900692/; classtype:trojan-activity;sid:84763792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nelsoncordeiro24-droid/26e6f76fb48da38d446497b7ac8323d4/raw/fa81f521ba1948a50721a2fa077a0cc68eb55cc8/gistfile1.txt"; depth:115; endswith; nocase; http.host; content:"gist.githubusercontent.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900691/; classtype:trojan-activity;sid:84763791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.35.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900690/; classtype:trojan-activity;sid:84763790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.111.210.192"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900689/; classtype:trojan-activity;sid:84763789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"157.66.146.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900688/; classtype:trojan-activity;sid:84763788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.217.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900687/; classtype:trojan-activity;sid:84763787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/878f49"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900677/; classtype:trojan-activity;sid:84763777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/czg"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900678/; classtype:trojan-activity;sid:84763778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dmx"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900679/; classtype:trojan-activity;sid:84763779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/16268e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900680/; classtype:trojan-activity;sid:84763780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dncf"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900681/; classtype:trojan-activity;sid:84763781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5vza"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900682/; classtype:trojan-activity;sid:84763782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/932a2a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900683/; classtype:trojan-activity;sid:84763783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e6c81e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900684/; classtype:trojan-activity;sid:84763784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9fdeb7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900685/; classtype:trojan-activity;sid:84763785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot"; depth:4; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900686/; classtype:trojan-activity;sid:84763786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35079b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900647/; classtype:trojan-activity;sid:84763747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0c4b84"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900648/; classtype:trojan-activity;sid:84763748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e47c56"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900649/; classtype:trojan-activity;sid:84763749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/191276"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900650/; classtype:trojan-activity;sid:84763750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2adcae"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900651/; classtype:trojan-activity;sid:84763751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0e216c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900652/; classtype:trojan-activity;sid:84763752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gek"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900653/; classtype:trojan-activity;sid:84763753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vfgi"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900654/; classtype:trojan-activity;sid:84763754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jddj"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900655/; classtype:trojan-activity;sid:84763755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/de3259"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900656/; classtype:trojan-activity;sid:84763756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c70dba"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900657/; classtype:trojan-activity;sid:84763757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ds74"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900658/; classtype:trojan-activity;sid:84763758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8zg"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900659/; classtype:trojan-activity;sid:84763759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/71431a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900660/; classtype:trojan-activity;sid:84763760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tbw"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900661/; classtype:trojan-activity;sid:84763761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mys"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900662/; classtype:trojan-activity;sid:84763762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d236bf"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900663/; classtype:trojan-activity;sid:84763763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2j2"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900664/; classtype:trojan-activity;sid:84763764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50fc1e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900665/; classtype:trojan-activity;sid:84763765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6cd6ef"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900666/; classtype:trojan-activity;sid:84763766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5f60c7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900667/; classtype:trojan-activity;sid:84763767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0089b9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900668/; classtype:trojan-activity;sid:84763768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0d2891"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900669/; classtype:trojan-activity;sid:84763769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/072508"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900670/; classtype:trojan-activity;sid:84763770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/awg"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900671/; classtype:trojan-activity;sid:84763771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c3efb4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900672/; classtype:trojan-activity;sid:84763772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b08f0c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900673/; classtype:trojan-activity;sid:84763773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ole5"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900674/; classtype:trojan-activity;sid:84763774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1c7216"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900675/; classtype:trojan-activity;sid:84763775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86d"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900676/; classtype:trojan-activity;sid:84763776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ccf"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900646/; classtype:trojan-activity;sid:84763746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.4.69"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900645/; classtype:trojan-activity;sid:84763745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/x86"; depth:12; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900637/; classtype:trojan-activity;sid:84763737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm"; depth:12; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900638/; classtype:trojan-activity;sid:84763738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/mpsl"; depth:13; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900639/; classtype:trojan-activity;sid:84763739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm7"; depth:13; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900640/; classtype:trojan-activity;sid:84763740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/mips"; depth:13; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900641/; classtype:trojan-activity;sid:84763741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm5"; depth:13; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900642/; classtype:trojan-activity;sid:84763742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/x86_64"; depth:15; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900643/; classtype:trojan-activity;sid:84763743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/ppc"; depth:12; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900644/; classtype:trojan-activity;sid:84763744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2eue"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900631/; classtype:trojan-activity;sid:84763731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/98oe"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900632/; classtype:trojan-activity;sid:84763732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/m68k"; depth:13; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900633/; classtype:trojan-activity;sid:84763733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1htr"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900634/; classtype:trojan-activity;sid:84763734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djeq"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900635/; classtype:trojan-activity;sid:84763735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/arm6"; depth:13; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900636/; classtype:trojan-activity;sid:84763736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/spc"; depth:12; endswith; nocase; http.host; content:"43.98.174.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900630/; classtype:trojan-activity;sid:84763730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3aa8b4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900623/; classtype:trojan-activity;sid:84763723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cf3603"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900624/; classtype:trojan-activity;sid:84763724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e7e17e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900625/; classtype:trojan-activity;sid:84763725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7b2025"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900626/; classtype:trojan-activity;sid:84763726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f76f77"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900627/; classtype:trojan-activity;sid:84763727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/05ac9f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900628/; classtype:trojan-activity;sid:84763728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e67edd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900629/; classtype:trojan-activity;sid:84763729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/41cb7b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900613/; classtype:trojan-activity;sid:84763713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scy"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900614/; classtype:trojan-activity;sid:84763714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fcfd06"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900615/; classtype:trojan-activity;sid:84763715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bfeb03"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900616/; classtype:trojan-activity;sid:84763716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86521e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900617/; classtype:trojan-activity;sid:84763717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0aed7d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900618/; classtype:trojan-activity;sid:84763718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a82d92"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900619/; classtype:trojan-activity;sid:84763719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/69e697"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900620/; classtype:trojan-activity;sid:84763720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/57980e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900621/; classtype:trojan-activity;sid:84763721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpo"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900622/; classtype:trojan-activity;sid:84763722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9f15f6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900596/; classtype:trojan-activity;sid:84763696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9c504a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900597/; classtype:trojan-activity;sid:84763697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/78887f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900598/; classtype:trojan-activity;sid:84763698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/824d82"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900599/; classtype:trojan-activity;sid:84763699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/021219"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900600/; classtype:trojan-activity;sid:84763700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cc89e2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900601/; classtype:trojan-activity;sid:84763701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1d4271"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900602/; classtype:trojan-activity;sid:84763702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/db7b9c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900603/; classtype:trojan-activity;sid:84763703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bed3aa"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900604/; classtype:trojan-activity;sid:84763704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/51f300"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900605/; classtype:trojan-activity;sid:84763705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/42736b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900606/; classtype:trojan-activity;sid:84763706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2bd33f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900607/; classtype:trojan-activity;sid:84763707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6b72d3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900608/; classtype:trojan-activity;sid:84763708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a5d360"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900609/; classtype:trojan-activity;sid:84763709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/839ec9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900610/; classtype:trojan-activity;sid:84763710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/660bc9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900611/; classtype:trojan-activity;sid:84763711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/90e80a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900612/; classtype:trojan-activity;sid:84763712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3c14b4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900577/; classtype:trojan-activity;sid:84763677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d97f08"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900578/; classtype:trojan-activity;sid:84763678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/voga"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900579/; classtype:trojan-activity;sid:84763679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vjb"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900580/; classtype:trojan-activity;sid:84763680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/df5d68"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900581/; classtype:trojan-activity;sid:84763681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0e4138"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900582/; classtype:trojan-activity;sid:84763682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/af2ec4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900583/; classtype:trojan-activity;sid:84763683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f98144"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900584/; classtype:trojan-activity;sid:84763684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ztme"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900585/; classtype:trojan-activity;sid:84763685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ea7693"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900586/; classtype:trojan-activity;sid:84763686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f6d64f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900587/; classtype:trojan-activity;sid:84763687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ef75b2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900588/; classtype:trojan-activity;sid:84763688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0df469"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900589/; classtype:trojan-activity;sid:84763689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/10d086"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900590/; classtype:trojan-activity;sid:84763690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/78dbc7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900591/; classtype:trojan-activity;sid:84763691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d2965f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900592/; classtype:trojan-activity;sid:84763692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6e6855"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900593/; classtype:trojan-activity;sid:84763693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f97e6f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900594/; classtype:trojan-activity;sid:84763694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9ce5ed"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900595/; classtype:trojan-activity;sid:84763695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900576/; classtype:trojan-activity;sid:84763676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.43.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900575/; classtype:trojan-activity;sid:84763675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.217.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900574/; classtype:trojan-activity;sid:84763674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.193.35.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900573/; classtype:trojan-activity;sid:84763673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.209.155.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900572/; classtype:trojan-activity;sid:84763672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.18.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900571/; classtype:trojan-activity;sid:84763671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.112.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900570/; classtype:trojan-activity;sid:84763670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.82.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900569/; classtype:trojan-activity;sid:84763669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.148.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900568/; classtype:trojan-activity;sid:84763668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.43.119.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900567/; classtype:trojan-activity;sid:84763667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_cbc50300e3486e0c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900566/; classtype:trojan-activity;sid:84763666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uuyc.4.1.0.zip"; depth:15; endswith; nocase; http.host; content:"xunyyymdfv.oss-cn-hongkong.aliyuncs.com"; depth:39; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900565/; classtype:trojan-activity;sid:84763665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fktn62.sh"; depth:10; endswith; nocase; http.host; content:"141.11.100.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900564/; classtype:trojan-activity;sid:84763664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900563/; classtype:trojan-activity;sid:84763663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sostener2.vbs"; depth:14; endswith; nocase; http.host; content:"asegurar2026.duckdns.org"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900562/; classtype:trojan-activity;sid:84763662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mhsanaei/3x-ui/master/install.sh"; depth:33; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900561/; classtype:trojan-activity;sid:84763661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/runme.sh"; depth:9; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900558/; classtype:trojan-activity;sid:84763658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a6ea4f6f6031c128.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900559/; classtype:trojan-activity;sid:84763659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_57b60302f7986a48.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900560/; classtype:trojan-activity;sid:84763660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.209.155.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900557/; classtype:trojan-activity;sid:84763657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jenbrute"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900556/; classtype:trojan-activity;sid:84763656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cnc_new_x64"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900555/; classtype:trojan-activity;sid:84763655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.137.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900554/; classtype:trojan-activity;sid:84763654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.43.119.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900553/; classtype:trojan-activity;sid:84763653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/massloader_dvr.new"; depth:19; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900552/; classtype:trojan-activity;sid:84763652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/screenconnect.clientsetup.exe"; depth:30; endswith; nocase; http.host; content:"130.12.180.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900550/; classtype:trojan-activity;sid:84763650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.82.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900551/; classtype:trojan-activity;sid:84763651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.26.226.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900549/; classtype:trojan-activity;sid:84763649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/activemq"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900548/; classtype:trojan-activity;sid:84763648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.225.177.252"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900547/; classtype:trojan-activity;sid:84763647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.225.177.252"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900546/; classtype:trojan-activity;sid:84763646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.13.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900545/; classtype:trojan-activity;sid:84763645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvrk"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900544/; classtype:trojan-activity;sid:84763644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jenload"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900543/; classtype:trojan-activity;sid:84763643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adbload"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900542/; classtype:trojan-activity;sid:84763642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ar5"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900541/; classtype:trojan-activity;sid:84763641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"///main_mpsl"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900540/; classtype:trojan-activity;sid:84763640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900538/; classtype:trojan-activity;sid:84763638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.mipsel"; depth:11; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900539/; classtype:trojan-activity;sid:84763639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.arm6"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900537/; classtype:trojan-activity;sid:84763637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xparm7"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900535/; classtype:trojan-activity;sid:84763635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900536/; classtype:trojan-activity;sid:84763636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.ppc"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900534/; classtype:trojan-activity;sid:84763634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.mpsl"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900532/; classtype:trojan-activity;sid:84763632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_64"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900533/; classtype:trojan-activity;sid:84763633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.arm64"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900531/; classtype:trojan-activity;sid:84763631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.mpsl"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900529/; classtype:trojan-activity;sid:84763629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x86_64"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900530/; classtype:trojan-activity;sid:84763630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.x86"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900528/; classtype:trojan-activity;sid:84763628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.ar"; depth:15; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900527/; classtype:trojan-activity;sid:84763627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.ar6"; depth:16; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900526/; classtype:trojan-activity;sid:84763626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_sh4"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900525/; classtype:trojan-activity;sid:84763625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.arm5"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900524/; classtype:trojan-activity;sid:84763624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.x86"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900523/; classtype:trojan-activity;sid:84763623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.m68k"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900521/; classtype:trojan-activity;sid:84763621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ar7"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900522/; classtype:trojan-activity;sid:84763622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mpsl"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900520/; classtype:trojan-activity;sid:84763620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.ar6"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900519/; classtype:trojan-activity;sid:84763619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.x86_64"; depth:19; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900518/; classtype:trojan-activity;sid:84763618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.ar7"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900517/; classtype:trojan-activity;sid:84763617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900516/; classtype:trojan-activity;sid:84763616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900515/; classtype:trojan-activity;sid:84763615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run_adb.sh"; depth:11; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900514/; classtype:trojan-activity;sid:84763614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.mipsel"; depth:19; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900513/; classtype:trojan-activity;sid:84763613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.mips"; depth:17; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900511/; classtype:trojan-activity;sid:84763611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_aarch64"; depth:13; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900512/; classtype:trojan-activity;sid:84763612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_32"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900510/; classtype:trojan-activity;sid:84763610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_arm64"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900508/; classtype:trojan-activity;sid:84763608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900509/; classtype:trojan-activity;sid:84763609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm5"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900506/; classtype:trojan-activity;sid:84763606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900507/; classtype:trojan-activity;sid:84763607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.arm"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900505/; classtype:trojan-activity;sid:84763605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv6l"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900503/; classtype:trojan-activity;sid:84763603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.ar7"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900504/; classtype:trojan-activity;sid:84763604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm7"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900502/; classtype:trojan-activity;sid:84763602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.m68k"; depth:17; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900501/; classtype:trojan-activity;sid:84763601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ar"; depth:3; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900500/; classtype:trojan-activity;sid:84763600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.mips"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900498/; classtype:trojan-activity;sid:84763598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.aarch64"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900499/; classtype:trojan-activity;sid:84763599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.riscv64"; depth:20; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900496/; classtype:trojan-activity;sid:84763596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.powerpc"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900497/; classtype:trojan-activity;sid:84763597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.aarch64"; depth:13; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900495/; classtype:trojan-activity;sid:84763595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.arm7"; depth:17; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900494/; classtype:trojan-activity;sid:84763594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.ar"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900492/; classtype:trojan-activity;sid:84763592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i386"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900493/; classtype:trojan-activity;sid:84763593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.ar5"; depth:16; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900491/; classtype:trojan-activity;sid:84763591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i486"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900490/; classtype:trojan-activity;sid:84763590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900486/; classtype:trojan-activity;sid:84763586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.arm"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900487/; classtype:trojan-activity;sid:84763587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.m68k"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900488/; classtype:trojan-activity;sid:84763588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.ar5"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900489/; classtype:trojan-activity;sid:84763589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.arm6"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900485/; classtype:trojan-activity;sid:84763585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.aarch64"; depth:13; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900484/; classtype:trojan-activity;sid:84763584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.ar"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900483/; classtype:trojan-activity;sid:84763583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"///main_mips"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900482/; classtype:trojan-activity;sid:84763582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/massload"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900481/; classtype:trojan-activity;sid:84763581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900480/; classtype:trojan-activity;sid:84763580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jenkins.py"; depth:11; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900476/; classtype:trojan-activity;sid:84763576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.ppc64"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900477/; classtype:trojan-activity;sid:84763577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"///mpsl"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900478/; classtype:trojan-activity;sid:84763578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900479/; classtype:trojan-activity;sid:84763579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k.sh"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900475/; classtype:trojan-activity;sid:84763575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900473/; classtype:trojan-activity;sid:84763573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ar6"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900474/; classtype:trojan-activity;sid:84763574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.mipsel"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900472/; classtype:trojan-activity;sid:84763572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.m68k"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900469/; classtype:trojan-activity;sid:84763569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mips"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900470/; classtype:trojan-activity;sid:84763570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.x86"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900471/; classtype:trojan-activity;sid:84763571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.arm5"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900464/; classtype:trojan-activity;sid:84763564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mips.orig"; depth:15; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900465/; classtype:trojan-activity;sid:84763565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900466/; classtype:trojan-activity;sid:84763566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.arm6"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900467/; classtype:trojan-activity;sid:84763567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.sh"; depth:6; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900468/; classtype:trojan-activity;sid:84763568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.ppc"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900461/; classtype:trojan-activity;sid:84763561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.ppc"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900462/; classtype:trojan-activity;sid:84763562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.powerpc"; depth:13; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900463/; classtype:trojan-activity;sid:84763563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.mips"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900458/; classtype:trojan-activity;sid:84763558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900459/; classtype:trojan-activity;sid:84763559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900460/; classtype:trojan-activity;sid:84763560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.aarch64"; depth:20; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900457/; classtype:trojan-activity;sid:84763557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t"; depth:2; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900456/; classtype:trojan-activity;sid:84763556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900453/; classtype:trojan-activity;sid:84763553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.sh4"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900454/; classtype:trojan-activity;sid:84763554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.ar5"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900455/; classtype:trojan-activity;sid:84763555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.arm7"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900450/; classtype:trojan-activity;sid:84763550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7n"; depth:6; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900451/; classtype:trojan-activity;sid:84763551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900452/; classtype:trojan-activity;sid:84763552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.armeb"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900447/; classtype:trojan-activity;sid:84763547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.x86_64"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900448/; classtype:trojan-activity;sid:84763548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.sh4"; depth:16; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900449/; classtype:trojan-activity;sid:84763549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900446/; classtype:trojan-activity;sid:84763546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/powerpc"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900445/; classtype:trojan-activity;sid:84763545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900443/; classtype:trojan-activity;sid:84763543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.arm64"; depth:11; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900444/; classtype:trojan-activity;sid:84763544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armeb"; depth:6; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900442/; classtype:trojan-activity;sid:84763542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.amd64"; depth:11; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900441/; classtype:trojan-activity;sid:84763541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.arm7"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900440/; classtype:trojan-activity;sid:84763540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.i686"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900438/; classtype:trojan-activity;sid:84763538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900439/; classtype:trojan-activity;sid:84763539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riscv64"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900437/; classtype:trojan-activity;sid:84763537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ruck"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900435/; classtype:trojan-activity;sid:84763535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipmiv2.xml"; depth:11; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900436/; classtype:trojan-activity;sid:84763536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.xml"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900434/; classtype:trojan-activity;sid:84763534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.2.112"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900433/; classtype:trojan-activity;sid:84763533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.mips"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900432/; classtype:trojan-activity;sid:84763532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sora.x86"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900431/; classtype:trojan-activity;sid:84763531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900430/; classtype:trojan-activity;sid:84763530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.sh4eb"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900428/; classtype:trojan-activity;sid:84763528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_ppc"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900429/; classtype:trojan-activity;sid:84763529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.x86_64"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900427/; classtype:trojan-activity;sid:84763527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.x86_64"; depth:11; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900425/; classtype:trojan-activity;sid:84763525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pidtest/pid.powerpc"; depth:20; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900426/; classtype:trojan-activity;sid:84763526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.sh4"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900424/; classtype:trojan-activity;sid:84763524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm6"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900423/; classtype:trojan-activity;sid:84763523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.arm7"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900421/; classtype:trojan-activity;sid:84763521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4eb"; depth:6; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900422/; classtype:trojan-activity;sid:84763522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skid.i686"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900420/; classtype:trojan-activity;sid:84763520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.arm8"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900419/; classtype:trojan-activity;sid:84763519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x86"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900418/; classtype:trojan-activity;sid:84763518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.sh4"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900416/; classtype:trojan-activity;sid:84763516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.arm5"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900417/; classtype:trojan-activity;sid:84763517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlxx.arm"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900415/; classtype:trojan-activity;sid:84763515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_m68k"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900414/; classtype:trojan-activity;sid:84763514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x64"; depth:4; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900413/; classtype:trojan-activity;sid:84763513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.ar6"; depth:8; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900412/; classtype:trojan-activity;sid:84763512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_arm7"; depth:9; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900411/; classtype:trojan-activity;sid:84763511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pid.riscv64"; depth:12; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900410/; classtype:trojan-activity;sid:84763510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mips"; depth:10; endswith; nocase; http.host; content:"160.191.242.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900409/; classtype:trojan-activity;sid:84763509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.18.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900408/; classtype:trojan-activity;sid:84763508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.100.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900407/; classtype:trojan-activity;sid:84763507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.100.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900406/; classtype:trojan-activity;sid:84763506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.77.172.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900405/; classtype:trojan-activity;sid:84763505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.153.92.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900404/; classtype:trojan-activity;sid:84763504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.220.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900403/; classtype:trojan-activity;sid:84763503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.231.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900402/; classtype:trojan-activity;sid:84763502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.165.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900400/; classtype:trojan-activity;sid:84763500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.47.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900401/; classtype:trojan-activity;sid:84763501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.153.92.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900399/; classtype:trojan-activity;sid:84763499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.161.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900398/; classtype:trojan-activity;sid:84763498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.75.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900397/; classtype:trojan-activity;sid:84763497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.89.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900396/; classtype:trojan-activity;sid:84763496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.44.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900395/; classtype:trojan-activity;sid:84763495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.231.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900394/; classtype:trojan-activity;sid:84763494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.70.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900393/; classtype:trojan-activity;sid:84763493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.181.201"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900392/; classtype:trojan-activity;sid:84763492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.39.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900391/; classtype:trojan-activity;sid:84763491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.89.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900390/; classtype:trojan-activity;sid:84763490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.70.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900389/; classtype:trojan-activity;sid:84763489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.206.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900388/; classtype:trojan-activity;sid:84763488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.44.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900387/; classtype:trojan-activity;sid:84763487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.71.24.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900386/; classtype:trojan-activity;sid:84763486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.39.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900385/; classtype:trojan-activity;sid:84763485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.206.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900384/; classtype:trojan-activity;sid:84763484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.71.24.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900383/; classtype:trojan-activity;sid:84763483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_457316565c5d19a2.cmd"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900382/; classtype:trojan-activity;sid:84763482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.252.196.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900381/; classtype:trojan-activity;sid:84763481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.13.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900380/; classtype:trojan-activity;sid:84763480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.237.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900379/; classtype:trojan-activity;sid:84763479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.166.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900378/; classtype:trojan-activity;sid:84763478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.13.229"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900377/; classtype:trojan-activity;sid:84763477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.202.104"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900376/; classtype:trojan-activity;sid:84763476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.106.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900375/; classtype:trojan-activity;sid:84763475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.193.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900374/; classtype:trojan-activity;sid:84763474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.161.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900373/; classtype:trojan-activity;sid:84763473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.142.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900372/; classtype:trojan-activity;sid:84763472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.237.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900371/; classtype:trojan-activity;sid:84763471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.40.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900370/; classtype:trojan-activity;sid:84763470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.145.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900368/; classtype:trojan-activity;sid:84763468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.87.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900369/; classtype:trojan-activity;sid:84763469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.202.104"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900367/; classtype:trojan-activity;sid:84763467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.142.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900366/; classtype:trojan-activity;sid:84763466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.87.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900365/; classtype:trojan-activity;sid:84763465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.107.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900364/; classtype:trojan-activity;sid:84763464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.133.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900363/; classtype:trojan-activity;sid:84763463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7061144442/nxumfoe.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900362/; classtype:trojan-activity;sid:84763462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.146.110.122"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900361/; classtype:trojan-activity;sid:84763461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.98.147.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900360/; classtype:trojan-activity;sid:84763460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.238.178.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900359/; classtype:trojan-activity;sid:84763459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.238.178.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900358/; classtype:trojan-activity;sid:84763458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.146.110.122"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900357/; classtype:trojan-activity;sid:84763457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.69.86.82"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900356/; classtype:trojan-activity;sid:84763456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.234.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900355/; classtype:trojan-activity;sid:84763455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.79.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900354/; classtype:trojan-activity;sid:84763454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.7.221.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900353/; classtype:trojan-activity;sid:84763453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.69.86.82"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900352/; classtype:trojan-activity;sid:84763452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.41.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900351/; classtype:trojan-activity;sid:84763451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bolodo"; depth:7; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900350/; classtype:trojan-activity;sid:84763450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"2.187.39.131"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900349/; classtype:trojan-activity;sid:84763449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.193.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900348/; classtype:trojan-activity;sid:84763448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.25.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900347/; classtype:trojan-activity;sid:84763447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.25.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900346/; classtype:trojan-activity;sid:84763446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.218.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900345/; classtype:trojan-activity;sid:84763445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900336/; classtype:trojan-activity;sid:84763436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900337/; classtype:trojan-activity;sid:84763437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900338/; classtype:trojan-activity;sid:84763438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900339/; classtype:trojan-activity;sid:84763439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900340/; classtype:trojan-activity;sid:84763440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900341/; classtype:trojan-activity;sid:84763441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900342/; classtype:trojan-activity;sid:84763442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900343/; classtype:trojan-activity;sid:84763443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"194.26.192.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900344/; classtype:trojan-activity;sid:84763444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"85.11.167.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900328/; classtype:trojan-activity;sid:84763428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"85.11.167.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900329/; classtype:trojan-activity;sid:84763429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"85.11.167.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900330/; classtype:trojan-activity;sid:84763430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"85.11.167.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900331/; classtype:trojan-activity;sid:84763431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"85.11.167.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900332/; classtype:trojan-activity;sid:84763432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"85.11.167.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900333/; classtype:trojan-activity;sid:84763433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"85.11.167.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900334/; classtype:trojan-activity;sid:84763434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"85.11.167.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900335/; classtype:trojan-activity;sid:84763435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.175.26.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900327/; classtype:trojan-activity;sid:84763427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.202.187.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900326/; classtype:trojan-activity;sid:84763426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.101.187.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900325/; classtype:trojan-activity;sid:84763425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"203.101.187.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900324/; classtype:trojan-activity;sid:84763424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.9.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900323/; classtype:trojan-activity;sid:84763423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.61.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900322/; classtype:trojan-activity;sid:84763422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.61.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900321/; classtype:trojan-activity;sid:84763421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.9.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900320/; classtype:trojan-activity;sid:84763420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5939fd79fb073513.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900319/; classtype:trojan-activity;sid:84763419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.202.187.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900318/; classtype:trojan-activity;sid:84763418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.218.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900317/; classtype:trojan-activity;sid:84763417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.192.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900316/; classtype:trojan-activity;sid:84763416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.150.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900315/; classtype:trojan-activity;sid:84763415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.43.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900314/; classtype:trojan-activity;sid:84763414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.230.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900313/; classtype:trojan-activity;sid:84763413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.230.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900312/; classtype:trojan-activity;sid:84763412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.188.44.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900311/; classtype:trojan-activity;sid:84763411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.188.44.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900310/; classtype:trojan-activity;sid:84763410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.69.66.139"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900309/; classtype:trojan-activity;sid:84763409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900308/; classtype:trojan-activity;sid:84763408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900307/; classtype:trojan-activity;sid:84763407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.150.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900306/; classtype:trojan-activity;sid:84763406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.148.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900305/; classtype:trojan-activity;sid:84763405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.220.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900304/; classtype:trojan-activity;sid:84763404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.69.66.139"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900303/; classtype:trojan-activity;sid:84763403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.9.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900302/; classtype:trojan-activity;sid:84763402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.9.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900301/; classtype:trojan-activity;sid:84763401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"37.77.150.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900300/; classtype:trojan-activity;sid:84763400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/setup.exe"; depth:10; endswith; nocase; http.host; content:"45.141.119.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900297/; classtype:trojan-activity;sid:84763397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update.ps1"; depth:11; endswith; nocase; http.host; content:"45.141.119.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900298/; classtype:trojan-activity;sid:84763398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"37.77.150.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900299/; classtype:trojan-activity;sid:84763399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.217.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900296/; classtype:trojan-activity;sid:84763396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.133.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900295/; classtype:trojan-activity;sid:84763395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.91.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900294/; classtype:trojan-activity;sid:84763394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.90.145.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900293/; classtype:trojan-activity;sid:84763393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900291/; classtype:trojan-activity;sid:84763391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.150.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900292/; classtype:trojan-activity;sid:84763392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.152.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900290/; classtype:trojan-activity;sid:84763390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.151.82.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900289/; classtype:trojan-activity;sid:84763389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.186.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900288/; classtype:trojan-activity;sid:84763388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.186.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900287/; classtype:trojan-activity;sid:84763387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.244.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900286/; classtype:trojan-activity;sid:84763386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.176.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900285/; classtype:trojan-activity;sid:84763385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/systemdd"; depth:9; endswith; nocase; http.host; content:"143.246.195.33"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900284/; classtype:trojan-activity;sid:84763384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.79.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900283/; classtype:trojan-activity;sid:84763383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.176.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900282/; classtype:trojan-activity;sid:84763382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.244.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900281/; classtype:trojan-activity;sid:84763381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"130.12.209.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900280/; classtype:trojan-activity;sid:84763380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.127.232.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900279/; classtype:trojan-activity;sid:84763379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm4"; depth:10; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900278/; classtype:trojan-activity;sid:84763378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_powerpc"; depth:13; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900275/; classtype:trojan-activity;sid:84763375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_aarch64"; depth:13; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900276/; classtype:trojan-activity;sid:84763376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86"; depth:9; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900277/; classtype:trojan-activity;sid:84763377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm7"; depth:10; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900271/; classtype:trojan-activity;sid:84763371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm6"; depth:10; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900272/; classtype:trojan-activity;sid:84763372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86_64"; depth:12; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900273/; classtype:trojan-activity;sid:84763373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm5"; depth:10; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900274/; classtype:trojan-activity;sid:84763374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbc"; depth:4; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900269/; classtype:trojan-activity;sid:84763369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mips"; depth:10; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900268/; classtype:trojan-activity;sid:84763368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.x86"; depth:13; endswith; nocase; http.host; content:"46.151.182.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900267/; classtype:trojan-activity;sid:84763367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mipsel"; depth:12; endswith; nocase; http.host; content:"109.248.160.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900266/; classtype:trojan-activity;sid:84763366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.11.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900265/; classtype:trojan-activity;sid:84763365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.145.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900264/; classtype:trojan-activity;sid:84763364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.230.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900263/; classtype:trojan-activity;sid:84763363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.230.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900262/; classtype:trojan-activity;sid:84763362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900261/; classtype:trojan-activity;sid:84763361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.197.132.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900260/; classtype:trojan-activity;sid:84763360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.106.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900259/; classtype:trojan-activity;sid:84763359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900258/; classtype:trojan-activity;sid:84763358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.127.232.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900257/; classtype:trojan-activity;sid:84763357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.150.155"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900256/; classtype:trojan-activity;sid:84763356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.150.155"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900255/; classtype:trojan-activity;sid:84763355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.24.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900254/; classtype:trojan-activity;sid:84763354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.118.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900253/; classtype:trojan-activity;sid:84763353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.118.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900252/; classtype:trojan-activity;sid:84763352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.255.6.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900251/; classtype:trojan-activity;sid:84763351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.231.139.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900250/; classtype:trojan-activity;sid:84763350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.167.254.183"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900249/; classtype:trojan-activity;sid:84763349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.48.41.248"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900248/; classtype:trojan-activity;sid:84763348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900246/; classtype:trojan-activity;sid:84763346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.167.254.183"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900247/; classtype:trojan-activity;sid:84763347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lol"; depth:4; endswith; nocase; http.host; content:"176.65.148.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900245/; classtype:trojan-activity;sid:84763345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data.msi"; depth:9; endswith; nocase; http.host; content:"fkoqonr2vgbsw7qu.public.blob.vercel-storage.com"; depth:47; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900244/; classtype:trojan-activity;sid:84763344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/krypton.jar"; depth:22; endswith; nocase; http.host; content:"cheatclients.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900243/; classtype:trojan-activity;sid:84763343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/zyphers_rig_mod.jar"; depth:30; endswith; nocase; http.host; content:"cheatclients.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900242/; classtype:trojan-activity;sid:84763342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/radium_client.jar"; depth:28; endswith; nocase; http.host; content:"cheatclients.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900240/; classtype:trojan-activity;sid:84763340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteorclientjar/meteorclient-1.21.11-84.jar"; depth:44; endswith; nocase; http.host; content:"meteorclient.shop"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900241/; classtype:trojan-activity;sid:84763341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/4e_client.jar"; depth:24; endswith; nocase; http.host; content:"cheatclients.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900239/; classtype:trojan-activity;sid:84763339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/package.zip"; depth:12; endswith; nocase; http.host; content:"pub-00d54ae289e84e93a3c8640fb2301c5f.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900238/; classtype:trojan-activity;sid:84763338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_8d4eff19b5763782.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900237/; classtype:trojan-activity;sid:84763337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.106.46"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900236/; classtype:trojan-activity;sid:84763336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.237.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900235/; classtype:trojan-activity;sid:84763335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.237.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900234/; classtype:trojan-activity;sid:84763334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.205.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900233/; classtype:trojan-activity;sid:84763333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.48.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900232/; classtype:trojan-activity;sid:84763332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.205.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900231/; classtype:trojan-activity;sid:84763331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900230/; classtype:trojan-activity;sid:84763330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.30.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900229/; classtype:trojan-activity;sid:84763329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.149.65.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900228/; classtype:trojan-activity;sid:84763328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.212.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900227/; classtype:trojan-activity;sid:84763327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900226/; classtype:trojan-activity;sid:84763326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm64"; depth:23; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900225/; classtype:trojan-activity;sid:84763325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.m68k"; depth:22; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900224/; classtype:trojan-activity;sid:84763324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm"; depth:21; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900213/; classtype:trojan-activity;sid:84763313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.x86"; depth:21; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900214/; classtype:trojan-activity;sid:84763314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.mpsl"; depth:22; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900215/; classtype:trojan-activity;sid:84763315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.ppc"; depth:21; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900216/; classtype:trojan-activity;sid:84763316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm5"; depth:22; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900217/; classtype:trojan-activity;sid:84763317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm7"; depth:22; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900218/; classtype:trojan-activity;sid:84763318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.x86_64"; depth:24; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900219/; classtype:trojan-activity;sid:84763319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arc"; depth:21; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900220/; classtype:trojan-activity;sid:84763320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm6"; depth:22; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900221/; classtype:trojan-activity;sid:84763321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.sh4"; depth:21; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900222/; classtype:trojan-activity;sid:84763322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.mips"; depth:22; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900223/; classtype:trojan-activity;sid:84763323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.i686"; depth:22; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900212/; classtype:trojan-activity;sid:84763312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lkxstress.sh"; depth:13; endswith; nocase; http.host; content:"170.205.31.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900211/; classtype:trojan-activity;sid:84763311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.149.65.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900210/; classtype:trojan-activity;sid:84763310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.ppc"; depth:21; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900208/; classtype:trojan-activity;sid:84763308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.mpsl"; depth:22; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900209/; classtype:trojan-activity;sid:84763309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm64"; depth:23; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900206/; classtype:trojan-activity;sid:84763306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.mips"; depth:22; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900207/; classtype:trojan-activity;sid:84763307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.sh4"; depth:21; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900203/; classtype:trojan-activity;sid:84763303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arc"; depth:21; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900204/; classtype:trojan-activity;sid:84763304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.m68k"; depth:22; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900205/; classtype:trojan-activity;sid:84763305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.i686"; depth:22; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900199/; classtype:trojan-activity;sid:84763299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.x86_64"; depth:24; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900200/; classtype:trojan-activity;sid:84763300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm7"; depth:22; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900201/; classtype:trojan-activity;sid:84763301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm6"; depth:22; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900202/; classtype:trojan-activity;sid:84763302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.x86"; depth:21; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900198/; classtype:trojan-activity;sid:84763298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm5"; depth:22; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900196/; classtype:trojan-activity;sid:84763296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lkxstress.sh"; depth:13; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900197/; classtype:trojan-activity;sid:84763297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm"; depth:21; endswith; nocase; http.host; content:"lol.exodustrala.dpdns.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900195/; classtype:trojan-activity;sid:84763295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.178.118.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900194/; classtype:trojan-activity;sid:84763294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.119.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900193/; classtype:trojan-activity;sid:84763293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.178.118.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900192/; classtype:trojan-activity;sid:84763292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.103.116.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900191/; classtype:trojan-activity;sid:84763291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.95.255.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900190/; classtype:trojan-activity;sid:84763290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.194.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900188/; classtype:trojan-activity;sid:84763288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.26.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900189/; classtype:trojan-activity;sid:84763289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.178.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900187/; classtype:trojan-activity;sid:84763287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.121.138.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900186/; classtype:trojan-activity;sid:84763286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.255.6.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900185/; classtype:trojan-activity;sid:84763285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.29.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900184/; classtype:trojan-activity;sid:84763284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.113.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900181/; classtype:trojan-activity;sid:84763281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.26.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900182/; classtype:trojan-activity;sid:84763282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.69.80.149"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900183/; classtype:trojan-activity;sid:84763283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.41.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900177/; classtype:trojan-activity;sid:84763277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.41.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900178/; classtype:trojan-activity;sid:84763278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.26.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900179/; classtype:trojan-activity;sid:84763279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.69.80.149"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900180/; classtype:trojan-activity;sid:84763280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"194.28.62.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900166/; classtype:trojan-activity;sid:84763266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.252.209.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900167/; classtype:trojan-activity;sid:84763267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.219.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900168/; classtype:trojan-activity;sid:84763268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.184.29.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900169/; classtype:trojan-activity;sid:84763269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.7.68"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900170/; classtype:trojan-activity;sid:84763270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.53.72.145"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900171/; classtype:trojan-activity;sid:84763271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.217.3.109"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900172/; classtype:trojan-activity;sid:84763272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900173/; classtype:trojan-activity;sid:84763273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.213.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900174/; classtype:trojan-activity;sid:84763274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.48.41.248"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900175/; classtype:trojan-activity;sid:84763275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.86.172.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900176/; classtype:trojan-activity;sid:84763276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.12.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900165/; classtype:trojan-activity;sid:84763265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"82.48.207.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900163/; classtype:trojan-activity;sid:84763263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.179.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900164/; classtype:trojan-activity;sid:84763264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.25.110"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900161/; classtype:trojan-activity;sid:84763261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.134.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900162/; classtype:trojan-activity;sid:84763262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.172.13.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900151/; classtype:trojan-activity;sid:84763251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.197.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900152/; classtype:trojan-activity;sid:84763252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.252.209.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900153/; classtype:trojan-activity;sid:84763253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.95.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900154/; classtype:trojan-activity;sid:84763254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.197.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900155/; classtype:trojan-activity;sid:84763255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"194.28.62.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900156/; classtype:trojan-activity;sid:84763256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.181.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900157/; classtype:trojan-activity;sid:84763257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.35.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900158/; classtype:trojan-activity;sid:84763258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.103.116.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900159/; classtype:trojan-activity;sid:84763259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900160/; classtype:trojan-activity;sid:84763260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.171.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900133/; classtype:trojan-activity;sid:84763233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.39.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900134/; classtype:trojan-activity;sid:84763234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.241.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900135/; classtype:trojan-activity;sid:84763235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.85.6.186"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900136/; classtype:trojan-activity;sid:84763236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.9.151"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900137/; classtype:trojan-activity;sid:84763237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.206.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900138/; classtype:trojan-activity;sid:84763238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.0.79"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900139/; classtype:trojan-activity;sid:84763239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.244.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900140/; classtype:trojan-activity;sid:84763240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.134.172.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900141/; classtype:trojan-activity;sid:84763241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.164.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900142/; classtype:trojan-activity;sid:84763242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.184.7.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900143/; classtype:trojan-activity;sid:84763243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.160.130.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900144/; classtype:trojan-activity;sid:84763244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.51.109"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900145/; classtype:trojan-activity;sid:84763245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"179.108.89.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900146/; classtype:trojan-activity;sid:84763246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.24.218.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900147/; classtype:trojan-activity;sid:84763247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.124.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900148/; classtype:trojan-activity;sid:84763248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.29.170"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900149/; classtype:trojan-activity;sid:84763249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.17.147"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900150/; classtype:trojan-activity;sid:84763250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.228.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900130/; classtype:trojan-activity;sid:84763230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.113.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900131/; classtype:trojan-activity;sid:84763231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.124.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900132/; classtype:trojan-activity;sid:84763232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.29.170"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900129/; classtype:trojan-activity;sid:84763229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.24.218.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900128/; classtype:trojan-activity;sid:84763228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.72.145"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900127/; classtype:trojan-activity;sid:84763227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900116/; classtype:trojan-activity;sid:84763216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900117/; classtype:trojan-activity;sid:84763217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.213.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900118/; classtype:trojan-activity;sid:84763218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.9.151"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900119/; classtype:trojan-activity;sid:84763219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.249.68.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900120/; classtype:trojan-activity;sid:84763220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.0.79"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900121/; classtype:trojan-activity;sid:84763221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.99.250.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900122/; classtype:trojan-activity;sid:84763222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.184.7.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900123/; classtype:trojan-activity;sid:84763223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.58.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900124/; classtype:trojan-activity;sid:84763224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.184.29.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900125/; classtype:trojan-activity;sid:84763225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.192.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900126/; classtype:trojan-activity;sid:84763226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.12.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900093/; classtype:trojan-activity;sid:84763193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.149.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900094/; classtype:trojan-activity;sid:84763194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.177.186.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900095/; classtype:trojan-activity;sid:84763195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.54.13"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900096/; classtype:trojan-activity;sid:84763196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.183.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900097/; classtype:trojan-activity;sid:84763197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.204.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900098/; classtype:trojan-activity;sid:84763198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.96.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900099/; classtype:trojan-activity;sid:84763199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"144.48.123.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900100/; classtype:trojan-activity;sid:84763200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.52.248"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900101/; classtype:trojan-activity;sid:84763201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.52.248"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900102/; classtype:trojan-activity;sid:84763202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.164.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900103/; classtype:trojan-activity;sid:84763203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.149.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900104/; classtype:trojan-activity;sid:84763204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.212.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900105/; classtype:trojan-activity;sid:84763205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.183.1"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900106/; classtype:trojan-activity;sid:84763206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.156.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900107/; classtype:trojan-activity;sid:84763207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.24.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900108/; classtype:trojan-activity;sid:84763208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.236.157.223"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900109/; classtype:trojan-activity;sid:84763209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.115.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900110/; classtype:trojan-activity;sid:84763210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.25.110"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900111/; classtype:trojan-activity;sid:84763211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.212.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900112/; classtype:trojan-activity;sid:84763212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.17.147"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900113/; classtype:trojan-activity;sid:84763213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.179.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900114/; classtype:trojan-activity;sid:84763214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.241.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900115/; classtype:trojan-activity;sid:84763215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.58.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900090/; classtype:trojan-activity;sid:84763190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.18.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900091/; classtype:trojan-activity;sid:84763191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.144.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900092/; classtype:trojan-activity;sid:84763192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.229.247.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900089/; classtype:trojan-activity;sid:84763189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.119.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900088/; classtype:trojan-activity;sid:84763188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.144.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900087/; classtype:trojan-activity;sid:84763187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.136.13.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900086/; classtype:trojan-activity;sid:84763186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.55.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900084/; classtype:trojan-activity;sid:84763184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.116.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900085/; classtype:trojan-activity;sid:84763185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.119.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900083/; classtype:trojan-activity;sid:84763183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.11.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900082/; classtype:trojan-activity;sid:84763182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.136.13.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900081/; classtype:trojan-activity;sid:84763181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.236.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900080/; classtype:trojan-activity;sid:84763180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.116.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900079/; classtype:trojan-activity;sid:84763179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.194.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900078/; classtype:trojan-activity;sid:84763178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.113.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900077/; classtype:trojan-activity;sid:84763177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.138.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900076/; classtype:trojan-activity;sid:84763176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.55.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900075/; classtype:trojan-activity;sid:84763175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.252.205"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900074/; classtype:trojan-activity;sid:84763174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.21.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900071/; classtype:trojan-activity;sid:84763171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.226.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900070/; classtype:trojan-activity;sid:84763170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.226.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900069/; classtype:trojan-activity;sid:84763169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900068/; classtype:trojan-activity;sid:84763168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.231.229.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900067/; classtype:trojan-activity;sid:84763167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.101.187.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900066/; classtype:trojan-activity;sid:84763166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900065/; classtype:trojan-activity;sid:84763165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"203.101.187.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900064/; classtype:trojan-activity;sid:84763164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.98.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900063/; classtype:trojan-activity;sid:84763163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.33.248"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900062/; classtype:trojan-activity;sid:84763162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/pfxpcqrssrvi4h4/file"; depth:26; endswith; nocase; http.host; content:"www.mediafire.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900061/; classtype:trojan-activity;sid:84763161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/pfxpcqrssrvi4h4/file"; depth:26; endswith; nocase; http.host; content:"mediafire.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900060/; classtype:trojan-activity;sid:84763160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.33.248"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900059/; classtype:trojan-activity;sid:84763159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.98.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900058/; classtype:trojan-activity;sid:84763158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"115.55.183.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900057/; classtype:trojan-activity;sid:84763157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moho-pro-14-win-x64-full-version-free-download/"; depth:48; endswith; nocase; http.host; content:"www.downloadpirate.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900055/; classtype:trojan-activity;sid:84763155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_20993cb64056ec76.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900056/; classtype:trojan-activity;sid:84763156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.147.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900054/; classtype:trojan-activity;sid:84763154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.107.229.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900053/; classtype:trojan-activity;sid:84763153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.147.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900052/; classtype:trojan-activity;sid:84763152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.217.34.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900051/; classtype:trojan-activity;sid:84763151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.107.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900050/; classtype:trojan-activity;sid:84763150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.138.134.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900049/; classtype:trojan-activity;sid:84763149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.10.48.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900048/; classtype:trojan-activity;sid:84763148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.107.229.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900047/; classtype:trojan-activity;sid:84763147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.104.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900046/; classtype:trojan-activity;sid:84763146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.138.134.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900045/; classtype:trojan-activity;sid:84763145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.80.60.21"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900044/; classtype:trojan-activity;sid:84763144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.10.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900043/; classtype:trojan-activity;sid:84763143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.139.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900042/; classtype:trojan-activity;sid:84763142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.119.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900041/; classtype:trojan-activity;sid:84763141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.133.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900040/; classtype:trojan-activity;sid:84763140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"77.236.74.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900039/; classtype:trojan-activity;sid:84763139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm64"; depth:6; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900038/; classtype:trojan-activity;sid:84763138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_tbk"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900028/; classtype:trojan-activity;sid:84763128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi"; depth:6; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900029/; classtype:trojan-activity;sid:84763129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hnap.sh"; depth:8; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900030/; classtype:trojan-activity;sid:84763130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/netgear.sh"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900031/; classtype:trojan-activity;sid:84763131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_av"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900032/; classtype:trojan-activity;sid:84763132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900033/; classtype:trojan-activity;sid:84763133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huawei.sh"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900034/; classtype:trojan-activity;sid:84763134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_tp"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900035/; classtype:trojan-activity;sid:84763135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm64"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900036/; classtype:trojan-activity;sid:84763136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.aarch64"; depth:13; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900037/; classtype:trojan-activity;sid:84763137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unifi.sh"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900027/; classtype:trojan-activity;sid:84763127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_hk"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900026/; classtype:trojan-activity;sid:84763126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"212.164.115.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900025/; classtype:trojan-activity;sid:84763125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.235.243.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900024/; classtype:trojan-activity;sid:84763124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.236.74.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900023/; classtype:trojan-activity;sid:84763123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.209.236"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900022/; classtype:trojan-activity;sid:84763122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main2.exe"; depth:10; endswith; nocase; http.host; content:"triflackcom.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900021/; classtype:trojan-activity;sid:84763121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.209.236"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900020/; classtype:trojan-activity;sid:84763120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.132.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900019/; classtype:trojan-activity;sid:84763119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.231.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900018/; classtype:trojan-activity;sid:84763118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.136.49.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900017/; classtype:trojan-activity;sid:84763117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.217.3.109"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900016/; classtype:trojan-activity;sid:84763116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.136.49.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900015/; classtype:trojan-activity;sid:84763115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.231.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900014/; classtype:trojan-activity;sid:84763114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_aarch64"; depth:13; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900013/; classtype:trojan-activity;sid:84763113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.83.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900012/; classtype:trojan-activity;sid:84763112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbc"; depth:4; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900011/; classtype:trojan-activity;sid:84763111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.204.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900010/; classtype:trojan-activity;sid:84763110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.83.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900009/; classtype:trojan-activity;sid:84763109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.253.29.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900008/; classtype:trojan-activity;sid:84763108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.189.22.51"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900007/; classtype:trojan-activity;sid:84763107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.8.86"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900006/; classtype:trojan-activity;sid:84763106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.193.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900005/; classtype:trojan-activity;sid:84763105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.138.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900004/; classtype:trojan-activity;sid:84763104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.253.29.68"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900003/; classtype:trojan-activity;sid:84763103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/1781548144/ql0ijz0.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900001/; classtype:trojan-activity;sid:84763101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/5223853602/udsthxb.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900002/; classtype:trojan-activity;sid:84763102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.131.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900000/; classtype:trojan-activity;sid:84763100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.107.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3899999/; classtype:trojan-activity;sid:84763099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.160.130.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3899998/; classtype:trojan-activity;sid:84763098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.59.22.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3899997/; classtype:trojan-activity;sid:84763097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.219.74.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3899996/; classtype:trojan-activity;sid:84763096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.95.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3899995/; classtype:trojan-activity;sid:84763095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.59.22.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899994/; classtype:trojan-activity;sid:84763094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.234.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899993/; classtype:trojan-activity;sid:84763093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.60.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899992/; classtype:trojan-activity;sid:84763092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.151.82.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899991/; classtype:trojan-activity;sid:84763091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.89.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899990/; classtype:trojan-activity;sid:84763090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.113.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899989/; classtype:trojan-activity;sid:84763089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.38.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899988/; classtype:trojan-activity;sid:84763088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.89.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899987/; classtype:trojan-activity;sid:84763087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.209.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899986/; classtype:trojan-activity;sid:84763086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.79.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899985/; classtype:trojan-activity;sid:84763085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.213.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899984/; classtype:trojan-activity;sid:84763084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.82.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899983/; classtype:trojan-activity;sid:84763083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.223.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899982/; classtype:trojan-activity;sid:84763082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.139.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899981/; classtype:trojan-activity;sid:84763081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.70.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899980/; classtype:trojan-activity;sid:84763080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.223.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899979/; classtype:trojan-activity;sid:84763079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.213.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899978/; classtype:trojan-activity;sid:84763078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.97.94.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899977/; classtype:trojan-activity;sid:84763077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.139.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899976/; classtype:trojan-activity;sid:84763076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899975/; classtype:trojan-activity;sid:84763075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.197.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899974/; classtype:trojan-activity;sid:84763074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.175.92.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899973/; classtype:trojan-activity;sid:84763073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.237.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899972/; classtype:trojan-activity;sid:84763072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.157.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899971/; classtype:trojan-activity;sid:84763071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/73/gooddaycomingforu.hta"; depth:25; endswith; nocase; http.host; content:"204.44.69.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899970/; classtype:trojan-activity;sid:84763070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/threadcolonelsouk/release/releases/download/release/release.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899969/; classtype:trojan-activity;sid:84763069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shapecluneedle/jubilant-engine/releases/download/exec/payd.exe"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899968/; classtype:trojan-activity;sid:84763068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shapecluneedle/jubilant-engine/releases/download/exec/payl.exe"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899967/; classtype:trojan-activity;sid:84763067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blacksuite999/fishstrap-roblox-2026/releases/download/release/release.v.1.3.8.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899965/; classtype:trojan-activity;sid:84763065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cooperloq9/project-zomboid-build-42-map/releases/download/release/release.v.1.3.8.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899966/; classtype:trojan-activity;sid:84763066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alomonohom6/stalzone-cheat-2026/releases/download/release/release.v.3.1.4.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899964/; classtype:trojan-activity;sid:84763064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alinright93/stalzone-tools-cheat-2026/releases/download/release/stalzone.v1.6.by.kernel.labs.zip"; depth:97; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899963/; classtype:trojan-activity;sid:84763063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.237.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899962/; classtype:trojan-activity;sid:84763062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beamchunin42/jennymod-installer/releases/download/latest/jennymod.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899961/; classtype:trojan-activity;sid:84763061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.157.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899960/; classtype:trojan-activity;sid:84763060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.175.92.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899959/; classtype:trojan-activity;sid:84763059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.88.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899958/; classtype:trojan-activity;sid:84763058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.196.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899957/; classtype:trojan-activity;sid:84763057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.196.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899956/; classtype:trojan-activity;sid:84763056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.23.194.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899955/; classtype:trojan-activity;sid:84763055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.234.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899954/; classtype:trojan-activity;sid:84763054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.169.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899953/; classtype:trojan-activity;sid:84763053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.13.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899952/; classtype:trojan-activity;sid:84763052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ntb.x64"; depth:13; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899944/; classtype:trojan-activity;sid:84763044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ntb.mipsel"; depth:16; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899945/; classtype:trojan-activity;sid:84763045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ntb.arm5"; depth:14; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899946/; classtype:trojan-activity;sid:84763046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ntb.arm64"; depth:15; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899947/; classtype:trojan-activity;sid:84763047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ntb.x86"; depth:13; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899948/; classtype:trojan-activity;sid:84763048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ntb.arm6"; depth:14; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899949/; classtype:trojan-activity;sid:84763049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ntb.arm7"; depth:14; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899950/; classtype:trojan-activity;sid:84763050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ntb.mips"; depth:14; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899951/; classtype:trojan-activity;sid:84763051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/clashroyalv2.apk"; depth:22; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899943/; classtype:trojan-activity;sid:84763043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.234.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899942/; classtype:trojan-activity;sid:84763042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.169.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899941/; classtype:trojan-activity;sid:84763041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.47.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899940/; classtype:trojan-activity;sid:84763040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.219.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899939/; classtype:trojan-activity;sid:84763039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.13.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899938/; classtype:trojan-activity;sid:84763038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dit.bin"; depth:8; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899937/; classtype:trojan-activity;sid:84763037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/slim.arm64"; depth:13; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899936/; classtype:trojan-activity;sid:84763036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek.sh"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899933/; classtype:trojan-activity;sid:84763033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/slim.arm7"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899934/; classtype:trojan-activity;sid:84763034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/slim.mpsl"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899935/; classtype:trojan-activity;sid:84763035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adas.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899931/; classtype:trojan-activity;sid:84763031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ados.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899932/; classtype:trojan-activity;sid:84763032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mina.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899929/; classtype:trojan-activity;sid:84763029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maya.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899930/; classtype:trojan-activity;sid:84763030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jhgjse.exe"; depth:11; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899918/; classtype:trojan-activity;sid:84763018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suza.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899919/; classtype:trojan-activity;sid:84763019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dt.bin"; depth:7; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899920/; classtype:trojan-activity;sid:84763020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anfo.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899921/; classtype:trojan-activity;sid:84763021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msis.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899922/; classtype:trojan-activity;sid:84763022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntmyebewekca.exe"; depth:17; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899923/; classtype:trojan-activity;sid:84763023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/babust.exe"; depth:11; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899924/; classtype:trojan-activity;sid:84763024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/slim.arm"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899925/; classtype:trojan-activity;sid:84763025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/term.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899926/; classtype:trojan-activity;sid:84763026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lol.exe"; depth:8; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899927/; classtype:trojan-activity;sid:84763027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/single.exe"; depth:11; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899928/; classtype:trojan-activity;sid:84763028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gpon.sh"; depth:8; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899917/; classtype:trojan-activity;sid:84763017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.36.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899916/; classtype:trojan-activity;sid:84763016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/slim.mips"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899915/; classtype:trojan-activity;sid:84763015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seung90912/sad23213zxc/raw/refs/heads/main/freebobux.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899914/; classtype:trojan-activity;sid:84763014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.36.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899913/; classtype:trojan-activity;sid:84763013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm"; depth:10; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899908/; classtype:trojan-activity;sid:84763008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm7"; depth:11; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899909/; classtype:trojan-activity;sid:84763009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899910/; classtype:trojan-activity;sid:84763010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899911/; classtype:trojan-activity;sid:84763011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899912/; classtype:trojan-activity;sid:84763012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899902/; classtype:trojan-activity;sid:84763002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i686"; depth:11; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899903/; classtype:trojan-activity;sid:84763003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899904/; classtype:trojan-activity;sid:84763004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899905/; classtype:trojan-activity;sid:84763005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899906/; classtype:trojan-activity;sid:84763006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arc"; depth:10; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899907/; classtype:trojan-activity;sid:84763007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899899/; classtype:trojan-activity;sid:84762999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899900/; classtype:trojan-activity;sid:84763000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899901/; classtype:trojan-activity;sid:84763001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899897/; classtype:trojan-activity;sid:84762997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"jkqhdbbbqwiujkaz.hopto.org"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899898/; classtype:trojan-activity;sid:84762998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tris.exe"; depth:9; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899893/; classtype:trojan-activity;sid:84762993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heras.exe"; depth:10; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899894/; classtype:trojan-activity;sid:84762994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uos.bin"; depth:8; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899895/; classtype:trojan-activity;sid:84762995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/actami.exe"; depth:11; endswith; nocase; http.host; content:"95.164.53.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899896/; classtype:trojan-activity;sid:84762996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ad49f7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899890/; classtype:trojan-activity;sid:84762990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/77fda1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899891/; classtype:trojan-activity;sid:84762991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2de858"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899892/; classtype:trojan-activity;sid:84762992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8e9d9e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899879/; classtype:trojan-activity;sid:84762979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/013767"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899880/; classtype:trojan-activity;sid:84762980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/be3b0c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899881/; classtype:trojan-activity;sid:84762981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hxqh"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899882/; classtype:trojan-activity;sid:84762982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txa"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899883/; classtype:trojan-activity;sid:84762983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/096459"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899884/; classtype:trojan-activity;sid:84762984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mxx"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899885/; classtype:trojan-activity;sid:84762985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5s4"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899886/; classtype:trojan-activity;sid:84762986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/475040"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899887/; classtype:trojan-activity;sid:84762987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e78460"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899888/; classtype:trojan-activity;sid:84762988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xzoq"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899889/; classtype:trojan-activity;sid:84762989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/552ff2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899876/; classtype:trojan-activity;sid:84762976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3cd35f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899877/; classtype:trojan-activity;sid:84762977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d0ab28"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899878/; classtype:trojan-activity;sid:84762978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.136.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899875/; classtype:trojan-activity;sid:84762975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jqxpnsnuikq90.bin"; depth:18; endswith; nocase; http.host; content:"backup.tkspr1v.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899874/; classtype:trojan-activity;sid:84762974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.9.22"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899873/; classtype:trojan-activity;sid:84762973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dbg"; depth:9; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899872/; classtype:trojan-activity;sid:84762972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899869/; classtype:trojan-activity;sid:84762969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i686"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899870/; classtype:trojan-activity;sid:84762970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsrouter"; depth:16; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899871/; classtype:trojan-activity;sid:84762971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899867/; classtype:trojan-activity;sid:84762967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telnet.sh"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899868/; classtype:trojan-activity;sid:84762968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.82.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899866/; classtype:trojan-activity;sid:84762966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899865/; classtype:trojan-activity;sid:84762965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899863/; classtype:trojan-activity;sid:84762963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sparc"; depth:6; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899864/; classtype:trojan-activity;sid:84762964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899850/; classtype:trojan-activity;sid:84762950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899851/; classtype:trojan-activity;sid:84762951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899852/; classtype:trojan-activity;sid:84762952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899853/; classtype:trojan-activity;sid:84762953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899854/; classtype:trojan-activity;sid:84762954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899855/; classtype:trojan-activity;sid:84762955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899856/; classtype:trojan-activity;sid:84762956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899857/; classtype:trojan-activity;sid:84762957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899858/; classtype:trojan-activity;sid:84762958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899859/; classtype:trojan-activity;sid:84762959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899860/; classtype:trojan-activity;sid:84762960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899861/; classtype:trojan-activity;sid:84762961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899862/; classtype:trojan-activity;sid:84762962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6af350"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899832/; classtype:trojan-activity;sid:84762932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/607754"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899833/; classtype:trojan-activity;sid:84762933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.sparc"; depth:17; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899834/; classtype:trojan-activity;sid:84762934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/734ef2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899835/; classtype:trojan-activity;sid:84762935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5b5d99"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899836/; classtype:trojan-activity;sid:84762936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b7ecfa"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899837/; classtype:trojan-activity;sid:84762937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9a19b5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899838/; classtype:trojan-activity;sid:84762938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c085b3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899839/; classtype:trojan-activity;sid:84762939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2c5700"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899840/; classtype:trojan-activity;sid:84762940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bae1f5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899841/; classtype:trojan-activity;sid:84762941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1d6369"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899842/; classtype:trojan-activity;sid:84762942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.i686"; depth:16; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899843/; classtype:trojan-activity;sid:84762943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d6b53f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899844/; classtype:trojan-activity;sid:84762944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mips64"; depth:18; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899845/; classtype:trojan-activity;sid:84762945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arc"; depth:15; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899846/; classtype:trojan-activity;sid:84762946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.x86_64"; depth:18; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899847/; classtype:trojan-activity;sid:84762947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d54145"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899848/; classtype:trojan-activity;sid:84762948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899849/; classtype:trojan-activity;sid:84762949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.12.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899831/; classtype:trojan-activity;sid:84762931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.202.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899830/; classtype:trojan-activity;sid:84762930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sysorbit.apk"; depth:13; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899829/; classtype:trojan-activity;sid:84762929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom2.sh"; depth:12; endswith; nocase; http.host; content:"91.92.42.213"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899821/; classtype:trojan-activity;sid:84762921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"41.216.189.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899822/; classtype:trojan-activity;sid:84762922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom.sh"; depth:11; endswith; nocase; http.host; content:"91.92.42.213"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899823/; classtype:trojan-activity;sid:84762923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom1.sh"; depth:12; endswith; nocase; http.host; content:"91.92.42.213"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899824/; classtype:trojan-activity;sid:84762924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"41.216.189.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899825/; classtype:trojan-activity;sid:84762925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"41.216.189.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899826/; classtype:trojan-activity;sid:84762926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.sh"; depth:5; endswith; nocase; http.host; content:"41.216.189.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899827/; classtype:trojan-activity;sid:84762927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.sh"; depth:5; endswith; nocase; http.host; content:"41.216.189.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899828/; classtype:trojan-activity;sid:84762928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.9.22"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899820/; classtype:trojan-activity;sid:84762920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.12.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899819/; classtype:trojan-activity;sid:84762919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.17.89.214"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899818/; classtype:trojan-activity;sid:84762918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.i486"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899817/; classtype:trojan-activity;sid:84762917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.ppc"; depth:10; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899816/; classtype:trojan-activity;sid:84762916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm5"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899813/; classtype:trojan-activity;sid:84762913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.i686"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899814/; classtype:trojan-activity;sid:84762914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.m68k"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899815/; classtype:trojan-activity;sid:84762915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.mips"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899801/; classtype:trojan-activity;sid:84762901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.sh4"; depth:10; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899802/; classtype:trojan-activity;sid:84762902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm6"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899803/; classtype:trojan-activity;sid:84762903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.mpsl"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899804/; classtype:trojan-activity;sid:84762904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm4"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899805/; classtype:trojan-activity;sid:84762905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.x86"; depth:10; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899806/; classtype:trojan-activity;sid:84762906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.mips"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899807/; classtype:trojan-activity;sid:84762907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.m68k"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899808/; classtype:trojan-activity;sid:84762908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm7"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899809/; classtype:trojan-activity;sid:84762909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.ppc440"; depth:13; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899810/; classtype:trojan-activity;sid:84762910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.sh4"; depth:10; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899811/; classtype:trojan-activity;sid:84762911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm5"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899812/; classtype:trojan-activity;sid:84762912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.ppc"; depth:10; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899798/; classtype:trojan-activity;sid:84762898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm7"; depth:11; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899799/; classtype:trojan-activity;sid:84762899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.mpsl"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899800/; classtype:trojan-activity;sid:84762900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.ppc440"; depth:13; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899793/; classtype:trojan-activity;sid:84762893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm4"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899794/; classtype:trojan-activity;sid:84762894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.i486"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899795/; classtype:trojan-activity;sid:84762895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.x86"; depth:10; endswith; nocase; http.host; content:"chaninami123123.duckdns.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899796/; classtype:trojan-activity;sid:84762896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.i686"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899797/; classtype:trojan-activity;sid:84762897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm7"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899787/; classtype:trojan-activity;sid:84762887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.x86"; depth:10; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899788/; classtype:trojan-activity;sid:84762888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.i486"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899789/; classtype:trojan-activity;sid:84762889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.ppc440"; depth:13; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899790/; classtype:trojan-activity;sid:84762890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.i686"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899791/; classtype:trojan-activity;sid:84762891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.mpsl"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899792/; classtype:trojan-activity;sid:84762892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.ppc"; depth:10; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899786/; classtype:trojan-activity;sid:84762886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm6"; depth:11; endswith; nocase; http.host; content:"www.chaninami123123.duckdns.org"; depth:31; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899785/; classtype:trojan-activity;sid:84762885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.m68k"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899781/; classtype:trojan-activity;sid:84762881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.sh4"; depth:10; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899782/; classtype:trojan-activity;sid:84762882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.mips"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899783/; classtype:trojan-activity;sid:84762883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.i686"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899784/; classtype:trojan-activity;sid:84762884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm6"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899778/; classtype:trojan-activity;sid:84762878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm4"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899779/; classtype:trojan-activity;sid:84762879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm5"; depth:11; endswith; nocase; http.host; content:"jam.cleverpondky.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899780/; classtype:trojan-activity;sid:84762880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.ppc440"; depth:13; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899772/; classtype:trojan-activity;sid:84762872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.i486"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899773/; classtype:trojan-activity;sid:84762873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm7"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899774/; classtype:trojan-activity;sid:84762874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.m68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899775/; classtype:trojan-activity;sid:84762875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm6"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899776/; classtype:trojan-activity;sid:84762876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.mpsl"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899777/; classtype:trojan-activity;sid:84762877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm5"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899766/; classtype:trojan-activity;sid:84762866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.x86"; depth:10; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899767/; classtype:trojan-activity;sid:84762867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.sh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899768/; classtype:trojan-activity;sid:84762868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.arm4"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899769/; classtype:trojan-activity;sid:84762869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.mips"; depth:11; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899770/; classtype:trojan-activity;sid:84762870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manji.ppc"; depth:10; endswith; nocase; http.host; content:"94.154.43.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899771/; classtype:trojan-activity;sid:84762871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.252.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899765/; classtype:trojan-activity;sid:84762865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.17.89.214"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899764/; classtype:trojan-activity;sid:84762864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.169.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899763/; classtype:trojan-activity;sid:84762863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.58.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899762/; classtype:trojan-activity;sid:84762862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asset/update.dat"; depth:17; endswith; nocase; http.host; content:"baltos.online"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899761/; classtype:trojan-activity;sid:84762861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s.ps1"; depth:6; endswith; nocase; http.host; content:"104.239.66.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899760/; classtype:trojan-activity;sid:84762860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899759/; classtype:trojan-activity;sid:84762859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.253.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899758/; classtype:trojan-activity;sid:84762858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svchost.exe"; depth:12; endswith; nocase; http.host; content:"217.60.241.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899757/; classtype:trojan-activity;sid:84762857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/screenconnect.clientsetup.exe"; depth:30; endswith; nocase; http.host; content:"130.12.180.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899756/; classtype:trojan-activity;sid:84762856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/screenconnect.clientsetup.exe"; depth:30; endswith; nocase; http.host; content:"130.12.180.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899755/; classtype:trojan-activity;sid:84762855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899754/; classtype:trojan-activity;sid:84762854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arm6"; depth:13; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899752/; classtype:trojan-activity;sid:84762852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arm"; depth:12; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899753/; classtype:trojan-activity;sid:84762853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.mips"; depth:13; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899748/; classtype:trojan-activity;sid:84762848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.sh4"; depth:12; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899749/; classtype:trojan-activity;sid:84762849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arm5"; depth:13; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899750/; classtype:trojan-activity;sid:84762850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.x86"; depth:12; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899751/; classtype:trojan-activity;sid:84762851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.m68k"; depth:13; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899745/; classtype:trojan-activity;sid:84762845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.ppc"; depth:12; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899746/; classtype:trojan-activity;sid:84762846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.spc"; depth:12; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899747/; classtype:trojan-activity;sid:84762847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arm7"; depth:13; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899742/; classtype:trojan-activity;sid:84762842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arm5"; depth:13; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899743/; classtype:trojan-activity;sid:84762843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.mpsl"; depth:13; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899744/; classtype:trojan-activity;sid:84762844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arc"; depth:12; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899740/; classtype:trojan-activity;sid:84762840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arm7"; depth:13; endswith; nocase; http.host; content:"reavercncv4.duckdns.org"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899741/; classtype:trojan-activity;sid:84762841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.mpsl"; depth:13; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899739/; classtype:trojan-activity;sid:84762839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.mips"; depth:13; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899728/; classtype:trojan-activity;sid:84762828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arm"; depth:12; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899729/; classtype:trojan-activity;sid:84762829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.ppc"; depth:12; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899730/; classtype:trojan-activity;sid:84762830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.sh4"; depth:12; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899731/; classtype:trojan-activity;sid:84762831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.x86"; depth:12; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899732/; classtype:trojan-activity;sid:84762832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899733/; classtype:trojan-activity;sid:84762833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.spc"; depth:12; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899734/; classtype:trojan-activity;sid:84762834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arm6"; depth:13; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899735/; classtype:trojan-activity;sid:84762835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.arc"; depth:12; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899736/; classtype:trojan-activity;sid:84762836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boatnet.m68k"; depth:13; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899737/; classtype:trojan-activity;sid:84762837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.169.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899738/; classtype:trojan-activity;sid:84762838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899727/; classtype:trojan-activity;sid:84762827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899726/; classtype:trojan-activity;sid:84762826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899724/; classtype:trojan-activity;sid:84762824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899725/; classtype:trojan-activity;sid:84762825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i486"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899715/; classtype:trojan-activity;sid:84762815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899716/; classtype:trojan-activity;sid:84762816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899717/; classtype:trojan-activity;sid:84762817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899718/; classtype:trojan-activity;sid:84762818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899719/; classtype:trojan-activity;sid:84762819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i486"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899720/; classtype:trojan-activity;sid:84762820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc440"; depth:7; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899721/; classtype:trojan-activity;sid:84762821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899722/; classtype:trojan-activity;sid:84762822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc440"; depth:7; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899723/; classtype:trojan-activity;sid:84762823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899714/; classtype:trojan-activity;sid:84762814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899713/; classtype:trojan-activity;sid:84762813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899710/; classtype:trojan-activity;sid:84762810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899711/; classtype:trojan-activity;sid:84762811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899712/; classtype:trojan-activity;sid:84762812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899701/; classtype:trojan-activity;sid:84762801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899702/; classtype:trojan-activity;sid:84762802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899703/; classtype:trojan-activity;sid:84762803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899704/; classtype:trojan-activity;sid:84762804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899705/; classtype:trojan-activity;sid:84762805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899706/; classtype:trojan-activity;sid:84762806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899707/; classtype:trojan-activity;sid:84762807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899708/; classtype:trojan-activity;sid:84762808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899709/; classtype:trojan-activity;sid:84762809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899700/; classtype:trojan-activity;sid:84762800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"load.dstat.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899699/; classtype:trojan-activity;sid:84762799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899697/; classtype:trojan-activity;sid:84762797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"oregano.brightleafrv.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899698/; classtype:trojan-activity;sid:84762798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899693/; classtype:trojan-activity;sid:84762793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899694/; classtype:trojan-activity;sid:84762794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899695/; classtype:trojan-activity;sid:84762795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899696/; classtype:trojan-activity;sid:84762796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899682/; classtype:trojan-activity;sid:84762782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899683/; classtype:trojan-activity;sid:84762783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899684/; classtype:trojan-activity;sid:84762784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899685/; classtype:trojan-activity;sid:84762785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i486"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899686/; classtype:trojan-activity;sid:84762786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899687/; classtype:trojan-activity;sid:84762787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899688/; classtype:trojan-activity;sid:84762788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899689/; classtype:trojan-activity;sid:84762789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899690/; classtype:trojan-activity;sid:84762790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc440"; depth:7; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899691/; classtype:trojan-activity;sid:84762791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899692/; classtype:trojan-activity;sid:84762792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899681/; classtype:trojan-activity;sid:84762781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"31.173.12.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899680/; classtype:trojan-activity;sid:84762780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899678/; classtype:trojan-activity;sid:84762778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/l"; depth:2; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899679/; classtype:trojan-activity;sid:84762779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.138.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899677/; classtype:trojan-activity;sid:84762777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/id/id/connectproagentsetup.msi"; depth:31; endswith; nocase; http.host; content:"45.154.98.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899676/; classtype:trojan-activity;sid:84762776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/id/connectproagentsetup.msi"; depth:28; endswith; nocase; http.host; content:"45.154.98.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899675/; classtype:trojan-activity;sid:84762775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.sh4"; depth:15; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899674/; classtype:trojan-activity;sid:84762774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.177.244.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899673/; classtype:trojan-activity;sid:84762773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.177.244.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899672/; classtype:trojan-activity;sid:84762772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"89.165.130.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899671/; classtype:trojan-activity;sid:84762771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm6"; depth:16; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899670/; classtype:trojan-activity;sid:84762770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899669/; classtype:trojan-activity;sid:84762769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mpsl"; depth:16; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899668/; classtype:trojan-activity;sid:84762768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.m68k"; depth:16; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899667/; classtype:trojan-activity;sid:84762767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mpsl"; depth:16; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899665/; classtype:trojan-activity;sid:84762765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.x86"; depth:15; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899666/; classtype:trojan-activity;sid:84762766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899664/; classtype:trojan-activity;sid:84762764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm5"; depth:16; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899663/; classtype:trojan-activity;sid:84762763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899661/; classtype:trojan-activity;sid:84762761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.x86"; depth:15; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899662/; classtype:trojan-activity;sid:84762762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mips"; depth:16; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899660/; classtype:trojan-activity;sid:84762760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm"; depth:15; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899652/; classtype:trojan-activity;sid:84762752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.ppc"; depth:15; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899653/; classtype:trojan-activity;sid:84762753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.spc"; depth:15; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899654/; classtype:trojan-activity;sid:84762754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.m68k"; depth:16; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899655/; classtype:trojan-activity;sid:84762755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm6"; depth:16; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899656/; classtype:trojan-activity;sid:84762756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899657/; classtype:trojan-activity;sid:84762757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm7"; depth:16; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899658/; classtype:trojan-activity;sid:84762758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.x86"; depth:15; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899659/; classtype:trojan-activity;sid:84762759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm"; depth:15; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899650/; classtype:trojan-activity;sid:84762750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm5"; depth:16; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899651/; classtype:trojan-activity;sid:84762751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mips"; depth:16; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899645/; classtype:trojan-activity;sid:84762745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm"; depth:15; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899646/; classtype:trojan-activity;sid:84762746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mips"; depth:16; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899647/; classtype:trojan-activity;sid:84762747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.sh4"; depth:15; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899648/; classtype:trojan-activity;sid:84762748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.sh4"; depth:15; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899649/; classtype:trojan-activity;sid:84762749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.ppc"; depth:15; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899636/; classtype:trojan-activity;sid:84762736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.spc"; depth:15; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899637/; classtype:trojan-activity;sid:84762737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm6"; depth:16; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899638/; classtype:trojan-activity;sid:84762738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.spc"; depth:15; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899639/; classtype:trojan-activity;sid:84762739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.ppc"; depth:15; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899640/; classtype:trojan-activity;sid:84762740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.ppc"; depth:15; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899641/; classtype:trojan-activity;sid:84762741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899642/; classtype:trojan-activity;sid:84762742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mips"; depth:16; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899643/; classtype:trojan-activity;sid:84762743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm"; depth:15; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899644/; classtype:trojan-activity;sid:84762744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.m68k"; depth:16; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899627/; classtype:trojan-activity;sid:84762727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm7"; depth:16; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899628/; classtype:trojan-activity;sid:84762728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899629/; classtype:trojan-activity;sid:84762729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mpsl"; depth:16; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899630/; classtype:trojan-activity;sid:84762730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm7"; depth:16; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899631/; classtype:trojan-activity;sid:84762731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.spc"; depth:15; endswith; nocase; http.host; content:"mail.springnetpm.pro"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899632/; classtype:trojan-activity;sid:84762732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm5"; depth:16; endswith; nocase; http.host; content:"94.154.43.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899633/; classtype:trojan-activity;sid:84762733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm6"; depth:16; endswith; nocase; http.host; content:"springnetpm.pro"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899634/; classtype:trojan-activity;sid:84762734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.mpsl"; depth:16; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899635/; classtype:trojan-activity;sid:84762735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm5"; depth:16; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899625/; classtype:trojan-activity;sid:84762725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.x86"; depth:15; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899626/; classtype:trojan-activity;sid:84762726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.sh4"; depth:15; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899622/; classtype:trojan-activity;sid:84762722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.arm7"; depth:16; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899623/; classtype:trojan-activity;sid:84762723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/david.m68k"; depth:16; endswith; nocase; http.host; content:"utensil.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899624/; classtype:trojan-activity;sid:84762724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899618/; classtype:trojan-activity;sid:84762718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899619/; classtype:trojan-activity;sid:84762719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899620/; classtype:trojan-activity;sid:84762720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899621/; classtype:trojan-activity;sid:84762721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899617/; classtype:trojan-activity;sid:84762717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899612/; classtype:trojan-activity;sid:84762712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899613/; classtype:trojan-activity;sid:84762713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899614/; classtype:trojan-activity;sid:84762714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899615/; classtype:trojan-activity;sid:84762715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899616/; classtype:trojan-activity;sid:84762716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899604/; classtype:trojan-activity;sid:84762704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899605/; classtype:trojan-activity;sid:84762705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899606/; classtype:trojan-activity;sid:84762706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899607/; classtype:trojan-activity;sid:84762707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899608/; classtype:trojan-activity;sid:84762708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899609/; classtype:trojan-activity;sid:84762709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899610/; classtype:trojan-activity;sid:84762710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899611/; classtype:trojan-activity;sid:84762711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899603/; classtype:trojan-activity;sid:84762703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899601/; classtype:trojan-activity;sid:84762701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899602/; classtype:trojan-activity;sid:84762702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899598/; classtype:trojan-activity;sid:84762698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899599/; classtype:trojan-activity;sid:84762699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899600/; classtype:trojan-activity;sid:84762700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899597/; classtype:trojan-activity;sid:84762697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899596/; classtype:trojan-activity;sid:84762696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899594/; classtype:trojan-activity;sid:84762694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899595/; classtype:trojan-activity;sid:84762695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899593/; classtype:trojan-activity;sid:84762693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899592/; classtype:trojan-activity;sid:84762692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899586/; classtype:trojan-activity;sid:84762686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899587/; classtype:trojan-activity;sid:84762687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899588/; classtype:trojan-activity;sid:84762688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899589/; classtype:trojan-activity;sid:84762689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899590/; classtype:trojan-activity;sid:84762690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899591/; classtype:trojan-activity;sid:84762691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899582/; classtype:trojan-activity;sid:84762682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899583/; classtype:trojan-activity;sid:84762683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899584/; classtype:trojan-activity;sid:84762684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899585/; classtype:trojan-activity;sid:84762685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899580/; classtype:trojan-activity;sid:84762680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899581/; classtype:trojan-activity;sid:84762681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899579/; classtype:trojan-activity;sid:84762679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899575/; classtype:trojan-activity;sid:84762675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899576/; classtype:trojan-activity;sid:84762676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899577/; classtype:trojan-activity;sid:84762677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899578/; classtype:trojan-activity;sid:84762678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899574/; classtype:trojan-activity;sid:84762674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899569/; classtype:trojan-activity;sid:84762669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899570/; classtype:trojan-activity;sid:84762670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899571/; classtype:trojan-activity;sid:84762671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899572/; classtype:trojan-activity;sid:84762672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899573/; classtype:trojan-activity;sid:84762673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899554/; classtype:trojan-activity;sid:84762654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899555/; classtype:trojan-activity;sid:84762655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899556/; classtype:trojan-activity;sid:84762656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899557/; classtype:trojan-activity;sid:84762657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899558/; classtype:trojan-activity;sid:84762658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899559/; classtype:trojan-activity;sid:84762659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899560/; classtype:trojan-activity;sid:84762660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899561/; classtype:trojan-activity;sid:84762661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899562/; classtype:trojan-activity;sid:84762662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899563/; classtype:trojan-activity;sid:84762663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899564/; classtype:trojan-activity;sid:84762664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899565/; classtype:trojan-activity;sid:84762665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899566/; classtype:trojan-activity;sid:84762666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899567/; classtype:trojan-activity;sid:84762667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899568/; classtype:trojan-activity;sid:84762668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899553/; classtype:trojan-activity;sid:84762653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899551/; classtype:trojan-activity;sid:84762651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899552/; classtype:trojan-activity;sid:84762652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899549/; classtype:trojan-activity;sid:84762649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899550/; classtype:trojan-activity;sid:84762650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899545/; classtype:trojan-activity;sid:84762645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899546/; classtype:trojan-activity;sid:84762646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899547/; classtype:trojan-activity;sid:84762647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899548/; classtype:trojan-activity;sid:84762648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899541/; classtype:trojan-activity;sid:84762641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899542/; classtype:trojan-activity;sid:84762642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899543/; classtype:trojan-activity;sid:84762643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899544/; classtype:trojan-activity;sid:84762644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899539/; classtype:trojan-activity;sid:84762639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899540/; classtype:trojan-activity;sid:84762640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899538/; classtype:trojan-activity;sid:84762638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899535/; classtype:trojan-activity;sid:84762635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899536/; classtype:trojan-activity;sid:84762636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899537/; classtype:trojan-activity;sid:84762637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899529/; classtype:trojan-activity;sid:84762629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899530/; classtype:trojan-activity;sid:84762630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899531/; classtype:trojan-activity;sid:84762631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899532/; classtype:trojan-activity;sid:84762632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899533/; classtype:trojan-activity;sid:84762633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899534/; classtype:trojan-activity;sid:84762634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899516/; classtype:trojan-activity;sid:84762616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899517/; classtype:trojan-activity;sid:84762617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899518/; classtype:trojan-activity;sid:84762618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899519/; classtype:trojan-activity;sid:84762619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899520/; classtype:trojan-activity;sid:84762620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899521/; classtype:trojan-activity;sid:84762621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899522/; classtype:trojan-activity;sid:84762622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899523/; classtype:trojan-activity;sid:84762623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899524/; classtype:trojan-activity;sid:84762624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899525/; classtype:trojan-activity;sid:84762625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899526/; classtype:trojan-activity;sid:84762626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899527/; classtype:trojan-activity;sid:84762627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899528/; classtype:trojan-activity;sid:84762628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899513/; classtype:trojan-activity;sid:84762613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899514/; classtype:trojan-activity;sid:84762614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899515/; classtype:trojan-activity;sid:84762615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899511/; classtype:trojan-activity;sid:84762611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899512/; classtype:trojan-activity;sid:84762612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899510/; classtype:trojan-activity;sid:84762610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899506/; classtype:trojan-activity;sid:84762606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899507/; classtype:trojan-activity;sid:84762607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899508/; classtype:trojan-activity;sid:84762608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899509/; classtype:trojan-activity;sid:84762609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899505/; classtype:trojan-activity;sid:84762605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899504/; classtype:trojan-activity;sid:84762604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899498/; classtype:trojan-activity;sid:84762598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899499/; classtype:trojan-activity;sid:84762599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899500/; classtype:trojan-activity;sid:84762600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899501/; classtype:trojan-activity;sid:84762601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899502/; classtype:trojan-activity;sid:84762602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899503/; classtype:trojan-activity;sid:84762603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899485/; classtype:trojan-activity;sid:84762585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899486/; classtype:trojan-activity;sid:84762586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899487/; classtype:trojan-activity;sid:84762587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899488/; classtype:trojan-activity;sid:84762588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899489/; classtype:trojan-activity;sid:84762589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899490/; classtype:trojan-activity;sid:84762590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899491/; classtype:trojan-activity;sid:84762591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899492/; classtype:trojan-activity;sid:84762592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899493/; classtype:trojan-activity;sid:84762593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899494/; classtype:trojan-activity;sid:84762594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899495/; classtype:trojan-activity;sid:84762595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899496/; classtype:trojan-activity;sid:84762596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899497/; classtype:trojan-activity;sid:84762597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899484/; classtype:trojan-activity;sid:84762584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899483/; classtype:trojan-activity;sid:84762583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899482/; classtype:trojan-activity;sid:84762582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899480/; classtype:trojan-activity;sid:84762580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899481/; classtype:trojan-activity;sid:84762581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899479/; classtype:trojan-activity;sid:84762579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899477/; classtype:trojan-activity;sid:84762577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899478/; classtype:trojan-activity;sid:84762578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899476/; classtype:trojan-activity;sid:84762576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899464/; classtype:trojan-activity;sid:84762564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899465/; classtype:trojan-activity;sid:84762565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899466/; classtype:trojan-activity;sid:84762566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899467/; classtype:trojan-activity;sid:84762567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899468/; classtype:trojan-activity;sid:84762568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899469/; classtype:trojan-activity;sid:84762569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899470/; classtype:trojan-activity;sid:84762570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899471/; classtype:trojan-activity;sid:84762571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899472/; classtype:trojan-activity;sid:84762572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899473/; classtype:trojan-activity;sid:84762573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899474/; classtype:trojan-activity;sid:84762574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899475/; classtype:trojan-activity;sid:84762575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899463/; classtype:trojan-activity;sid:84762563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899461/; classtype:trojan-activity;sid:84762561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899462/; classtype:trojan-activity;sid:84762562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899458/; classtype:trojan-activity;sid:84762558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899459/; classtype:trojan-activity;sid:84762559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899460/; classtype:trojan-activity;sid:84762560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899456/; classtype:trojan-activity;sid:84762556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899457/; classtype:trojan-activity;sid:84762557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899455/; classtype:trojan-activity;sid:84762555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899443/; classtype:trojan-activity;sid:84762543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899444/; classtype:trojan-activity;sid:84762544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899445/; classtype:trojan-activity;sid:84762545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899446/; classtype:trojan-activity;sid:84762546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899447/; classtype:trojan-activity;sid:84762547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899448/; classtype:trojan-activity;sid:84762548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899449/; classtype:trojan-activity;sid:84762549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899450/; classtype:trojan-activity;sid:84762550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899451/; classtype:trojan-activity;sid:84762551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899452/; classtype:trojan-activity;sid:84762552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899453/; classtype:trojan-activity;sid:84762553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899454/; classtype:trojan-activity;sid:84762554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899441/; classtype:trojan-activity;sid:84762541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899442/; classtype:trojan-activity;sid:84762542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899440/; classtype:trojan-activity;sid:84762540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899439/; classtype:trojan-activity;sid:84762539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899437/; classtype:trojan-activity;sid:84762537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899438/; classtype:trojan-activity;sid:84762538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899433/; classtype:trojan-activity;sid:84762533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899434/; classtype:trojan-activity;sid:84762534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899435/; classtype:trojan-activity;sid:84762535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899436/; classtype:trojan-activity;sid:84762536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899429/; classtype:trojan-activity;sid:84762529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899430/; classtype:trojan-activity;sid:84762530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899431/; classtype:trojan-activity;sid:84762531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899432/; classtype:trojan-activity;sid:84762532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899415/; classtype:trojan-activity;sid:84762515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899416/; classtype:trojan-activity;sid:84762516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899417/; classtype:trojan-activity;sid:84762517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899418/; classtype:trojan-activity;sid:84762518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899419/; classtype:trojan-activity;sid:84762519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899420/; classtype:trojan-activity;sid:84762520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899421/; classtype:trojan-activity;sid:84762521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899422/; classtype:trojan-activity;sid:84762522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899423/; classtype:trojan-activity;sid:84762523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899424/; classtype:trojan-activity;sid:84762524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899425/; classtype:trojan-activity;sid:84762525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899426/; classtype:trojan-activity;sid:84762526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899427/; classtype:trojan-activity;sid:84762527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899428/; classtype:trojan-activity;sid:84762528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899414/; classtype:trojan-activity;sid:84762514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899409/; classtype:trojan-activity;sid:84762509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899410/; classtype:trojan-activity;sid:84762510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899411/; classtype:trojan-activity;sid:84762511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899412/; classtype:trojan-activity;sid:84762512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899413/; classtype:trojan-activity;sid:84762513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899408/; classtype:trojan-activity;sid:84762508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899406/; classtype:trojan-activity;sid:84762506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899407/; classtype:trojan-activity;sid:84762507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899404/; classtype:trojan-activity;sid:84762504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899405/; classtype:trojan-activity;sid:84762505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899403/; classtype:trojan-activity;sid:84762503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899384/; classtype:trojan-activity;sid:84762484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899385/; classtype:trojan-activity;sid:84762485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899386/; classtype:trojan-activity;sid:84762486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899387/; classtype:trojan-activity;sid:84762487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899388/; classtype:trojan-activity;sid:84762488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899389/; classtype:trojan-activity;sid:84762489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899390/; classtype:trojan-activity;sid:84762490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899391/; classtype:trojan-activity;sid:84762491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899392/; classtype:trojan-activity;sid:84762492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899393/; classtype:trojan-activity;sid:84762493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899394/; classtype:trojan-activity;sid:84762494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899395/; classtype:trojan-activity;sid:84762495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899396/; classtype:trojan-activity;sid:84762496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"smartsummitlo.pro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899397/; classtype:trojan-activity;sid:84762497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899398/; classtype:trojan-activity;sid:84762498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899399/; classtype:trojan-activity;sid:84762499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899400/; classtype:trojan-activity;sid:84762500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899401/; classtype:trojan-activity;sid:84762501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899402/; classtype:trojan-activity;sid:84762502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899382/; classtype:trojan-activity;sid:84762482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899383/; classtype:trojan-activity;sid:84762483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899381/; classtype:trojan-activity;sid:84762481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899376/; classtype:trojan-activity;sid:84762476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899377/; classtype:trojan-activity;sid:84762477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899378/; classtype:trojan-activity;sid:84762478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899379/; classtype:trojan-activity;sid:84762479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899380/; classtype:trojan-activity;sid:84762480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899365/; classtype:trojan-activity;sid:84762465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899366/; classtype:trojan-activity;sid:84762466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899367/; classtype:trojan-activity;sid:84762467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899368/; classtype:trojan-activity;sid:84762468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899369/; classtype:trojan-activity;sid:84762469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899370/; classtype:trojan-activity;sid:84762470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899371/; classtype:trojan-activity;sid:84762471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899372/; classtype:trojan-activity;sid:84762472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899373/; classtype:trojan-activity;sid:84762473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899374/; classtype:trojan-activity;sid:84762474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899375/; classtype:trojan-activity;sid:84762475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"ssh.microc2.lol"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899364/; classtype:trojan-activity;sid:84762464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899363/; classtype:trojan-activity;sid:84762463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899360/; classtype:trojan-activity;sid:84762460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899361/; classtype:trojan-activity;sid:84762461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899362/; classtype:trojan-activity;sid:84762462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899358/; classtype:trojan-activity;sid:84762458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899359/; classtype:trojan-activity;sid:84762459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899357/; classtype:trojan-activity;sid:84762457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899356/; classtype:trojan-activity;sid:84762456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899341/; classtype:trojan-activity;sid:84762441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899342/; classtype:trojan-activity;sid:84762442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899343/; classtype:trojan-activity;sid:84762443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899344/; classtype:trojan-activity;sid:84762444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899345/; classtype:trojan-activity;sid:84762445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899346/; classtype:trojan-activity;sid:84762446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899347/; classtype:trojan-activity;sid:84762447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899348/; classtype:trojan-activity;sid:84762448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899349/; classtype:trojan-activity;sid:84762449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899350/; classtype:trojan-activity;sid:84762450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899351/; classtype:trojan-activity;sid:84762451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899352/; classtype:trojan-activity;sid:84762452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899353/; classtype:trojan-activity;sid:84762453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899354/; classtype:trojan-activity;sid:84762454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899355/; classtype:trojan-activity;sid:84762455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899340/; classtype:trojan-activity;sid:84762440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899333/; classtype:trojan-activity;sid:84762433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899334/; classtype:trojan-activity;sid:84762434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899335/; classtype:trojan-activity;sid:84762435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899336/; classtype:trojan-activity;sid:84762436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899337/; classtype:trojan-activity;sid:84762437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899338/; classtype:trojan-activity;sid:84762438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899339/; classtype:trojan-activity;sid:84762439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899329/; classtype:trojan-activity;sid:84762429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899330/; classtype:trojan-activity;sid:84762430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899331/; classtype:trojan-activity;sid:84762431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899332/; classtype:trojan-activity;sid:84762432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899326/; classtype:trojan-activity;sid:84762426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899327/; classtype:trojan-activity;sid:84762427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899328/; classtype:trojan-activity;sid:84762428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899322/; classtype:trojan-activity;sid:84762422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899323/; classtype:trojan-activity;sid:84762423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899324/; classtype:trojan-activity;sid:84762424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899325/; classtype:trojan-activity;sid:84762425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899319/; classtype:trojan-activity;sid:84762419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899320/; classtype:trojan-activity;sid:84762420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899321/; classtype:trojan-activity;sid:84762421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899318/; classtype:trojan-activity;sid:84762418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.125"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899315/; classtype:trojan-activity;sid:84762415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899316/; classtype:trojan-activity;sid:84762416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"coralwebqe.help"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899317/; classtype:trojan-activity;sid:84762417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.18.9.255"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899314/; classtype:trojan-activity;sid:84762414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.210.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899313/; classtype:trojan-activity;sid:84762413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_f5aca509ea370844.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899312/; classtype:trojan-activity;sid:84762412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"89.165.130.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899311/; classtype:trojan-activity;sid:84762411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899305/; classtype:trojan-activity;sid:84762405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899306/; classtype:trojan-activity;sid:84762406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899307/; classtype:trojan-activity;sid:84762407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899308/; classtype:trojan-activity;sid:84762408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899309/; classtype:trojan-activity;sid:84762409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899310/; classtype:trojan-activity;sid:84762410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899304/; classtype:trojan-activity;sid:84762404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899303/; classtype:trojan-activity;sid:84762403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899302/; classtype:trojan-activity;sid:84762402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899301/; classtype:trojan-activity;sid:84762401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899299/; classtype:trojan-activity;sid:84762399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899300/; classtype:trojan-activity;sid:84762400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899297/; classtype:trojan-activity;sid:84762397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899298/; classtype:trojan-activity;sid:84762398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899293/; classtype:trojan-activity;sid:84762393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899294/; classtype:trojan-activity;sid:84762394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899295/; classtype:trojan-activity;sid:84762395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899296/; classtype:trojan-activity;sid:84762396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899291/; classtype:trojan-activity;sid:84762391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899292/; classtype:trojan-activity;sid:84762392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899289/; classtype:trojan-activity;sid:84762389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899290/; classtype:trojan-activity;sid:84762390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899286/; classtype:trojan-activity;sid:84762386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899287/; classtype:trojan-activity;sid:84762387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899288/; classtype:trojan-activity;sid:84762388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899285/; classtype:trojan-activity;sid:84762385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899279/; classtype:trojan-activity;sid:84762379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899280/; classtype:trojan-activity;sid:84762380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899281/; classtype:trojan-activity;sid:84762381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899282/; classtype:trojan-activity;sid:84762382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899283/; classtype:trojan-activity;sid:84762383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899284/; classtype:trojan-activity;sid:84762384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899266/; classtype:trojan-activity;sid:84762366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899267/; classtype:trojan-activity;sid:84762367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899268/; classtype:trojan-activity;sid:84762368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899269/; classtype:trojan-activity;sid:84762369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899270/; classtype:trojan-activity;sid:84762370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899271/; classtype:trojan-activity;sid:84762371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899272/; classtype:trojan-activity;sid:84762372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899273/; classtype:trojan-activity;sid:84762373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899274/; classtype:trojan-activity;sid:84762374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899275/; classtype:trojan-activity;sid:84762375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899276/; classtype:trojan-activity;sid:84762376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899277/; classtype:trojan-activity;sid:84762377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899278/; classtype:trojan-activity;sid:84762378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899263/; classtype:trojan-activity;sid:84762363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899264/; classtype:trojan-activity;sid:84762364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899265/; classtype:trojan-activity;sid:84762365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899262/; classtype:trojan-activity;sid:84762362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899260/; classtype:trojan-activity;sid:84762360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899261/; classtype:trojan-activity;sid:84762361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899258/; classtype:trojan-activity;sid:84762358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.65.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899259/; classtype:trojan-activity;sid:84762359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899254/; classtype:trojan-activity;sid:84762354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899255/; classtype:trojan-activity;sid:84762355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899256/; classtype:trojan-activity;sid:84762356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899257/; classtype:trojan-activity;sid:84762357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899252/; classtype:trojan-activity;sid:84762352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899253/; classtype:trojan-activity;sid:84762353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899251/; classtype:trojan-activity;sid:84762351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899245/; classtype:trojan-activity;sid:84762345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899246/; classtype:trojan-activity;sid:84762346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899247/; classtype:trojan-activity;sid:84762347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899248/; classtype:trojan-activity;sid:84762348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899249/; classtype:trojan-activity;sid:84762349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"arcade.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899250/; classtype:trojan-activity;sid:84762350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/locopoco"; depth:9; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899244/; classtype:trojan-activity;sid:84762344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899243/; classtype:trojan-activity;sid:84762343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899242/; classtype:trojan-activity;sid:84762342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899241/; classtype:trojan-activity;sid:84762341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.116.152.6"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899240/; classtype:trojan-activity;sid:84762340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899236/; classtype:trojan-activity;sid:84762336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899237/; classtype:trojan-activity;sid:84762337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899238/; classtype:trojan-activity;sid:84762338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899239/; classtype:trojan-activity;sid:84762339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899235/; classtype:trojan-activity;sid:84762335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899231/; classtype:trojan-activity;sid:84762331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899232/; classtype:trojan-activity;sid:84762332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899233/; classtype:trojan-activity;sid:84762333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899234/; classtype:trojan-activity;sid:84762334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899224/; classtype:trojan-activity;sid:84762324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899225/; classtype:trojan-activity;sid:84762325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899226/; classtype:trojan-activity;sid:84762326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899227/; classtype:trojan-activity;sid:84762327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899228/; classtype:trojan-activity;sid:84762328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899229/; classtype:trojan-activity;sid:84762329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899230/; classtype:trojan-activity;sid:84762330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899223/; classtype:trojan-activity;sid:84762323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899216/; classtype:trojan-activity;sid:84762316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899217/; classtype:trojan-activity;sid:84762317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899218/; classtype:trojan-activity;sid:84762318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899219/; classtype:trojan-activity;sid:84762319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899220/; classtype:trojan-activity;sid:84762320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899221/; classtype:trojan-activity;sid:84762321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899222/; classtype:trojan-activity;sid:84762322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899215/; classtype:trojan-activity;sid:84762315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899211/; classtype:trojan-activity;sid:84762311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899212/; classtype:trojan-activity;sid:84762312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899213/; classtype:trojan-activity;sid:84762313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899214/; classtype:trojan-activity;sid:84762314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899207/; classtype:trojan-activity;sid:84762307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899208/; classtype:trojan-activity;sid:84762308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899209/; classtype:trojan-activity;sid:84762309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899210/; classtype:trojan-activity;sid:84762310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899204/; classtype:trojan-activity;sid:84762304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899205/; classtype:trojan-activity;sid:84762305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899206/; classtype:trojan-activity;sid:84762306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.210.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899203/; classtype:trojan-activity;sid:84762303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899201/; classtype:trojan-activity;sid:84762301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899202/; classtype:trojan-activity;sid:84762302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899189/; classtype:trojan-activity;sid:84762289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899190/; classtype:trojan-activity;sid:84762290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899191/; classtype:trojan-activity;sid:84762291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899192/; classtype:trojan-activity;sid:84762292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899193/; classtype:trojan-activity;sid:84762293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899194/; classtype:trojan-activity;sid:84762294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899195/; classtype:trojan-activity;sid:84762295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899196/; classtype:trojan-activity;sid:84762296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899197/; classtype:trojan-activity;sid:84762297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899198/; classtype:trojan-activity;sid:84762298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899199/; classtype:trojan-activity;sid:84762299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899200/; classtype:trojan-activity;sid:84762300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899188/; classtype:trojan-activity;sid:84762288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899187/; classtype:trojan-activity;sid:84762287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899185/; classtype:trojan-activity;sid:84762285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899186/; classtype:trojan-activity;sid:84762286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899184/; classtype:trojan-activity;sid:84762284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899183/; classtype:trojan-activity;sid:84762283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899175/; classtype:trojan-activity;sid:84762275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899176/; classtype:trojan-activity;sid:84762276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899177/; classtype:trojan-activity;sid:84762277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899178/; classtype:trojan-activity;sid:84762278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899179/; classtype:trojan-activity;sid:84762279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899180/; classtype:trojan-activity;sid:84762280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899181/; classtype:trojan-activity;sid:84762281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899182/; classtype:trojan-activity;sid:84762282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899174/; classtype:trojan-activity;sid:84762274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899171/; classtype:trojan-activity;sid:84762271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899172/; classtype:trojan-activity;sid:84762272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899173/; classtype:trojan-activity;sid:84762273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899166/; classtype:trojan-activity;sid:84762266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899167/; classtype:trojan-activity;sid:84762267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899168/; classtype:trojan-activity;sid:84762268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899169/; classtype:trojan-activity;sid:84762269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899170/; classtype:trojan-activity;sid:84762270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899164/; classtype:trojan-activity;sid:84762264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899165/; classtype:trojan-activity;sid:84762265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899162/; classtype:trojan-activity;sid:84762262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899163/; classtype:trojan-activity;sid:84762263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899161/; classtype:trojan-activity;sid:84762261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899158/; classtype:trojan-activity;sid:84762258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899159/; classtype:trojan-activity;sid:84762259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899160/; classtype:trojan-activity;sid:84762260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899143/; classtype:trojan-activity;sid:84762243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899144/; classtype:trojan-activity;sid:84762244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899145/; classtype:trojan-activity;sid:84762245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899146/; classtype:trojan-activity;sid:84762246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899147/; classtype:trojan-activity;sid:84762247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899148/; classtype:trojan-activity;sid:84762248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899149/; classtype:trojan-activity;sid:84762249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899150/; classtype:trojan-activity;sid:84762250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899151/; classtype:trojan-activity;sid:84762251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899152/; classtype:trojan-activity;sid:84762252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899153/; classtype:trojan-activity;sid:84762253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899154/; classtype:trojan-activity;sid:84762254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899155/; classtype:trojan-activity;sid:84762255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899156/; classtype:trojan-activity;sid:84762256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899157/; classtype:trojan-activity;sid:84762257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899141/; classtype:trojan-activity;sid:84762241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899142/; classtype:trojan-activity;sid:84762242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899138/; classtype:trojan-activity;sid:84762238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899139/; classtype:trojan-activity;sid:84762239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899140/; classtype:trojan-activity;sid:84762240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899136/; classtype:trojan-activity;sid:84762236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899137/; classtype:trojan-activity;sid:84762237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899135/; classtype:trojan-activity;sid:84762235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899134/; classtype:trojan-activity;sid:84762234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899131/; classtype:trojan-activity;sid:84762231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899132/; classtype:trojan-activity;sid:84762232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899133/; classtype:trojan-activity;sid:84762233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899130/; classtype:trojan-activity;sid:84762230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899129/; classtype:trojan-activity;sid:84762229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.39.32"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899128/; classtype:trojan-activity;sid:84762228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899122/; classtype:trojan-activity;sid:84762222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899123/; classtype:trojan-activity;sid:84762223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899124/; classtype:trojan-activity;sid:84762224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899125/; classtype:trojan-activity;sid:84762225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899126/; classtype:trojan-activity;sid:84762226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899127/; classtype:trojan-activity;sid:84762227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899116/; classtype:trojan-activity;sid:84762216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899117/; classtype:trojan-activity;sid:84762217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899118/; classtype:trojan-activity;sid:84762218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899119/; classtype:trojan-activity;sid:84762219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899120/; classtype:trojan-activity;sid:84762220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899121/; classtype:trojan-activity;sid:84762221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899115/; classtype:trojan-activity;sid:84762215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899114/; classtype:trojan-activity;sid:84762214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899099/; classtype:trojan-activity;sid:84762199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899100/; classtype:trojan-activity;sid:84762200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899101/; classtype:trojan-activity;sid:84762201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899102/; classtype:trojan-activity;sid:84762202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899103/; classtype:trojan-activity;sid:84762203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899104/; classtype:trojan-activity;sid:84762204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899105/; classtype:trojan-activity;sid:84762205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899106/; classtype:trojan-activity;sid:84762206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899107/; classtype:trojan-activity;sid:84762207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899108/; classtype:trojan-activity;sid:84762208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899109/; classtype:trojan-activity;sid:84762209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899110/; classtype:trojan-activity;sid:84762210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899111/; classtype:trojan-activity;sid:84762211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899112/; classtype:trojan-activity;sid:84762212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"mail.silverrockay.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899113/; classtype:trojan-activity;sid:84762213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.172.218.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899098/; classtype:trojan-activity;sid:84762198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899090/; classtype:trojan-activity;sid:84762190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899091/; classtype:trojan-activity;sid:84762191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899092/; classtype:trojan-activity;sid:84762192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899093/; classtype:trojan-activity;sid:84762193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"mail.zanyyewuh.pro"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899094/; classtype:trojan-activity;sid:84762194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899095/; classtype:trojan-activity;sid:84762195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899096/; classtype:trojan-activity;sid:84762196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899097/; classtype:trojan-activity;sid:84762197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"mail.windycreekbc.pro"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899088/; classtype:trojan-activity;sid:84762188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"windycreekbc.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899089/; classtype:trojan-activity;sid:84762189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"bauble.cleverpondky.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899087/; classtype:trojan-activity;sid:84762187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899086/; classtype:trojan-activity;sid:84762186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899077/; classtype:trojan-activity;sid:84762177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899078/; classtype:trojan-activity;sid:84762178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899079/; classtype:trojan-activity;sid:84762179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899080/; classtype:trojan-activity;sid:84762180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899081/; classtype:trojan-activity;sid:84762181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899082/; classtype:trojan-activity;sid:84762182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899083/; classtype:trojan-activity;sid:84762183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899084/; classtype:trojan-activity;sid:84762184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899085/; classtype:trojan-activity;sid:84762185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899073/; classtype:trojan-activity;sid:84762173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899074/; classtype:trojan-activity;sid:84762174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899075/; classtype:trojan-activity;sid:84762175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899076/; classtype:trojan-activity;sid:84762176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899067/; classtype:trojan-activity;sid:84762167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899068/; classtype:trojan-activity;sid:84762168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899069/; classtype:trojan-activity;sid:84762169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899070/; classtype:trojan-activity;sid:84762170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899071/; classtype:trojan-activity;sid:84762171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899072/; classtype:trojan-activity;sid:84762172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899066/; classtype:trojan-activity;sid:84762166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899061/; classtype:trojan-activity;sid:84762161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899062/; classtype:trojan-activity;sid:84762162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899063/; classtype:trojan-activity;sid:84762163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899064/; classtype:trojan-activity;sid:84762164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899065/; classtype:trojan-activity;sid:84762165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899060/; classtype:trojan-activity;sid:84762160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899058/; classtype:trojan-activity;sid:84762158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899059/; classtype:trojan-activity;sid:84762159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"zanyyewuh.pro"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899057/; classtype:trojan-activity;sid:84762157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899054/; classtype:trojan-activity;sid:84762154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899055/; classtype:trojan-activity;sid:84762155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899056/; classtype:trojan-activity;sid:84762156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899052/; classtype:trojan-activity;sid:84762152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899053/; classtype:trojan-activity;sid:84762153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899041/; classtype:trojan-activity;sid:84762141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899042/; classtype:trojan-activity;sid:84762142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899043/; classtype:trojan-activity;sid:84762143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899044/; classtype:trojan-activity;sid:84762144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899045/; classtype:trojan-activity;sid:84762145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899046/; classtype:trojan-activity;sid:84762146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899047/; classtype:trojan-activity;sid:84762147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899048/; classtype:trojan-activity;sid:84762148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899049/; classtype:trojan-activity;sid:84762149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899050/; classtype:trojan-activity;sid:84762150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899051/; classtype:trojan-activity;sid:84762151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899032/; classtype:trojan-activity;sid:84762132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899033/; classtype:trojan-activity;sid:84762133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899034/; classtype:trojan-activity;sid:84762134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899035/; classtype:trojan-activity;sid:84762135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899036/; classtype:trojan-activity;sid:84762136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899037/; classtype:trojan-activity;sid:84762137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899038/; classtype:trojan-activity;sid:84762138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899039/; classtype:trojan-activity;sid:84762139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899040/; classtype:trojan-activity;sid:84762140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899031/; classtype:trojan-activity;sid:84762131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899030/; classtype:trojan-activity;sid:84762130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899029/; classtype:trojan-activity;sid:84762129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899027/; classtype:trojan-activity;sid:84762127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899028/; classtype:trojan-activity;sid:84762128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"silverrockay.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899026/; classtype:trojan-activity;sid:84762126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i686"; depth:26; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899025/; classtype:trojan-activity;sid:84762125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv6l"; depth:19; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899024/; classtype:trojan-activity;sid:84762124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899023/; classtype:trojan-activity;sid:84762123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86"; depth:25; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899016/; classtype:trojan-activity;sid:84762116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899017/; classtype:trojan-activity;sid:84762117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_m68k"; depth:17; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899018/; classtype:trojan-activity;sid:84762118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.i486"; depth:26; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899019/; classtype:trojan-activity;sid:84762119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.m68k"; depth:26; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899020/; classtype:trojan-activity;sid:84762120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i586"; depth:17; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899021/; classtype:trojan-activity;sid:84762121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client"; depth:12; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899022/; classtype:trojan-activity;sid:84762122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_i686"; depth:17; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899010/; classtype:trojan-activity;sid:84762110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.ppc"; depth:25; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899011/; classtype:trojan-activity;sid:84762111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arc"; depth:25; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899012/; classtype:trojan-activity;sid:84762112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899013/; classtype:trojan-activity;sid:84762113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mips"; depth:17; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899014/; classtype:trojan-activity;sid:84762114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_powerpc"; depth:20; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899015/; classtype:trojan-activity;sid:84762115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mpsl"; depth:26; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899000/; classtype:trojan-activity;sid:84762100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899001/; classtype:trojan-activity;sid:84762101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv7l"; depth:19; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899002/; classtype:trojan-activity;sid:84762102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv5l"; depth:19; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899003/; classtype:trojan-activity;sid:84762103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_sh4"; depth:16; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899004/; classtype:trojan-activity;sid:84762104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm5"; depth:26; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899005/; classtype:trojan-activity;sid:84762105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_x86_64"; depth:19; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899006/; classtype:trojan-activity;sid:84762106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.sh4"; depth:25; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899007/; classtype:trojan-activity;sid:84762107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_mipsel"; depth:19; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899008/; classtype:trojan-activity;sid:84762108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3899009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm6"; depth:26; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3899009/; classtype:trojan-activity;sid:84762109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/sdfjgnjsdf.arm7"; depth:26; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898999/; classtype:trojan-activity;sid:84762099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/micro.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898998/; classtype:trojan-activity;sid:84762098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/gpon"; depth:15; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898996/; classtype:trojan-activity;sid:84762096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/android.sh"; depth:21; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898997/; classtype:trojan-activity;sid:84762097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/client_armv4l"; depth:19; endswith; nocase; http.host; content:"94.154.43.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898995/; classtype:trojan-activity;sid:84762095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.225.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898994/; classtype:trojan-activity;sid:84762094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.45.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898993/; classtype:trojan-activity;sid:84762093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.45.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898992/; classtype:trojan-activity;sid:84762092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.225.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898991/; classtype:trojan-activity;sid:84762091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.247.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898990/; classtype:trojan-activity;sid:84762090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.197.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898989/; classtype:trojan-activity;sid:84762089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.210.206"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898988/; classtype:trojan-activity;sid:84762088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.247.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898987/; classtype:trojan-activity;sid:84762087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.105.50.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898986/; classtype:trojan-activity;sid:84762086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plugins-dist/safehtml/lang/font/ksmd"; depth:37; endswith; nocase; http.host; content:"34.70.205.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898985/; classtype:trojan-activity;sid:84762085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ksmd"; depth:5; endswith; nocase; http.host; content:"kworker.eth.limo"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898984/; classtype:trojan-activity;sid:84762084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ksmd"; depth:5; endswith; nocase; http.host; content:"216.98.10.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898983/; classtype:trojan-activity;sid:84762083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/library/payment/adapter/payeer/ksmd"; depth:36; endswith; nocase; http.host; content:"69.30.251.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898982/; classtype:trojan-activity;sid:84762082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install.sh"; depth:11; endswith; nocase; http.host; content:"167.179.119.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898981/; classtype:trojan-activity;sid:84762081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ksmd"; depth:5; endswith; nocase; http.host; content:"kworker.eth.link"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898980/; classtype:trojan-activity;sid:84762080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b51b4703e727923f.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898979/; classtype:trojan-activity;sid:84762079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.210.206"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898978/; classtype:trojan-activity;sid:84762078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.105.50.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898977/; classtype:trojan-activity;sid:84762077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.171.177.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898976/; classtype:trojan-activity;sid:84762076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e18d10f2ab43.ps1"; depth:17; endswith; nocase; http.host; content:"pub-c1aae4eecd22436e835dc3a91e470062.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898975/; classtype:trojan-activity;sid:84762075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.83.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898974/; classtype:trojan-activity;sid:84762074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.135.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898973/; classtype:trojan-activity;sid:84762073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.239.97.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898972/; classtype:trojan-activity;sid:84762072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.55.138.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898971/; classtype:trojan-activity;sid:84762071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.234.128.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898970/; classtype:trojan-activity;sid:84762070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.14.94"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898969/; classtype:trojan-activity;sid:84762069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.26.227.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898968/; classtype:trojan-activity;sid:84762068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.183.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898966/; classtype:trojan-activity;sid:84762066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"171.83.59.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898967/; classtype:trojan-activity;sid:84762067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.173.86.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898947/; classtype:trojan-activity;sid:84762047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.49.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898948/; classtype:trojan-activity;sid:84762048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898949/; classtype:trojan-activity;sid:84762049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.10.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898950/; classtype:trojan-activity;sid:84762050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.32.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898951/; classtype:trojan-activity;sid:84762051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.195.212"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898952/; classtype:trojan-activity;sid:84762052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.186.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898953/; classtype:trojan-activity;sid:84762053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.104.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898954/; classtype:trojan-activity;sid:84762054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.4.237"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898955/; classtype:trojan-activity;sid:84762055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.110.46.203"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898956/; classtype:trojan-activity;sid:84762056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.182.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898957/; classtype:trojan-activity;sid:84762057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.60.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898958/; classtype:trojan-activity;sid:84762058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898959/; classtype:trojan-activity;sid:84762059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.124.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898960/; classtype:trojan-activity;sid:84762060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.29.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898961/; classtype:trojan-activity;sid:84762061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.148.201.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898962/; classtype:trojan-activity;sid:84762062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.33.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898963/; classtype:trojan-activity;sid:84762063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.26.227.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898964/; classtype:trojan-activity;sid:84762064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.171.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898965/; classtype:trojan-activity;sid:84762065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.120.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898943/; classtype:trojan-activity;sid:84762043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.219.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898944/; classtype:trojan-activity;sid:84762044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.179.152.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898945/; classtype:trojan-activity;sid:84762045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.119.29"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898946/; classtype:trojan-activity;sid:84762046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898942/; classtype:trojan-activity;sid:84762042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.197.132.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898941/; classtype:trojan-activity;sid:84762041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.236.44.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898939/; classtype:trojan-activity;sid:84762039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/init.sh"; depth:8; endswith; nocase; http.host; content:"181.214.140.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898940/; classtype:trojan-activity;sid:84762040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.186.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898935/; classtype:trojan-activity;sid:84762035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.104.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898936/; classtype:trojan-activity;sid:84762036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.225.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898937/; classtype:trojan-activity;sid:84762037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.58.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898938/; classtype:trojan-activity;sid:84762038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.206.81.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898915/; classtype:trojan-activity;sid:84762015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.170.100.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898916/; classtype:trojan-activity;sid:84762016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.219.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898917/; classtype:trojan-activity;sid:84762017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.62.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898918/; classtype:trojan-activity;sid:84762018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.238.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898919/; classtype:trojan-activity;sid:84762019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.214.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898920/; classtype:trojan-activity;sid:84762020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.39.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898921/; classtype:trojan-activity;sid:84762021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.26.202.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898922/; classtype:trojan-activity;sid:84762022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.212.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898923/; classtype:trojan-activity;sid:84762023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"167.250.158.32"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898924/; classtype:trojan-activity;sid:84762024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.119.29"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898925/; classtype:trojan-activity;sid:84762025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.236.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898926/; classtype:trojan-activity;sid:84762026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.53.22.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898927/; classtype:trojan-activity;sid:84762027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.117.193"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898928/; classtype:trojan-activity;sid:84762028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.22.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898929/; classtype:trojan-activity;sid:84762029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.49.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898930/; classtype:trojan-activity;sid:84762030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.79.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898931/; classtype:trojan-activity;sid:84762031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.173.86.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898932/; classtype:trojan-activity;sid:84762032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.25.58"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898933/; classtype:trojan-activity;sid:84762033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.219.168"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898934/; classtype:trojan-activity;sid:84762034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.9.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898901/; classtype:trojan-activity;sid:84762001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.212.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898902/; classtype:trojan-activity;sid:84762002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.236.44.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898903/; classtype:trojan-activity;sid:84762003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.47.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898904/; classtype:trojan-activity;sid:84762004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.255.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898905/; classtype:trojan-activity;sid:84762005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.244.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898906/; classtype:trojan-activity;sid:84762006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.44.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898907/; classtype:trojan-activity;sid:84762007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.97.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898908/; classtype:trojan-activity;sid:84762008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.115.102.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898909/; classtype:trojan-activity;sid:84762009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.50.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898910/; classtype:trojan-activity;sid:84762010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"156.146.24.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898911/; classtype:trojan-activity;sid:84762011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.104.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898912/; classtype:trojan-activity;sid:84762012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.166.115.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898913/; classtype:trojan-activity;sid:84762013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.92.34"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898914/; classtype:trojan-activity;sid:84762014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.193.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898900/; classtype:trojan-activity;sid:84762000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.16.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898899/; classtype:trojan-activity;sid:84761999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.168.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898878/; classtype:trojan-activity;sid:84761978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.212.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898879/; classtype:trojan-activity;sid:84761979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.89.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898880/; classtype:trojan-activity;sid:84761980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.134.172.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898881/; classtype:trojan-activity;sid:84761981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.183.1"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898882/; classtype:trojan-activity;sid:84761982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.26.202.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898883/; classtype:trojan-activity;sid:84761983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.68.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898884/; classtype:trojan-activity;sid:84761984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.96.94"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898885/; classtype:trojan-activity;sid:84761985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.59.38.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898886/; classtype:trojan-activity;sid:84761986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898887/; classtype:trojan-activity;sid:84761987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.41.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898888/; classtype:trojan-activity;sid:84761988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.238.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898889/; classtype:trojan-activity;sid:84761989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.4.237"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898890/; classtype:trojan-activity;sid:84761990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898891/; classtype:trojan-activity;sid:84761991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.70.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898892/; classtype:trojan-activity;sid:84761992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.212.236"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898893/; classtype:trojan-activity;sid:84761993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.92.34"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898894/; classtype:trojan-activity;sid:84761994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.110.46.203"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898895/; classtype:trojan-activity;sid:84761995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.54.13"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898896/; classtype:trojan-activity;sid:84761996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.236.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898897/; classtype:trojan-activity;sid:84761997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.225.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898898/; classtype:trojan-activity;sid:84761998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"216.249.4.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898861/; classtype:trojan-activity;sid:84761961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.9.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898862/; classtype:trojan-activity;sid:84761962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.199.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898863/; classtype:trojan-activity;sid:84761963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.132.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898864/; classtype:trojan-activity;sid:84761964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.214.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898865/; classtype:trojan-activity;sid:84761965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.193.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898866/; classtype:trojan-activity;sid:84761966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.206.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898867/; classtype:trojan-activity;sid:84761967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.109.228.177"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898868/; classtype:trojan-activity;sid:84761968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.206.197.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898869/; classtype:trojan-activity;sid:84761969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"159.255.7.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898870/; classtype:trojan-activity;sid:84761970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.207.139.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898871/; classtype:trojan-activity;sid:84761971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"31.173.12.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898872/; classtype:trojan-activity;sid:84761972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"144.48.123.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898873/; classtype:trojan-activity;sid:84761973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898874/; classtype:trojan-activity;sid:84761974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.117.193"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898875/; classtype:trojan-activity;sid:84761975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zedx"; depth:5; endswith; nocase; http.host; content:"147.182.224.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898876/; classtype:trojan-activity;sid:84761976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.58.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898877/; classtype:trojan-activity;sid:84761977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.146.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898858/; classtype:trojan-activity;sid:84761958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"108.168.0.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898859/; classtype:trojan-activity;sid:84761959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.25.235.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898860/; classtype:trojan-activity;sid:84761960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.83.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898857/; classtype:trojan-activity;sid:84761957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.195.212"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898856/; classtype:trojan-activity;sid:84761956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.190.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898855/; classtype:trojan-activity;sid:84761955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.10.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898854/; classtype:trojan-activity;sid:84761954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.190.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898853/; classtype:trojan-activity;sid:84761953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.243.24"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898852/; classtype:trojan-activity;sid:84761952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.243.24"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898851/; classtype:trojan-activity;sid:84761951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.205.38"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898850/; classtype:trojan-activity;sid:84761950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.22.108"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898849/; classtype:trojan-activity;sid:84761949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.207.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898848/; classtype:trojan-activity;sid:84761948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.204.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898847/; classtype:trojan-activity;sid:84761947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4a4b8b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898840/; classtype:trojan-activity;sid:84761940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0c3474"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898841/; classtype:trojan-activity;sid:84761941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d77667"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898842/; classtype:trojan-activity;sid:84761942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60689f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898843/; classtype:trojan-activity;sid:84761943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b63d70"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898844/; classtype:trojan-activity;sid:84761944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/07aedd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898845/; classtype:trojan-activity;sid:84761945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2419f5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898846/; classtype:trojan-activity;sid:84761946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b136a3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898835/; classtype:trojan-activity;sid:84761935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35c40c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898836/; classtype:trojan-activity;sid:84761936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/155a79"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898837/; classtype:trojan-activity;sid:84761937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1a59ff"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898838/; classtype:trojan-activity;sid:84761938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2c7a26"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898839/; classtype:trojan-activity;sid:84761939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.82.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898833/; classtype:trojan-activity;sid:84761933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.82.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898834/; classtype:trojan-activity;sid:84761934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/webauth/releases/download/1.1/webauthinstallerbundle.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898832/; classtype:trojan-activity;sid:84761932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.106.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898831/; classtype:trojan-activity;sid:84761931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.185.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898830/; classtype:trojan-activity;sid:84761930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/knakendocu/releases/download/1.1/installerbundle.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898829/; classtype:trojan-activity;sid:84761929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/secondfi/releases/download/1.1/secondfiinstallerbundle.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898828/; classtype:trojan-activity;sid:84761928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/pocket/releases/download/1.1/youtrustinstallerbundle.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898827/; classtype:trojan-activity;sid:84761927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/ellipal/releases/download/1.1/ellipalinstallerbundle.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898826/; classtype:trojan-activity;sid:84761926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.204.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898825/; classtype:trojan-activity;sid:84761925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/dcent/releases/download/1.1/dcentinstallerbundle.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898824/; classtype:trojan-activity;sid:84761924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.235.197.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898823/; classtype:trojan-activity;sid:84761923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/relai/releases/download/1.1/docusigninstallerbundle.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898822/; classtype:trojan-activity;sid:84761922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/river/releases/download/1.1/docusigninstallerbundle.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898821/; classtype:trojan-activity;sid:84761921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/sparrow/releases/download/1.1/docusigninstallerbundle.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898820/; classtype:trojan-activity;sid:84761920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/wasabi/releases/download/1.1/docusigninstallerbundle.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898819/; classtype:trojan-activity;sid:84761919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.79.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898818/; classtype:trojan-activity;sid:84761918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/casa/releases/download/1.1/docusigninstallerbundle.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898817/; classtype:trojan-activity;sid:84761917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/coldcard/releases/download/1.1/docusigninstallerbundle.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898816/; classtype:trojan-activity;sid:84761916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.235.197.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898815/; classtype:trojan-activity;sid:84761915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cw.exe"; depth:7; endswith; nocase; http.host; content:"91.92.47.8"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898814/; classtype:trojan-activity;sid:84761914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quis.exe"; depth:9; endswith; nocase; http.host; content:"91.92.47.8"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898813/; classtype:trojan-activity;sid:84761913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/swan/releases/download/1.1/docusigninstallerbundle.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898812/; classtype:trojan-activity;sid:84761912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pufcw"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898811/; classtype:trojan-activity;sid:84761911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_112634.png"; depth:15; endswith; nocase; http.host; content:"citrusmangos.ct.ws"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898810/; classtype:trojan-activity;sid:84761910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/bullbitcoin/releases/download/1.1/docusigninstallerbundle.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898809/; classtype:trojan-activity;sid:84761909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/onekey/releases/download/1.1/docusigninstallerbundle.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898808/; classtype:trojan-activity;sid:84761908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/fold/releases/download/1.1/docusigninstallerbundle.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898807/; classtype:trojan-activity;sid:84761907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.227.48.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898806/; classtype:trojan-activity;sid:84761906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.243.228.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898805/; classtype:trojan-activity;sid:84761905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eb5263"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898793/; classtype:trojan-activity;sid:84761893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22393a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898794/; classtype:trojan-activity;sid:84761894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/32441c"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898795/; classtype:trojan-activity;sid:84761895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/690e95"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898796/; classtype:trojan-activity;sid:84761896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fb21f1"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898797/; classtype:trojan-activity;sid:84761897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fd89ab"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898798/; classtype:trojan-activity;sid:84761898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7215c9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898799/; classtype:trojan-activity;sid:84761899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2ca244"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898800/; classtype:trojan-activity;sid:84761900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/924208"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898801/; classtype:trojan-activity;sid:84761901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/82c703"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898802/; classtype:trojan-activity;sid:84761902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/80b16f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898803/; classtype:trojan-activity;sid:84761903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cc8b91"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898804/; classtype:trojan-activity;sid:84761904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/settings/bootstraplinux"; depth:28; endswith; nocase; http.host; content:"quick-load.vercel.app"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898792/; classtype:trojan-activity;sid:84761892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44e32f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898754/; classtype:trojan-activity;sid:84761854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/21a9d4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898755/; classtype:trojan-activity;sid:84761855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ot7"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898756/; classtype:trojan-activity;sid:84761856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8a320b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898757/; classtype:trojan-activity;sid:84761857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4ykq"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898758/; classtype:trojan-activity;sid:84761858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4vqu"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898759/; classtype:trojan-activity;sid:84761859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c1ic"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898760/; classtype:trojan-activity;sid:84761860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/04e832"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898761/; classtype:trojan-activity;sid:84761861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a5b334"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898762/; classtype:trojan-activity;sid:84761862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3b0256"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898763/; classtype:trojan-activity;sid:84761863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e8e811"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898764/; classtype:trojan-activity;sid:84761864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xl01"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898765/; classtype:trojan-activity;sid:84761865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7uv8"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898766/; classtype:trojan-activity;sid:84761866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f818ff"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898767/; classtype:trojan-activity;sid:84761867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rzwf"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898768/; classtype:trojan-activity;sid:84761868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6cf53f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898769/; classtype:trojan-activity;sid:84761869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rg3i"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898770/; classtype:trojan-activity;sid:84761870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f91198"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898771/; classtype:trojan-activity;sid:84761871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cd049e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898772/; classtype:trojan-activity;sid:84761872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/575708"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898773/; classtype:trojan-activity;sid:84761873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ef363f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898774/; classtype:trojan-activity;sid:84761874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/704581"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898775/; classtype:trojan-activity;sid:84761875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f39a8e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898776/; classtype:trojan-activity;sid:84761876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fxd"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898777/; classtype:trojan-activity;sid:84761877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/747c0d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898778/; classtype:trojan-activity;sid:84761878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d6c209"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898779/; classtype:trojan-activity;sid:84761879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wqm"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898780/; classtype:trojan-activity;sid:84761880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lwc"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898781/; classtype:trojan-activity;sid:84761881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19e860"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898782/; classtype:trojan-activity;sid:84761882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yx2w"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898783/; classtype:trojan-activity;sid:84761883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0eaa32"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898784/; classtype:trojan-activity;sid:84761884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/99764f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898785/; classtype:trojan-activity;sid:84761885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/783f2a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898786/; classtype:trojan-activity;sid:84761886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f4f193"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898787/; classtype:trojan-activity;sid:84761887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2nxl"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898788/; classtype:trojan-activity;sid:84761888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/y3p"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898789/; classtype:trojan-activity;sid:84761889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/759f0d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898790/; classtype:trojan-activity;sid:84761890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xkw"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898791/; classtype:trojan-activity;sid:84761891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e55fd5"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898753/; classtype:trojan-activity;sid:84761853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaswareteam/willy/releases/download/1.1/docusigninstallerbundle.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898752/; classtype:trojan-activity;sid:84761852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.207.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898751/; classtype:trojan-activity;sid:84761851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.163.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898750/; classtype:trojan-activity;sid:84761850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.amd64"; depth:10; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898749/; classtype:trojan-activity;sid:84761849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"221.15.226.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898748/; classtype:trojan-activity;sid:84761848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_bec865d8acfd0630.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898747/; classtype:trojan-activity;sid:84761847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_38244c706786dad7.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898746/; classtype:trojan-activity;sid:84761846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.s390x"; depth:10; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898743/; classtype:trojan-activity;sid:84761843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898744/; classtype:trojan-activity;sid:84761844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mipsle"; depth:11; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898745/; classtype:trojan-activity;sid:84761845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc64"; depth:10; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898739/; classtype:trojan-activity;sid:84761839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.riscv64"; depth:12; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898740/; classtype:trojan-activity;sid:84761840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898741/; classtype:trojan-activity;sid:84761841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.386"; depth:8; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898742/; classtype:trojan-activity;sid:84761842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips64le"; depth:13; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898735/; classtype:trojan-activity;sid:84761835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc64le"; depth:12; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898736/; classtype:trojan-activity;sid:84761836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm64"; depth:10; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898737/; classtype:trojan-activity;sid:84761837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips64"; depth:11; endswith; nocase; http.host; content:"92.5.66.49"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898738/; classtype:trojan-activity;sid:84761838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/troubleshoot.ps1"; depth:17; endswith; nocase; http.host; content:"199.217.99.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898734/; classtype:trojan-activity;sid:84761834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update1.zip"; depth:12; endswith; nocase; http.host; content:"192.252.178.228"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898733/; classtype:trojan-activity;sid:84761833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5ebfecdc25724f43.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898732/; classtype:trojan-activity;sid:84761832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/rew3rtghymrag7y/file"; depth:26; endswith; nocase; http.host; content:"www.mediafire.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898731/; classtype:trojan-activity;sid:84761831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.163.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898730/; classtype:trojan-activity;sid:84761830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.42.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898729/; classtype:trojan-activity;sid:84761829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.42.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898728/; classtype:trojan-activity;sid:84761828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.2.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898727/; classtype:trojan-activity;sid:84761827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.2.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898726/; classtype:trojan-activity;sid:84761826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.115.143"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898725/; classtype:trojan-activity;sid:84761825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/molakc"; depth:7; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898724/; classtype:trojan-activity;sid:84761824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.234.239.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898723/; classtype:trojan-activity;sid:84761823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.109.140.49"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898722/; classtype:trojan-activity;sid:84761822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.6.165.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898721/; classtype:trojan-activity;sid:84761821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.7.68"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898720/; classtype:trojan-activity;sid:84761820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.234.239.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898719/; classtype:trojan-activity;sid:84761819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.6.165.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898718/; classtype:trojan-activity;sid:84761818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.213.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898717/; classtype:trojan-activity;sid:84761817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.213.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898716/; classtype:trojan-activity;sid:84761816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.186.208.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898715/; classtype:trojan-activity;sid:84761815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.10.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898714/; classtype:trojan-activity;sid:84761814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.67.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898713/; classtype:trojan-activity;sid:84761813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.40.241"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898712/; classtype:trojan-activity;sid:84761812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm7"; depth:10; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898710/; classtype:trojan-activity;sid:84761810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm5"; depth:10; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898711/; classtype:trojan-activity;sid:84761811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm6"; depth:10; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898705/; classtype:trojan-activity;sid:84761805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86_64"; depth:12; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898706/; classtype:trojan-activity;sid:84761806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_powerpc"; depth:13; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898707/; classtype:trojan-activity;sid:84761807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm4"; depth:10; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898708/; classtype:trojan-activity;sid:84761808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86"; depth:9; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898709/; classtype:trojan-activity;sid:84761809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.40.241"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898704/; classtype:trojan-activity;sid:84761804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mips"; depth:10; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898703/; classtype:trojan-activity;sid:84761803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mipsel"; depth:12; endswith; nocase; http.host; content:"94.183.233.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898702/; classtype:trojan-activity;sid:84761802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.186.208.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898701/; classtype:trojan-activity;sid:84761801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.0.49"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898700/; classtype:trojan-activity;sid:84761800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.107.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898699/; classtype:trojan-activity;sid:84761799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.140.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898698/; classtype:trojan-activity;sid:84761798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.107.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898697/; classtype:trojan-activity;sid:84761797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.234.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898696/; classtype:trojan-activity;sid:84761796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.194.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898695/; classtype:trojan-activity;sid:84761795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.140.157"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898694/; classtype:trojan-activity;sid:84761794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.234.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898693/; classtype:trojan-activity;sid:84761793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.94.125.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898692/; classtype:trojan-activity;sid:84761792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.223.175"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898691/; classtype:trojan-activity;sid:84761791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.150.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898690/; classtype:trojan-activity;sid:84761790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.150.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898689/; classtype:trojan-activity;sid:84761789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.68.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898687/; classtype:trojan-activity;sid:84761787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.sh4musl"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898688/; classtype:trojan-activity;sid:84761788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.sparc64"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898686/; classtype:trojan-activity;sid:84761786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f"; depth:2; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898665/; classtype:trojan-activity;sid:84761765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.sh4aeb"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898666/; classtype:trojan-activity;sid:84761766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.e500mc"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898667/; classtype:trojan-activity;sid:84761767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86-i686"; depth:14; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898668/; classtype:trojan-activity;sid:84761768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.s390x"; depth:11; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898669/; classtype:trojan-activity;sid:84761769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86-64-v2"; depth:15; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898670/; classtype:trojan-activity;sid:84761770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips32r6el"; depth:16; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898671/; classtype:trojan-activity;sid:84761771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86-core2"; depth:15; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898672/; classtype:trojan-activity;sid:84761772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86-64"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898673/; classtype:trojan-activity;sid:84761773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips64el-n32"; depth:18; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898674/; classtype:trojan-activity;sid:84761774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86-64-v3"; depth:15; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898675/; classtype:trojan-activity;sid:84761775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.power8le"; depth:14; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898676/; classtype:trojan-activity;sid:84761776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86-64-i7"; depth:15; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898677/; classtype:trojan-activity;sid:84761777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86-64-v4"; depth:15; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898678/; classtype:trojan-activity;sid:84761778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.aarch64be"; depth:15; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898679/; classtype:trojan-activity;sid:84761779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips32r5el"; depth:16; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898680/; classtype:trojan-activity;sid:84761780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.ppc440fp"; depth:14; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898681/; classtype:trojan-activity;sid:84761781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.e6500"; depth:11; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898682/; classtype:trojan-activity;sid:84761782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.power8"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898683/; classtype:trojan-activity;sid:84761783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.sparcv8"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898684/; classtype:trojan-activity;sid:84761784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.151.217.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898685/; classtype:trojan-activity;sid:84761785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips64-n32"; depth:16; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898660/; classtype:trojan-activity;sid:84761760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.m68k-68xxx"; depth:16; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898661/; classtype:trojan-activity;sid:84761761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips64r6el-n32"; depth:20; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898662/; classtype:trojan-activity;sid:84761762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips32"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898663/; classtype:trojan-activity;sid:84761763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.e5500"; depth:11; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898664/; classtype:trojan-activity;sid:84761764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.88.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898659/; classtype:trojan-activity;sid:84761759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.146.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898658/; classtype:trojan-activity;sid:84761758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.68.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898657/; classtype:trojan-activity;sid:84761757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.94.116.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898656/; classtype:trojan-activity;sid:84761756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.151.217.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898655/; classtype:trojan-activity;sid:84761755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.234.134"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898654/; classtype:trojan-activity;sid:84761754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.88.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898653/; classtype:trojan-activity;sid:84761753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.223.175"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898652/; classtype:trojan-activity;sid:84761752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.231.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898651/; classtype:trojan-activity;sid:84761751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.195.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898650/; classtype:trojan-activity;sid:84761750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.231.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898649/; classtype:trojan-activity;sid:84761749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.10.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898648/; classtype:trojan-activity;sid:84761748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.195.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898647/; classtype:trojan-activity;sid:84761747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.87.190.196"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898646/; classtype:trojan-activity;sid:84761746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.10.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898645/; classtype:trojan-activity;sid:84761745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.72.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898643/; classtype:trojan-activity;sid:84761743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.87.190.196"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898644/; classtype:trojan-activity;sid:84761744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.230.18.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898642/; classtype:trojan-activity;sid:84761742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.147.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898641/; classtype:trojan-activity;sid:84761741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/settings/env"; depth:17; endswith; nocase; http.host; content:"quick-load.vercel.app"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898638/; classtype:trojan-activity;sid:84761738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/settings/bootstrap"; depth:23; endswith; nocase; http.host; content:"quick-load.vercel.app"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898639/; classtype:trojan-activity;sid:84761739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/settings/package"; depth:21; endswith; nocase; http.host; content:"quick-load.vercel.app"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898640/; classtype:trojan-activity;sid:84761740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.94.125.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898637/; classtype:trojan-activity;sid:84761737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traff"; depth:6; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898636/; classtype:trojan-activity;sid:84761736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/log"; depth:4; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898635/; classtype:trojan-activity;sid:84761735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss"; depth:5; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898634/; classtype:trojan-activity;sid:84761734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvidia.sh"; depth:10; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898631/; classtype:trojan-activity;sid:84761731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syst3md"; depth:8; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898632/; classtype:trojan-activity;sid:84761732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wd1337"; depth:7; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898633/; classtype:trojan-activity;sid:84761733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/error84"; depth:8; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898628/; classtype:trojan-activity;sid:84761728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"115.51.80.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898629/; classtype:trojan-activity;sid:84761729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cli"; depth:4; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898630/; classtype:trojan-activity;sid:84761730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto1"; depth:6; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898621/; classtype:trojan-activity;sid:84761721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check.sh"; depth:9; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898622/; classtype:trojan-activity;sid:84761722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check1.sh"; depth:10; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898623/; classtype:trojan-activity;sid:84761723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proot"; depth:6; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898624/; classtype:trojan-activity;sid:84761724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cliaarch"; depth:9; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898625/; classtype:trojan-activity;sid:84761725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traffaarch"; depth:11; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898626/; classtype:trojan-activity;sid:84761726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/checkmacos.sh"; depth:14; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898627/; classtype:trojan-activity;sid:84761727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldboss"; depth:8; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898620/; classtype:trojan-activity;sid:84761720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto"; depth:5; endswith; nocase; http.host; content:"rippled.cleverpondky.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898619/; classtype:trojan-activity;sid:84761719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g1/6.txt"; depth:9; endswith; nocase; http.host; content:"93.105.205.92.host.secureserver.net"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898601/; classtype:trojan-activity;sid:84761701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g1/exe.txt"; depth:11; endswith; nocase; http.host; content:"93.105.205.92.host.secureserver.net"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898599/; classtype:trojan-activity;sid:84761699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g1/sc.txt"; depth:10; endswith; nocase; http.host; content:"93.105.205.92.host.secureserver.net"; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898600/; classtype:trojan-activity;sid:84761700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.148.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898598/; classtype:trojan-activity;sid:84761698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.148.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898597/; classtype:trojan-activity;sid:84761697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.72.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898596/; classtype:trojan-activity;sid:84761696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.24.27.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898595/; classtype:trojan-activity;sid:84761695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.22.216"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898594/; classtype:trojan-activity;sid:84761694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.98.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898593/; classtype:trojan-activity;sid:84761693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.25.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898592/; classtype:trojan-activity;sid:84761692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.8.245"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898591/; classtype:trojan-activity;sid:84761691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.95.24.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898590/; classtype:trojan-activity;sid:84761690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.25.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898589/; classtype:trojan-activity;sid:84761689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.181.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898588/; classtype:trojan-activity;sid:84761688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.95.24.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898587/; classtype:trojan-activity;sid:84761687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/settings/mac"; depth:17; endswith; nocase; http.host; content:"quick-load.vercel.app"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898584/; classtype:trojan-activity;sid:84761684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/settings/linux"; depth:19; endswith; nocase; http.host; content:"quick-load.vercel.app"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898585/; classtype:trojan-activity;sid:84761685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/settings/windows"; depth:21; endswith; nocase; http.host; content:"quick-load.vercel.app"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898586/; classtype:trojan-activity;sid:84761686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.181.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898583/; classtype:trojan-activity;sid:84761683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.98.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898582/; classtype:trojan-activity;sid:84761682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.10.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898581/; classtype:trojan-activity;sid:84761681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.8.131.222"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898580/; classtype:trojan-activity;sid:84761680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.17.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898579/; classtype:trojan-activity;sid:84761679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.59.13.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898578/; classtype:trojan-activity;sid:84761678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.185.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898577/; classtype:trojan-activity;sid:84761677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"159.255.7.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898576/; classtype:trojan-activity;sid:84761676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.118.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898575/; classtype:trojan-activity;sid:84761675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.185.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898574/; classtype:trojan-activity;sid:84761674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ddos.zip"; depth:9; endswith; nocase; http.host; content:"yakult-hk.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898573/; classtype:trojan-activity;sid:84761673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.156.97.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898572/; classtype:trojan-activity;sid:84761672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.59.13.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898571/; classtype:trojan-activity;sid:84761671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.156.97.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898570/; classtype:trojan-activity;sid:84761670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4b9ed200c95f2598.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898569/; classtype:trojan-activity;sid:84761669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/accrypted.ps1"; depth:17; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898566/; classtype:trojan-activity;sid:84761666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t3swaz48/image/upload/v1786064222/img_205416_efsex4.jpg"; depth:56; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898567/; classtype:trojan-activity;sid:84761667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t3swaz48/image/upload/v1786063446/img_204228_kc4cit.jpg"; depth:56; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898568/; classtype:trojan-activity;sid:84761668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmszch/electricityjog.ps1"; depth:26; endswith; nocase; http.host; content:"31.76.93.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898564/; classtype:trojan-activity;sid:84761664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmszch/steepleadmit.ps1"; depth:24; endswith; nocase; http.host; content:"31.76.93.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898565/; classtype:trojan-activity;sid:84761665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filess/teleg.exe"; depth:17; endswith; nocase; http.host; content:"meridia.rs"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898563/; classtype:trojan-activity;sid:84761663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m/jscotbpl.dat"; depth:15; endswith; nocase; http.host; content:"89.23.107.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898562/; classtype:trojan-activity;sid:84761662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supply%20order/crypted.zip.ps1"; depth:31; endswith; nocase; http.host; content:"mailglobalsbg.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898560/; classtype:trojan-activity;sid:84761660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supply%20order/so_08072026.rar"; depth:31; endswith; nocase; http.host; content:"mailglobalsbg.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898561/; classtype:trojan-activity;sid:84761661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_234525.png"; depth:15; endswith; nocase; http.host; content:"wealthishealth.free.je"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898559/; classtype:trojan-activity;sid:84761659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbeiv"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898558/; classtype:trojan-activity;sid:84761658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898533/; classtype:trojan-activity;sid:84761633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.x86"; depth:11; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898534/; classtype:trojan-activity;sid:84761634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.mpsl"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898535/; classtype:trojan-activity;sid:84761635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898536/; classtype:trojan-activity;sid:84761636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.ppc"; depth:11; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898537/; classtype:trojan-activity;sid:84761637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898538/; classtype:trojan-activity;sid:84761638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898539/; classtype:trojan-activity;sid:84761639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898540/; classtype:trojan-activity;sid:84761640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898541/; classtype:trojan-activity;sid:84761641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.arm7"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898542/; classtype:trojan-activity;sid:84761642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898543/; classtype:trojan-activity;sid:84761643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.arm6"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898544/; classtype:trojan-activity;sid:84761644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898545/; classtype:trojan-activity;sid:84761645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.m68k"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898546/; classtype:trojan-activity;sid:84761646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.sparc"; depth:13; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898547/; classtype:trojan-activity;sid:84761647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.arm4"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898548/; classtype:trojan-activity;sid:84761648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898549/; classtype:trojan-activity;sid:84761649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.i586"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898550/; classtype:trojan-activity;sid:84761650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.arm5"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898551/; classtype:trojan-activity;sid:84761651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898552/; classtype:trojan-activity;sid:84761652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.sh4"; depth:11; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898553/; classtype:trojan-activity;sid:84761653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898554/; classtype:trojan-activity;sid:84761654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.mips"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898555/; classtype:trojan-activity;sid:84761655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.i686"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898556/; classtype:trojan-activity;sid:84761656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898557/; classtype:trojan-activity;sid:84761657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohycb"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898532/; classtype:trojan-activity;sid:84761632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_072806.png"; depth:15; endswith; nocase; http.host; content:"effectively32.infinityfree.me"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898531/; classtype:trojan-activity;sid:84761631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pot/crypted.ps1"; depth:16; endswith; nocase; http.host; content:"ryanborn.net"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898530/; classtype:trojan-activity;sid:84761630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dad/crypted.ps1"; depth:16; endswith; nocase; http.host; content:"ryanborn.net"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898529/; classtype:trojan-activity;sid:84761629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/weprovideforbesthingstocomebackgoodthings.hta"; depth:49; endswith; nocase; http.host; content:"172.245.209.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898528/; classtype:trojan-activity;sid:84761628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/img_201031.png"; depth:18; endswith; nocase; http.host; content:"172.245.209.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898527/; classtype:trojan-activity;sid:84761627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22/img_203145.png"; depth:18; endswith; nocase; http.host; content:"107.175.88.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898526/; classtype:trojan-activity;sid:84761626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22/goodpersonforbestthingsfor.hta"; depth:34; endswith; nocase; http.host; content:"107.175.88.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898525/; classtype:trojan-activity;sid:84761625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soft/muvaro.exe"; depth:16; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898524/; classtype:trojan-activity;sid:84761624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/kjhgfds.exe"; depth:27; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898523/; classtype:trojan-activity;sid:84761623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/arbeb.exe"; depth:25; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898522/; classtype:trojan-activity;sid:84761622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/arftu.exe"; depth:22; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898521/; classtype:trojan-activity;sid:84761621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/kliulij.exe"; depth:24; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898520/; classtype:trojan-activity;sid:84761620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/kjhjhkjkjh.exe"; depth:27; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898509/; classtype:trojan-activity;sid:84761609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/klhdfs.exe"; depth:23; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898510/; classtype:trojan-activity;sid:84761610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/build_mix.exe"; depth:28; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898511/; classtype:trojan-activity;sid:84761611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/arbeb.exe"; depth:22; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898512/; classtype:trojan-activity;sid:84761612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/build_mix.exe"; depth:25; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898513/; classtype:trojan-activity;sid:84761613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soft/hiegq.exe"; depth:15; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898514/; classtype:trojan-activity;sid:84761614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/r6.exe"; depth:18; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898515/; classtype:trojan-activity;sid:84761615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/hnmh.exe"; depth:21; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898516/; classtype:trojan-activity;sid:84761616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soft/cheat_x.exe"; depth:17; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898517/; classtype:trojan-activity;sid:84761617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/hjbk.exe"; depth:21; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898518/; classtype:trojan-activity;sid:84761618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/mixnew1.exe"; depth:23; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898519/; classtype:trojan-activity;sid:84761619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/mixnew1.exe"; depth:26; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898507/; classtype:trojan-activity;sid:84761607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/klhdfs_260731110521.exe"; depth:39; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898508/; classtype:trojan-activity;sid:84761608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/ojujn.exe"; depth:22; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898505/; classtype:trojan-activity;sid:84761605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/kjhgfds.exe"; depth:24; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898506/; classtype:trojan-activity;sid:84761606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/jhgkuyyg.exe"; depth:28; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898504/; classtype:trojan-activity;sid:84761604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/zalupa.exe"; depth:22; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898498/; classtype:trojan-activity;sid:84761598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/r7.exe"; depth:21; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898499/; classtype:trojan-activity;sid:84761599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/jhgkuyyg.exe"; depth:25; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898500/; classtype:trojan-activity;sid:84761600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/hjbk.exe"; depth:24; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898501/; classtype:trojan-activity;sid:84761601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/mixres3.exe"; depth:23; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898502/; classtype:trojan-activity;sid:84761602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/arftu.exe"; depth:25; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898503/; classtype:trojan-activity;sid:84761603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/kllnmf.exe"; depth:26; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898490/; classtype:trojan-activity;sid:84761590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/hnmh.exe"; depth:24; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898491/; classtype:trojan-activity;sid:84761591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/crz.exe"; depth:22; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898492/; classtype:trojan-activity;sid:84761592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/bjbh.exe"; depth:24; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898493/; classtype:trojan-activity;sid:84761593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/ojujn.exe"; depth:25; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898494/; classtype:trojan-activity;sid:84761594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/kllnmf.exe"; depth:23; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898495/; classtype:trojan-activity;sid:84761595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/kjhjhkjkjh.exe"; depth:30; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898496/; classtype:trojan-activity;sid:84761596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/mixres3.exe"; depth:26; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898497/; classtype:trojan-activity;sid:84761597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/klhdfs.exe"; depth:26; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898488/; classtype:trojan-activity;sid:84761588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/xqaae.exe"; depth:22; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898489/; classtype:trojan-activity;sid:84761589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/crz.exe"; depth:19; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898484/; classtype:trojan-activity;sid:84761584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/bjbh.exe"; depth:21; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898485/; classtype:trojan-activity;sid:84761585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/r7.exe"; depth:18; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898486/; classtype:trojan-activity;sid:84761586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/xqaae.exe"; depth:25; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898487/; classtype:trojan-activity;sid:84761587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/kliulij.exe"; depth:27; endswith; nocase; http.host; content:"cryptomeshforge5.lol"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898483/; classtype:trojan-activity;sid:84761583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4f77864d0a6bff5e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898482/; classtype:trojan-activity;sid:84761582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http/crypted1.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898481/; classtype:trojan-activity;sid:84761581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http/img_043214.png"; depth:20; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898479/; classtype:trojan-activity;sid:84761579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/pwcrypted.ps1"; depth:17; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898480/; classtype:trojan-activity;sid:84761580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main/pure.bat"; depth:14; endswith; nocase; http.host; content:"45.83.31.27"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898478/; classtype:trojan-activity;sid:84761578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/index.json"; depth:11; endswith; nocase; http.host; content:"gray-dyane-31.tiiny.site"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898477/; classtype:trojan-activity;sid:84761577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898474/; classtype:trojan-activity;sid:84761574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.26.226.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898475/; classtype:trojan-activity;sid:84761575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.138.19.119"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898476/; classtype:trojan-activity;sid:84761576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.148.129.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898471/; classtype:trojan-activity;sid:84761571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.252.223.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898472/; classtype:trojan-activity;sid:84761572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.53.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898473/; classtype:trojan-activity;sid:84761573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898455/; classtype:trojan-activity;sid:84761555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.144.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898456/; classtype:trojan-activity;sid:84761556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.90.145.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898457/; classtype:trojan-activity;sid:84761557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.204.233.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898458/; classtype:trojan-activity;sid:84761558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.35.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898459/; classtype:trojan-activity;sid:84761559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.93.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898460/; classtype:trojan-activity;sid:84761560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gots"; depth:5; endswith; nocase; http.host; content:"213.177.179.11"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898461/; classtype:trojan-activity;sid:84761561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"167.250.158.32"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898462/; classtype:trojan-activity;sid:84761562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"156.146.24.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898463/; classtype:trojan-activity;sid:84761563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.85.180.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898464/; classtype:trojan-activity;sid:84761564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.53.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898465/; classtype:trojan-activity;sid:84761565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.179.152.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898466/; classtype:trojan-activity;sid:84761566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.148.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898467/; classtype:trojan-activity;sid:84761567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.199.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898468/; classtype:trojan-activity;sid:84761568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"183.23.139.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898469/; classtype:trojan-activity;sid:84761569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.0.62.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898470/; classtype:trojan-activity;sid:84761570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.84.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898444/; classtype:trojan-activity;sid:84761544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.175.215.229"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898445/; classtype:trojan-activity;sid:84761545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.80.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898446/; classtype:trojan-activity;sid:84761546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.226.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898447/; classtype:trojan-activity;sid:84761547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.0.62.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898448/; classtype:trojan-activity;sid:84761548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.141.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898449/; classtype:trojan-activity;sid:84761549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.49.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898450/; classtype:trojan-activity;sid:84761550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.126.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898451/; classtype:trojan-activity;sid:84761551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.107.63.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898452/; classtype:trojan-activity;sid:84761552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.228.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898453/; classtype:trojan-activity;sid:84761553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.212.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898454/; classtype:trojan-activity;sid:84761554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.155.201.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898440/; classtype:trojan-activity;sid:84761540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.180.11.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898441/; classtype:trojan-activity;sid:84761541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.54.177.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898442/; classtype:trojan-activity;sid:84761542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.190.203.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898443/; classtype:trojan-activity;sid:84761543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.154.174.185"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898439/; classtype:trojan-activity;sid:84761539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.228.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898437/; classtype:trojan-activity;sid:84761537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"91.108.27.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898438/; classtype:trojan-activity;sid:84761538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.141.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898436/; classtype:trojan-activity;sid:84761536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.80.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898435/; classtype:trojan-activity;sid:84761535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.205.38"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898427/; classtype:trojan-activity;sid:84761527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.31.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898428/; classtype:trojan-activity;sid:84761528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.120.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898429/; classtype:trojan-activity;sid:84761529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.51.204.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898430/; classtype:trojan-activity;sid:84761530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.209.101.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898431/; classtype:trojan-activity;sid:84761531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.175.215.229"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898432/; classtype:trojan-activity;sid:84761532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"89.189.181.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898433/; classtype:trojan-activity;sid:84761533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.90.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898434/; classtype:trojan-activity;sid:84761534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.1.226.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898416/; classtype:trojan-activity;sid:84761516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.87.169.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898417/; classtype:trojan-activity;sid:84761517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.130.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898418/; classtype:trojan-activity;sid:84761518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.198.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898419/; classtype:trojan-activity;sid:84761519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898420/; classtype:trojan-activity;sid:84761520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898421/; classtype:trojan-activity;sid:84761521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"108.168.0.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898422/; classtype:trojan-activity;sid:84761522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.212.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898423/; classtype:trojan-activity;sid:84761523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.8.245"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898424/; classtype:trojan-activity;sid:84761524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.154.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898425/; classtype:trojan-activity;sid:84761525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.212.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898426/; classtype:trojan-activity;sid:84761526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.252.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898408/; classtype:trojan-activity;sid:84761508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.81.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898409/; classtype:trojan-activity;sid:84761509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.144.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898410/; classtype:trojan-activity;sid:84761510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.231.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898411/; classtype:trojan-activity;sid:84761511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.26.18.38"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898412/; classtype:trojan-activity;sid:84761512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.92.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898413/; classtype:trojan-activity;sid:84761513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.55.138.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898414/; classtype:trojan-activity;sid:84761514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.84.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898415/; classtype:trojan-activity;sid:84761515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"210.95.98.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898405/; classtype:trojan-activity;sid:84761505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.183.130.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898406/; classtype:trojan-activity;sid:84761506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.239.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898407/; classtype:trojan-activity;sid:84761507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.81.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898403/; classtype:trojan-activity;sid:84761503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.149.193"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898404/; classtype:trojan-activity;sid:84761504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.9.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898400/; classtype:trojan-activity;sid:84761500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.130.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898401/; classtype:trojan-activity;sid:84761501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.126.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898402/; classtype:trojan-activity;sid:84761502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.152.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898399/; classtype:trojan-activity;sid:84761499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.214.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898397/; classtype:trojan-activity;sid:84761497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.207.139.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898398/; classtype:trojan-activity;sid:84761498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.90.145.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898384/; classtype:trojan-activity;sid:84761484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.138.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898385/; classtype:trojan-activity;sid:84761485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.26.18.38"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898386/; classtype:trojan-activity;sid:84761486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.182.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898387/; classtype:trojan-activity;sid:84761487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.252.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898388/; classtype:trojan-activity;sid:84761488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.226.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898389/; classtype:trojan-activity;sid:84761489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.198.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898390/; classtype:trojan-activity;sid:84761490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.157.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898391/; classtype:trojan-activity;sid:84761491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.9.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898392/; classtype:trojan-activity;sid:84761492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.109.219.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898393/; classtype:trojan-activity;sid:84761493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.58.42.82"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898394/; classtype:trojan-activity;sid:84761494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.170.100.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898395/; classtype:trojan-activity;sid:84761495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.212.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898396/; classtype:trojan-activity;sid:84761496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.177.186.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898369/; classtype:trojan-activity;sid:84761469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"68.65.100.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898370/; classtype:trojan-activity;sid:84761470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.222.47.36"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898371/; classtype:trojan-activity;sid:84761471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.56.232.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898372/; classtype:trojan-activity;sid:84761472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.89.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898373/; classtype:trojan-activity;sid:84761473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.108.82.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898374/; classtype:trojan-activity;sid:84761474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.207.236.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898375/; classtype:trojan-activity;sid:84761475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"204.244.176.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898376/; classtype:trojan-activity;sid:84761476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.108.82.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898377/; classtype:trojan-activity;sid:84761477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898378/; classtype:trojan-activity;sid:84761478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.231.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898379/; classtype:trojan-activity;sid:84761479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.88.136.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898380/; classtype:trojan-activity;sid:84761480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.12.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898381/; classtype:trojan-activity;sid:84761481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"81.227.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898382/; classtype:trojan-activity;sid:84761482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.56.232.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898383/; classtype:trojan-activity;sid:84761483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.155.201.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898366/; classtype:trojan-activity;sid:84761466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.35.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898367/; classtype:trojan-activity;sid:84761467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.5.60"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898368/; classtype:trojan-activity;sid:84761468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dodu"; depth:5; endswith; nocase; http.host; content:"213.177.179.11"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898365/; classtype:trojan-activity;sid:84761465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/c.sh"; depth:10; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898364/; classtype:trojan-activity;sid:84761464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ehrvdypc-gjc7hs5p-ysqckcka-5z3sw8fk/vkjerowp.msi"; depth:49; endswith; nocase; http.host; content:"94.26.83.35"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898363/; classtype:trojan-activity;sid:84761463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vkjerowp.msi"; depth:13; endswith; nocase; http.host; content:"pub-c9224963ee6a49b194bba4acac778b13.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898362/; classtype:trojan-activity;sid:84761462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2kqyrm0dcrnyjgos4gvll_fhjrrdtuhgcbjyuywpz6c/dante/update"; depth:57; endswith; nocase; http.host; content:"ferncurrent14.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898360/; classtype:trojan-activity;sid:84761460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm7"; depth:10; endswith; nocase; http.host; content:"87.120.196.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898361/; classtype:trojan-activity;sid:84761461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/yl2g3svth10bgzd/file"; depth:26; endswith; nocase; http.host; content:"www.mediafire.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898359/; classtype:trojan-activity;sid:84761459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898357/; classtype:trojan-activity;sid:84761457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898358/; classtype:trojan-activity;sid:84761458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.217.97.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898356/; classtype:trojan-activity;sid:84761456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.217.97.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898355/; classtype:trojan-activity;sid:84761455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys/a/ec_puller.vbs"; depth:20; endswith; nocase; http.host; content:"156.246.95.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898352/; classtype:trojan-activity;sid:84761452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys/a/test.exe"; depth:15; endswith; nocase; http.host; content:"156.246.95.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898353/; classtype:trojan-activity;sid:84761453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys/a/34534.exe"; depth:16; endswith; nocase; http.host; content:"156.246.95.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898354/; classtype:trojan-activity;sid:84761454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys/a/white_notepad_rcdata.vbs"; depth:31; endswith; nocase; http.host; content:"156.246.95.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898351/; classtype:trojan-activity;sid:84761451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/666.exe"; depth:8; endswith; nocase; http.host; content:"hindustanagency.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898350/; classtype:trojan-activity;sid:84761450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"85.137.245.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898349/; classtype:trojan-activity;sid:84761449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.exe"; depth:6; endswith; nocase; http.host; content:"85.137.245.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898348/; classtype:trojan-activity;sid:84761448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv4eb"; depth:17; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898332/; classtype:trojan-activity;sid:84761432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv6l"; depth:16; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898333/; classtype:trojan-activity;sid:84761433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.x86_64"; depth:16; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898334/; classtype:trojan-activity;sid:84761434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.i586"; depth:14; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898335/; classtype:trojan-activity;sid:84761435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv7l"; depth:16; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898336/; classtype:trojan-activity;sid:84761436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.i486"; depth:14; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898337/; classtype:trojan-activity;sid:84761437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.powerpc"; depth:17; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898338/; classtype:trojan-activity;sid:84761438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.mips64"; depth:16; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898339/; classtype:trojan-activity;sid:84761439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.mipsel"; depth:16; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898340/; classtype:trojan-activity;sid:84761440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.sh4"; depth:13; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898341/; classtype:trojan-activity;sid:84761441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.m68k"; depth:14; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898342/; classtype:trojan-activity;sid:84761442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv4tl"; depth:17; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898343/; classtype:trojan-activity;sid:84761443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv4l"; depth:16; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898344/; classtype:trojan-activity;sid:84761444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.i686"; depth:14; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898345/; classtype:trojan-activity;sid:84761445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.mips"; depth:14; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898346/; classtype:trojan-activity;sid:84761446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.armv5l"; depth:16; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898347/; classtype:trojan-activity;sid:84761447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bin.powerpc-440fp"; depth:23; endswith; nocase; http.host; content:"94.154.43.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898331/; classtype:trojan-activity;sid:84761431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.239.66.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898330/; classtype:trojan-activity;sid:84761430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"104.239.66.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898329/; classtype:trojan-activity;sid:84761429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898328/; classtype:trojan-activity;sid:84761428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898327/; classtype:trojan-activity;sid:84761427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898326/; classtype:trojan-activity;sid:84761426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.80"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898324/; classtype:trojan-activity;sid:84761424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.80"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898325/; classtype:trojan-activity;sid:84761425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898323/; classtype:trojan-activity;sid:84761423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898322/; classtype:trojan-activity;sid:84761422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.217.97.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898321/; classtype:trojan-activity;sid:84761421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898320/; classtype:trojan-activity;sid:84761420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898319/; classtype:trojan-activity;sid:84761419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"194.26.192.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898316/; classtype:trojan-activity;sid:84761416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"192.159.99.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898317/; classtype:trojan-activity;sid:84761417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"45.88.186.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898318/; classtype:trojan-activity;sid:84761418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"45.88.186.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898313/; classtype:trojan-activity;sid:84761413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"194.26.192.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898314/; classtype:trojan-activity;sid:84761414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"192.159.99.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898315/; classtype:trojan-activity;sid:84761415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"178.16.55.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898312/; classtype:trojan-activity;sid:84761412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"178.16.55.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898311/; classtype:trojan-activity;sid:84761411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x"; depth:2; endswith; nocase; http.host; content:"195.177.94.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898310/; classtype:trojan-activity;sid:84761410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.exe"; depth:6; endswith; nocase; http.host; content:"195.177.94.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898309/; classtype:trojan-activity;sid:84761409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; depth:30; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898295/; classtype:trojan-activity;sid:84761395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; depth:33; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898296/; classtype:trojan-activity;sid:84761396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; depth:33; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898297/; classtype:trojan-activity;sid:84761397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898298/; classtype:trojan-activity;sid:84761398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; depth:33; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898299/; classtype:trojan-activity;sid:84761399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; depth:32; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898300/; classtype:trojan-activity;sid:84761400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; depth:29; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898301/; classtype:trojan-activity;sid:84761401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; depth:30; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898302/; classtype:trojan-activity;sid:84761402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; depth:30; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898303/; classtype:trojan-activity;sid:84761403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; depth:36; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898304/; classtype:trojan-activity;sid:84761404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; depth:37; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898305/; classtype:trojan-activity;sid:84761405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; depth:29; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898306/; classtype:trojan-activity;sid:84761406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; depth:33; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898307/; classtype:trojan-activity;sid:84761407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; depth:30; endswith; nocase; http.host; content:"45.135.194.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898308/; classtype:trojan-activity;sid:84761408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898278/; classtype:trojan-activity;sid:84761378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898279/; classtype:trojan-activity;sid:84761379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898280/; classtype:trojan-activity;sid:84761380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898281/; classtype:trojan-activity;sid:84761381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898282/; classtype:trojan-activity;sid:84761382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898283/; classtype:trojan-activity;sid:84761383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898284/; classtype:trojan-activity;sid:84761384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898285/; classtype:trojan-activity;sid:84761385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsrouter"; depth:16; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898286/; classtype:trojan-activity;sid:84761386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898287/; classtype:trojan-activity;sid:84761387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898288/; classtype:trojan-activity;sid:84761388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898289/; classtype:trojan-activity;sid:84761389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898290/; classtype:trojan-activity;sid:84761390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898291/; classtype:trojan-activity;sid:84761391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telnet.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898292/; classtype:trojan-activity;sid:84761392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898293/; classtype:trojan-activity;sid:84761393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"94.154.43.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898294/; classtype:trojan-activity;sid:84761394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psh4"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898270/; classtype:trojan-activity;sid:84761370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pmpsl"; depth:6; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898271/; classtype:trojan-activity;sid:84761371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898272/; classtype:trojan-activity;sid:84761372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898273/; classtype:trojan-activity;sid:84761373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/px86"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898274/; classtype:trojan-activity;sid:84761374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898275/; classtype:trojan-activity;sid:84761375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pm68k"; depth:6; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898276/; classtype:trojan-activity;sid:84761376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pppc"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898277/; classtype:trojan-activity;sid:84761377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898247/; classtype:trojan-activity;sid:84761347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898248/; classtype:trojan-activity;sid:84761348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898249/; classtype:trojan-activity;sid:84761349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898250/; classtype:trojan-activity;sid:84761350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898251/; classtype:trojan-activity;sid:84761351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898252/; classtype:trojan-activity;sid:84761352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898253/; classtype:trojan-activity;sid:84761353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm6"; depth:6; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898254/; classtype:trojan-activity;sid:84761354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898255/; classtype:trojan-activity;sid:84761355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pmips"; depth:6; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898256/; classtype:trojan-activity;sid:84761356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898257/; classtype:trojan-activity;sid:84761357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kla.sh"; depth:7; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898258/; classtype:trojan-activity;sid:84761358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm7"; depth:6; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898259/; classtype:trojan-activity;sid:84761359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm5"; depth:6; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898260/; classtype:trojan-activity;sid:84761360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898261/; classtype:trojan-activity;sid:84761361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898262/; classtype:trojan-activity;sid:84761362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898263/; classtype:trojan-activity;sid:84761363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898264/; classtype:trojan-activity;sid:84761364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898265/; classtype:trojan-activity;sid:84761365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898266/; classtype:trojan-activity;sid:84761366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898267/; classtype:trojan-activity;sid:84761367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898268/; classtype:trojan-activity;sid:84761368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898269/; classtype:trojan-activity;sid:84761369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898246/; classtype:trojan-activity;sid:84761346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898242/; classtype:trojan-activity;sid:84761342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898243/; classtype:trojan-activity;sid:84761343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898244/; classtype:trojan-activity;sid:84761344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898245/; classtype:trojan-activity;sid:84761345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898237/; classtype:trojan-activity;sid:84761337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telnet.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898238/; classtype:trojan-activity;sid:84761338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898239/; classtype:trojan-activity;sid:84761339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898240/; classtype:trojan-activity;sid:84761340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"94.154.43.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898241/; classtype:trojan-activity;sid:84761341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arc"; depth:21; endswith; nocase; http.host; content:"94.154.43.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898236/; classtype:trojan-activity;sid:84761336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898229/; classtype:trojan-activity;sid:84761329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl.sh"; depth:6; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898230/; classtype:trojan-activity;sid:84761330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips64"; depth:7; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898231/; classtype:trojan-activity;sid:84761331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riscv64"; depth:8; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898232/; classtype:trojan-activity;sid:84761332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc64"; depth:6; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898233/; classtype:trojan-activity;sid:84761333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898234/; classtype:trojan-activity;sid:84761334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s390x"; depth:6; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898235/; classtype:trojan-activity;sid:84761335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898218/; classtype:trojan-activity;sid:84761318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898219/; classtype:trojan-activity;sid:84761319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898220/; classtype:trojan-activity;sid:84761320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898221/; classtype:trojan-activity;sid:84761321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898222/; classtype:trojan-activity;sid:84761322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898223/; classtype:trojan-activity;sid:84761323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898224/; classtype:trojan-activity;sid:84761324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898225/; classtype:trojan-activity;sid:84761325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898226/; classtype:trojan-activity;sid:84761326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898227/; classtype:trojan-activity;sid:84761327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"94.154.43.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898228/; classtype:trojan-activity;sid:84761328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg10"; depth:5; endswith; nocase; http.host; content:"94.154.43.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898216/; classtype:trojan-activity;sid:84761316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg2"; depth:4; endswith; nocase; http.host; content:"94.154.43.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898217/; classtype:trojan-activity;sid:84761317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4ac22b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898215/; classtype:trojan-activity;sid:84761315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6ff88d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898204/; classtype:trojan-activity;sid:84761304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22a922"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898205/; classtype:trojan-activity;sid:84761305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e5508a"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898206/; classtype:trojan-activity;sid:84761306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/200d87"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898207/; classtype:trojan-activity;sid:84761307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2c854b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898208/; classtype:trojan-activity;sid:84761308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7d45dd"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898209/; classtype:trojan-activity;sid:84761309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dfaf27"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898210/; classtype:trojan-activity;sid:84761310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/345295"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898211/; classtype:trojan-activity;sid:84761311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e1fa95"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898212/; classtype:trojan-activity;sid:84761312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/554627"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898213/; classtype:trojan-activity;sid:84761313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/242649"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898214/; classtype:trojan-activity;sid:84761314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f3377f"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898203/; classtype:trojan-activity;sid:84761303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"72.255.19.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898199/; classtype:trojan-activity;sid:84761299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/11680a"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898200/; classtype:trojan-activity;sid:84761300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6b9c63"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898201/; classtype:trojan-activity;sid:84761301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/353bb3"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898202/; classtype:trojan-activity;sid:84761302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/574527"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898191/; classtype:trojan-activity;sid:84761291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7770c3"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898192/; classtype:trojan-activity;sid:84761292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eaa148"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898193/; classtype:trojan-activity;sid:84761293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/84f233"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898194/; classtype:trojan-activity;sid:84761294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d31ff9"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898195/; classtype:trojan-activity;sid:84761295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8a8980"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898196/; classtype:trojan-activity;sid:84761296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/178e82"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898197/; classtype:trojan-activity;sid:84761297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a41540"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898198/; classtype:trojan-activity;sid:84761298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9926d5"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898176/; classtype:trojan-activity;sid:84761276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9ab936"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898177/; classtype:trojan-activity;sid:84761277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/84f233"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898178/; classtype:trojan-activity;sid:84761278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/03bf77"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898179/; classtype:trojan-activity;sid:84761279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6fc486"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898180/; classtype:trojan-activity;sid:84761280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/11680a"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898181/; classtype:trojan-activity;sid:84761281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6b9c63"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898182/; classtype:trojan-activity;sid:84761282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/353bb3"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898183/; classtype:trojan-activity;sid:84761283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tplink.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898184/; classtype:trojan-activity;sid:84761284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eaa148"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898185/; classtype:trojan-activity;sid:84761285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cea2b"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898186/; classtype:trojan-activity;sid:84761286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e4bce9"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898187/; classtype:trojan-activity;sid:84761287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1b111f"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898188/; classtype:trojan-activity;sid:84761288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/79b487"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898189/; classtype:trojan-activity;sid:84761289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6fc486"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898190/; classtype:trojan-activity;sid:84761290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/tbk"; depth:7; endswith; nocase; http.host; content:"45.205.1.132"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898174/; classtype:trojan-activity;sid:84761274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/lterouter"; depth:13; endswith; nocase; http.host; content:"45.205.1.132"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898175/; classtype:trojan-activity;sid:84761275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898161/; classtype:trojan-activity;sid:84761261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898162/; classtype:trojan-activity;sid:84761262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898163/; classtype:trojan-activity;sid:84761263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898164/; classtype:trojan-activity;sid:84761264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mipsel"; depth:12; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898165/; classtype:trojan-activity;sid:84761265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898166/; classtype:trojan-activity;sid:84761266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898167/; classtype:trojan-activity;sid:84761267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898168/; classtype:trojan-activity;sid:84761268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898169/; classtype:trojan-activity;sid:84761269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898170/; classtype:trojan-activity;sid:84761270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898171/; classtype:trojan-activity;sid:84761271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898172/; classtype:trojan-activity;sid:84761272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898173/; classtype:trojan-activity;sid:84761273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.mpsl"; depth:14; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898149/; classtype:trojan-activity;sid:84761249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.sh4"; depth:13; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898150/; classtype:trojan-activity;sid:84761250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.m68k"; depth:14; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898151/; classtype:trojan-activity;sid:84761251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm7"; depth:14; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898152/; classtype:trojan-activity;sid:84761252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.x86_64"; depth:16; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898153/; classtype:trojan-activity;sid:84761253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.spc"; depth:13; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898154/; classtype:trojan-activity;sid:84761254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm6"; depth:14; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898155/; classtype:trojan-activity;sid:84761255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.x86"; depth:13; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898156/; classtype:trojan-activity;sid:84761256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.mips"; depth:14; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898157/; classtype:trojan-activity;sid:84761257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.i686"; depth:14; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898158/; classtype:trojan-activity;sid:84761258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.ppc"; depth:13; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898159/; classtype:trojan-activity;sid:84761259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm5"; depth:14; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898160/; classtype:trojan-activity;sid:84761260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fxrgbtj/gxcjtky/zkeibpn/stego_4ehpd80tsq.png"; depth:45; endswith; nocase; http.host; content:"www.knockknock.top"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898148/; classtype:trojan-activity;sid:84761248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proot"; depth:6; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898127/; classtype:trojan-activity;sid:84761227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1"; depth:2; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898128/; classtype:trojan-activity;sid:84761228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldercheck.sh"; depth:14; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898129/; classtype:trojan-activity;sid:84761229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cliaarch"; depth:9; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898130/; classtype:trojan-activity;sid:84761230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto"; depth:5; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898131/; classtype:trojan-activity;sid:84761231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main"; depth:5; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898132/; classtype:trojan-activity;sid:84761232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oldboss"; depth:8; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898133/; classtype:trojan-activity;sid:84761233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traff"; depth:6; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898134/; classtype:trojan-activity;sid:84761234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check1.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898135/; classtype:trojan-activity;sid:84761235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loli"; depth:5; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898136/; classtype:trojan-activity;sid:84761236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cli"; depth:4; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898137/; classtype:trojan-activity;sid:84761237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check.sh"; depth:9; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898138/; classtype:trojan-activity;sid:84761238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/checkmacos.sh"; depth:14; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898139/; classtype:trojan-activity;sid:84761239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boss"; depth:5; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898140/; classtype:trojan-activity;sid:84761240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traffaarch"; depth:11; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898141/; classtype:trojan-activity;sid:84761241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto1"; depth:6; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898142/; classtype:trojan-activity;sid:84761242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wd1337"; depth:7; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898143/; classtype:trojan-activity;sid:84761243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syst3md"; depth:8; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898144/; classtype:trojan-activity;sid:84761244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvidia.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898145/; classtype:trojan-activity;sid:84761245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/error84"; depth:8; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898146/; classtype:trojan-activity;sid:84761246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/log"; depth:4; endswith; nocase; http.host; content:"94.154.43.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898147/; classtype:trojan-activity;sid:84761247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/band/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"ryanborn.net"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898126/; classtype:trojan-activity;sid:84761226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http/2kcrypted.ps1"; depth:19; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898124/; classtype:trojan-activity;sid:84761224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/http/kcrypted.ps1"; depth:18; endswith; nocase; http.host; content:"178.16.53.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898125/; classtype:trojan-activity;sid:84761225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tools2.png"; depth:11; endswith; nocase; http.host; content:"pub-ce02802067934e0eb072f69bf6427bf6.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898123/; classtype:trojan-activity;sid:84761223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jjpe.png"; depth:9; endswith; nocase; http.host; content:"pub-ce02802067934e0eb072f69bf6427bf6.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898122/; classtype:trojan-activity;sid:84761222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bpvux"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898120/; classtype:trojan-activity;sid:84761220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.well-known/acme-challenge/sma.exe"; depth:35; endswith; nocase; http.host; content:"durakutihs.com"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898121/; classtype:trojan-activity;sid:84761221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hairlin.png"; depth:12; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898119/; classtype:trojan-activity;sid:84761219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_011230.png"; depth:15; endswith; nocase; http.host; content:"ifeanyioluwatobi.wuaze.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898117/; classtype:trojan-activity;sid:84761217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ucosn"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898118/; classtype:trojan-activity;sid:84761218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kbxaa"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898116/; classtype:trojan-activity;sid:84761216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljwev"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898114/; classtype:trojan-activity;sid:84761214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_022151.png"; depth:15; endswith; nocase; http.host; content:"ifeanyioluwatobi.wuaze.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898115/; classtype:trojan-activity;sid:84761215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bot.arm"; depth:13; endswith; nocase; http.host; content:"185.95.156.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898113/; classtype:trojan-activity;sid:84761213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/54ac4810b1d01207/ca06059d5d3d81d2.sh"; depth:37; endswith; nocase; http.host; content:"104.194.140.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898112/; classtype:trojan-activity;sid:84761212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty/load.bat"; depth:12; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898111/; classtype:trojan-activity;sid:84761211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty/p/cgnty_carrier.ahk"; depth:23; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898109/; classtype:trojan-activity;sid:84761209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty/v/client_carrier.ahk"; depth:24; endswith; nocase; http.host; content:"217.60.195.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898110/; classtype:trojan-activity;sid:84761210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cf8a08"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898097/; classtype:trojan-activity;sid:84761197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ccae61"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898098/; classtype:trojan-activity;sid:84761198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fbfaa3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898099/; classtype:trojan-activity;sid:84761199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/49ee5f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898100/; classtype:trojan-activity;sid:84761200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19845d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898101/; classtype:trojan-activity;sid:84761201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d6794d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898102/; classtype:trojan-activity;sid:84761202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9ee4ab"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898103/; classtype:trojan-activity;sid:84761203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8d415f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898104/; classtype:trojan-activity;sid:84761204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c0bec9"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898105/; classtype:trojan-activity;sid:84761205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8d9e3d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898106/; classtype:trojan-activity;sid:84761206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c9f1e6"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898107/; classtype:trojan-activity;sid:84761207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e13654"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898108/; classtype:trojan-activity;sid:84761208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86_64"; depth:10; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898088/; classtype:trojan-activity;sid:84761188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv6l"; depth:10; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898089/; classtype:trojan-activity;sid:84761189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv7l"; depth:10; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898090/; classtype:trojan-activity;sid:84761190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/ppc"; depth:7; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898091/; classtype:trojan-activity;sid:84761191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/sparc"; depth:9; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898092/; classtype:trojan-activity;sid:84761192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/sh4"; depth:7; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898093/; classtype:trojan-activity;sid:84761193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv4l"; depth:10; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898094/; classtype:trojan-activity;sid:84761194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/aarch64"; depth:11; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898095/; classtype:trojan-activity;sid:84761195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/m68k"; depth:8; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898096/; classtype:trojan-activity;sid:84761196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xz/bin%20(2)upload%20(1).txt"; depth:29; endswith; nocase; http.host; content:"216.9.224.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898087/; classtype:trojan-activity;sid:84761187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yuxwormaugust.png"; depth:18; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898085/; classtype:trojan-activity;sid:84761185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rumpaugust.png"; depth:15; endswith; nocase; http.host; content:"193.104.58.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898086/; classtype:trojan-activity;sid:84761186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.i586"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898084/; classtype:trojan-activity;sid:84761184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wordpress/wp-content/plugins/zxzxzx/stego_588ean488k.png"; depth:57; endswith; nocase; http.host; content:"www.hqsblog.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898083/; classtype:trojan-activity;sid:84761183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.x86_64"; depth:12; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898082/; classtype:trojan-activity;sid:84761182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.sh4"; depth:9; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898069/; classtype:trojan-activity;sid:84761169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.arc"; depth:9; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898070/; classtype:trojan-activity;sid:84761170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.m68k"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898071/; classtype:trojan-activity;sid:84761171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.arm64"; depth:11; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898072/; classtype:trojan-activity;sid:84761172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.i386"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898073/; classtype:trojan-activity;sid:84761173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.arm5"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898074/; classtype:trojan-activity;sid:84761174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.i686"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898075/; classtype:trojan-activity;sid:84761175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.arm6"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898076/; classtype:trojan-activity;sid:84761176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.arm7"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898077/; classtype:trojan-activity;sid:84761177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.i486"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898078/; classtype:trojan-activity;sid:84761178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.arm4"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898079/; classtype:trojan-activity;sid:84761179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.sparc"; depth:11; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898080/; classtype:trojan-activity;sid:84761180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.x86"; depth:9; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898081/; classtype:trojan-activity;sid:84761181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.ppc"; depth:9; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898068/; classtype:trojan-activity;sid:84761168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.mipsel"; depth:12; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898067/; classtype:trojan-activity;sid:84761167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"152.32.240.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898066/; classtype:trojan-activity;sid:84761166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/admin/bin.exe"; depth:25; endswith; nocase; http.host; content:"golvteametvarberg.se"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898065/; classtype:trojan-activity;sid:84761165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/router_drop.sh"; depth:15; endswith; nocase; http.host; content:"144.172.105.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898063/; classtype:trojan-activity;sid:84761163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/router_drop.sh"; depth:15; endswith; nocase; http.host; content:"144.172.105.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898064/; classtype:trojan-activity;sid:84761164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b086772f70506436.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898061/; classtype:trojan-activity;sid:84761161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/img_014109.png"; depth:18; endswith; nocase; http.host; content:"172.245.195.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898060/; classtype:trojan-activity;sid:84761160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/wegivingbestthingsfromthebestpeopelsforme.hta"; depth:49; endswith; nocase; http.host; content:"172.245.195.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898059/; classtype:trojan-activity;sid:84761159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pope.mips"; depth:10; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898058/; classtype:trojan-activity;sid:84761158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agent.bin"; depth:10; endswith; nocase; http.host; content:"193.26.115.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898057/; classtype:trojan-activity;sid:84761157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.py"; depth:5; endswith; nocase; http.host; content:"193.26.115.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898056/; classtype:trojan-activity;sid:84761156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.136.139"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898055/; classtype:trojan-activity;sid:84761155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.116.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898054/; classtype:trojan-activity;sid:84761154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.92.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898053/; classtype:trojan-activity;sid:84761153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3be3fa630977796a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898052/; classtype:trojan-activity;sid:84761152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main/x.bat"; depth:11; endswith; nocase; http.host; content:"45.83.31.27"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898050/; classtype:trojan-activity;sid:84761150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/purev2.bat"; depth:11; endswith; nocase; http.host; content:"45.83.31.27"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898051/; classtype:trojan-activity;sid:84761151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.108.27.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898049/; classtype:trojan-activity;sid:84761149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/armv7l"; depth:12; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898035/; classtype:trojan-activity;sid:84761135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/armv6l"; depth:12; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898036/; classtype:trojan-activity;sid:84761136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898037/; classtype:trojan-activity;sid:84761137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898038/; classtype:trojan-activity;sid:84761138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898039/; classtype:trojan-activity;sid:84761139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898040/; classtype:trojan-activity;sid:84761140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898041/; classtype:trojan-activity;sid:84761141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i586"; depth:10; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898042/; classtype:trojan-activity;sid:84761142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898043/; classtype:trojan-activity;sid:84761143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898044/; classtype:trojan-activity;sid:84761144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898045/; classtype:trojan-activity;sid:84761145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898046/; classtype:trojan-activity;sid:84761146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x64"; depth:4; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898047/; classtype:trojan-activity;sid:84761147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mipsel"; depth:12; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898048/; classtype:trojan-activity;sid:84761148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.92.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898034/; classtype:trojan-activity;sid:84761134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898029/; classtype:trojan-activity;sid:84761129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898030/; classtype:trojan-activity;sid:84761130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/armv5l"; depth:12; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898031/; classtype:trojan-activity;sid:84761131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/armv4l"; depth:12; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898032/; classtype:trojan-activity;sid:84761132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898033/; classtype:trojan-activity;sid:84761133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898028/; classtype:trojan-activity;sid:84761128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898025/; classtype:trojan-activity;sid:84761125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv7l"; depth:13; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898026/; classtype:trojan-activity;sid:84761126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.x86_64"; depth:13; endswith; nocase; http.host; content:"94.154.43.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898027/; classtype:trojan-activity;sid:84761127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.93.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898024/; classtype:trojan-activity;sid:84761124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.119.177"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898023/; classtype:trojan-activity;sid:84761123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.92.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898022/; classtype:trojan-activity;sid:84761122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898015/; classtype:trojan-activity;sid:84761115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898016/; classtype:trojan-activity;sid:84761116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898017/; classtype:trojan-activity;sid:84761117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898018/; classtype:trojan-activity;sid:84761118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898019/; classtype:trojan-activity;sid:84761119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x64"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898020/; classtype:trojan-activity;sid:84761120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898021/; classtype:trojan-activity;sid:84761121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_spc"; depth:9; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898011/; classtype:trojan-activity;sid:84761111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898012/; classtype:trojan-activity;sid:84761112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mpsl"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898013/; classtype:trojan-activity;sid:84761113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898014/; classtype:trojan-activity;sid:84761114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898009/; classtype:trojan-activity;sid:84761109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898010/; classtype:trojan-activity;sid:84761110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.201.173"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898008/; classtype:trojan-activity;sid:84761108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.8.131.222"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898007/; classtype:trojan-activity;sid:84761107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.186.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898006/; classtype:trojan-activity;sid:84761106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.119.177"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898005/; classtype:trojan-activity;sid:84761105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.229.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898004/; classtype:trojan-activity;sid:84761104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.214.7"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898003/; classtype:trojan-activity;sid:84761103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.92.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898002/; classtype:trojan-activity;sid:84761102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.229.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898001/; classtype:trojan-activity;sid:84761101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.137.87"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898000/; classtype:trojan-activity;sid:84761100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/72/weneedbestthingsfromthebetterplacesonthis.hta"; depth:49; endswith; nocase; http.host; content:"107.172.172.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897999/; classtype:trojan-activity;sid:84761099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/img_010818.png"; depth:18; endswith; nocase; http.host; content:"155.103.69.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897998/; classtype:trojan-activity;sid:84761098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/wegivingbestthingsforbetterplacescoming.hta"; depth:47; endswith; nocase; http.host; content:"155.103.69.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897997/; classtype:trojan-activity;sid:84761097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/img_231911.png"; depth:18; endswith; nocase; http.host; content:"107.173.9.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897996/; classtype:trojan-activity;sid:84761096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/goodthingsfromtheheartformebestfeelsgivingforme.hta"; depth:55; endswith; nocase; http.host; content:"107.173.9.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897995/; classtype:trojan-activity;sid:84761095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/65/img_234612.png"; depth:18; endswith; nocase; http.host; content:"172.245.209.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897994/; classtype:trojan-activity;sid:84761094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/65/goodthingsfromebestthings.hta"; depth:33; endswith; nocase; http.host; content:"172.245.209.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897993/; classtype:trojan-activity;sid:84761093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_110418.png"; depth:15; endswith; nocase; http.host; content:"pocopaco.co.za"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897992/; classtype:trojan-activity;sid:84761092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wsojf"; depth:6; endswith; nocase; http.host; content:"muddy-sound-e0cd.nodetectonn.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897991/; classtype:trojan-activity;sid:84761091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/php/marleee.exe"; depth:16; endswith; nocase; http.host; content:"pzc.za.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897990/; classtype:trojan-activity;sid:84761090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/php/server64.exe"; depth:17; endswith; nocase; http.host; content:"pzc.za.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897989/; classtype:trojan-activity;sid:84761089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.137.87"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897988/; classtype:trojan-activity;sid:84761088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_pro.png"; depth:12; endswith; nocase; http.host; content:"czd.ru.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897986/; classtype:trojan-activity;sid:84761086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_035342.png"; depth:15; endswith; nocase; http.host; content:"czd.ru.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897987/; classtype:trojan-activity;sid:84761087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.207.87.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897985/; classtype:trojan-activity;sid:84761085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/donwnload/prortonvpn_x64.zip"; depth:29; endswith; nocase; http.host; content:"download.tfyxzai.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897984/; classtype:trojan-activity;sid:84761084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mvfc9q2xawgyn"; depth:14; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897971/; classtype:trojan-activity;sid:84761071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w4hp6eiyaelevhksxokzt5d"; depth:24; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897972/; classtype:trojan-activity;sid:84761072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ehx5xztkroxr4jn4wh"; depth:19; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897973/; classtype:trojan-activity;sid:84761073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6fspmtcfgkbne"; depth:14; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897974/; classtype:trojan-activity;sid:84761074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xvtfqxhdh4bg5b35n"; depth:18; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897975/; classtype:trojan-activity;sid:84761075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rzcjmzzbbuupb9iqnwbv"; depth:21; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897976/; classtype:trojan-activity;sid:84761076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/by3qx89m2zrjcwtcs"; depth:18; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897977/; classtype:trojan-activity;sid:84761077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1eft8fihbzbfvm"; depth:15; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897978/; classtype:trojan-activity;sid:84761078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/glh0d23omm0ah0mafyfy02gu"; depth:25; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897979/; classtype:trojan-activity;sid:84761079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/q9xfy2yyfbbg"; depth:13; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897980/; classtype:trojan-activity;sid:84761080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z15mz0moiihadjlu"; depth:17; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897981/; classtype:trojan-activity;sid:84761081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ezp1mgj8v4ucjmiy"; depth:17; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897982/; classtype:trojan-activity;sid:84761082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zyclkioqolicq"; depth:14; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897983/; classtype:trojan-activity;sid:84761083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyrbuiuuohppsyyvmc7z"; depth:21; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897958/; classtype:trojan-activity;sid:84761058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w8sawm68jrunx0l"; depth:16; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897959/; classtype:trojan-activity;sid:84761059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yczggwjkml47uyxizwgf2"; depth:22; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897960/; classtype:trojan-activity;sid:84761060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bc41olre38dfo"; depth:14; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897961/; classtype:trojan-activity;sid:84761061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6ltxifkpdhps1kabhn7gr"; depth:22; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897962/; classtype:trojan-activity;sid:84761062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9cscjtag4xftcfpfvwcqx"; depth:22; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897963/; classtype:trojan-activity;sid:84761063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7y1krq6rbduf0row"; depth:17; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897964/; classtype:trojan-activity;sid:84761064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fdp5xoj0ir7jxy6"; depth:16; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897965/; classtype:trojan-activity;sid:84761065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vd8vmkjbsku6fhucxmp9j7bj"; depth:25; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897966/; classtype:trojan-activity;sid:84761066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vtq9wafukyukd5slsra"; depth:20; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897967/; classtype:trojan-activity;sid:84761067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/njtykmeb9ycufz1g71kjpm"; depth:23; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897968/; classtype:trojan-activity;sid:84761068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8zjzw203dg2wluqs"; depth:17; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897969/; classtype:trojan-activity;sid:84761069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4lslvdsqr4utwo99o11qgb59"; depth:25; endswith; nocase; http.host; content:"178.16.54.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897970/; classtype:trojan-activity;sid:84761070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.22.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897957/; classtype:trojan-activity;sid:84761057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv5l"; depth:10; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897956/; classtype:trojan-activity;sid:84761056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86"; depth:7; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897954/; classtype:trojan-activity;sid:84761054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/tbk"; depth:7; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897955/; classtype:trojan-activity;sid:84761055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.25.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897953/; classtype:trojan-activity;sid:84761053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t3swaz48/image/upload/v1785999006/img_024854_mjepaa.jpg"; depth:56; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897952/; classtype:trojan-activity;sid:84761052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.57.63.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897951/; classtype:trojan-activity;sid:84761051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.180.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897950/; classtype:trojan-activity;sid:84761050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader.sh"; depth:10; endswith; nocase; http.host; content:"91.92.40.18"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897949/; classtype:trojan-activity;sid:84761049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv4tl"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897947/; classtype:trojan-activity;sid:84761047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86_64"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897948/; classtype:trojan-activity;sid:84761048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.e300c3"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897946/; classtype:trojan-activity;sid:84761046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.arm7"; depth:10; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897937/; classtype:trojan-activity;sid:84761037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv7-eabihf"; depth:18; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897938/; classtype:trojan-activity;sid:84761038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.arc700"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897939/; classtype:trojan-activity;sid:84761039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips32el"; depth:14; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897940/; classtype:trojan-activity;sid:84761040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.riscv64"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897941/; classtype:trojan-activity;sid:84761041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv4eb"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897942/; classtype:trojan-activity;sid:84761042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.microblazebe"; depth:18; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897943/; classtype:trojan-activity;sid:84761043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.xtensa"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897944/; classtype:trojan-activity;sid:84761044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m"; depth:2; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897945/; classtype:trojan-activity;sid:84761045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.archs38"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897935/; classtype:trojan-activity;sid:84761035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armebv7"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897936/; classtype:trojan-activity;sid:84761036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.sparc"; depth:11; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897922/; classtype:trojan-activity;sid:84761022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips64"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897923/; classtype:trojan-activity;sid:84761023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv6-eabihf"; depth:18; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897924/; classtype:trojan-activity;sid:84761024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.riscv32"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897925/; classtype:trojan-activity;sid:84761025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.microblazeel"; depth:18; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897926/; classtype:trojan-activity;sid:84761026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.powerpc"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897927/; classtype:trojan-activity;sid:84761027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897928/; classtype:trojan-activity;sid:84761028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv6"; depth:11; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897929/; classtype:trojan-activity;sid:84761029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.openrisc"; depth:14; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897930/; classtype:trojan-activity;sid:84761030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips"; depth:10; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897931/; classtype:trojan-activity;sid:84761031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv5"; depth:11; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897932/; classtype:trojan-activity;sid:84761032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tplink.sh"; depth:10; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897933/; classtype:trojan-activity;sid:84761033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv4"; depth:11; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897934/; classtype:trojan-activity;sid:84761034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.sh4"; depth:9; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897916/; classtype:trojan-activity;sid:84761016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.i486"; depth:10; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897917/; classtype:trojan-activity;sid:84761017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.aarch64"; depth:13; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897918/; classtype:trojan-activity;sid:84761018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv5-eabi"; depth:16; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897919/; classtype:trojan-activity;sid:84761019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mipsel"; depth:12; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897920/; classtype:trojan-activity;sid:84761020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.nios2"; depth:11; endswith; nocase; http.host; content:"130.12.182.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897921/; classtype:trojan-activity;sid:84761021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.180.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897915/; classtype:trojan-activity;sid:84761015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.172.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897914/; classtype:trojan-activity;sid:84761014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.172.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897913/; classtype:trojan-activity;sid:84761013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.254.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897912/; classtype:trojan-activity;sid:84761012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.25.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897911/; classtype:trojan-activity;sid:84761011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.237.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897910/; classtype:trojan-activity;sid:84761010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.96.93.32"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897909/; classtype:trojan-activity;sid:84761009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.198.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897908/; classtype:trojan-activity;sid:84761008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.100.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897907/; classtype:trojan-activity;sid:84761007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.87.169.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897906/; classtype:trojan-activity;sid:84761006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.153.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897905/; classtype:trojan-activity;sid:84761005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.153.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897904/; classtype:trojan-activity;sid:84761004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.166.115.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897903/; classtype:trojan-activity;sid:84761003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.202.233.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897902/; classtype:trojan-activity;sid:84761002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.168.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897901/; classtype:trojan-activity;sid:84761001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.80.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897900/; classtype:trojan-activity;sid:84761000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.100.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897899/; classtype:trojan-activity;sid:84760999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.89.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897898/; classtype:trojan-activity;sid:84760998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.80.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897897/; classtype:trojan-activity;sid:84760997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.187.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897896/; classtype:trojan-activity;sid:84760996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/ghs5xorewgj943fx9dgr7/screenconnectsetup.exe|3f|rlkey=7qg95my97ne53jhdmu7c7arex|7c|26|7c|st=zhed4h5r|7c|26|7c|dl=1"; depth:122; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897895/; classtype:trojan-activity;sid:84760995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/kni67o628yiiw4hj8yocy/screenconnectsetup.exe|3f|rlkey=3r9x5bfzav1oxwjq1goajtm5s|7c|26|7c|st=6cuqqcrw|7c|26|7c|dl=1"; depth:122; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897894/; classtype:trojan-activity;sid:84760994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.220.145.167"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897893/; classtype:trojan-activity;sid:84760993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mips"; depth:8; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897890/; classtype:trojan-activity;sid:84760990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mpsl"; depth:8; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897891/; classtype:trojan-activity;sid:84760991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/lterouter"; depth:13; endswith; nocase; http.host; content:"103.83.86.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897892/; classtype:trojan-activity;sid:84760992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"38.21.70.189"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897889/; classtype:trojan-activity;sid:84760989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.22.188.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897888/; classtype:trojan-activity;sid:84760988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.33.121"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897887/; classtype:trojan-activity;sid:84760987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.42.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897885/; classtype:trojan-activity;sid:84760985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"81.227.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897886/; classtype:trojan-activity;sid:84760986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.58.234.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897875/; classtype:trojan-activity;sid:84760975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.31.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897876/; classtype:trojan-activity;sid:84760976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.241.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897877/; classtype:trojan-activity;sid:84760977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.42.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897878/; classtype:trojan-activity;sid:84760978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.241.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897879/; classtype:trojan-activity;sid:84760979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.191.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897880/; classtype:trojan-activity;sid:84760980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.240.195"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897881/; classtype:trojan-activity;sid:84760981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.191.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897882/; classtype:trojan-activity;sid:84760982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.22.188.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897883/; classtype:trojan-activity;sid:84760983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.147.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897884/; classtype:trojan-activity;sid:84760984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.150.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897863/; classtype:trojan-activity;sid:84760963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.35.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897864/; classtype:trojan-activity;sid:84760964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.148.52.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897865/; classtype:trojan-activity;sid:84760965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897866/; classtype:trojan-activity;sid:84760966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.33.121"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897867/; classtype:trojan-activity;sid:84760967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.148.52.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897868/; classtype:trojan-activity;sid:84760968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.48.115.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897869/; classtype:trojan-activity;sid:84760969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.48.115.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897870/; classtype:trojan-activity;sid:84760970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.194.25.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897871/; classtype:trojan-activity;sid:84760971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.88.136.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897872/; classtype:trojan-activity;sid:84760972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.58.234.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897873/; classtype:trojan-activity;sid:84760973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.31.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897874/; classtype:trojan-activity;sid:84760974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"38.21.70.189"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897862/; classtype:trojan-activity;sid:84760962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"146.168.191.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897861/; classtype:trojan-activity;sid:84760961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.115.73.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897860/; classtype:trojan-activity;sid:84760960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.229.190.63"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897859/; classtype:trojan-activity;sid:84760959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.229.190.63"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897857/; classtype:trojan-activity;sid:84760957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.220.145.167"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897858/; classtype:trojan-activity;sid:84760958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.202.217.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897856/; classtype:trojan-activity;sid:84760956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.42.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897854/; classtype:trojan-activity;sid:84760954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.88.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897855/; classtype:trojan-activity;sid:84760955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.42.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897852/; classtype:trojan-activity;sid:84760952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.88.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897853/; classtype:trojan-activity;sid:84760953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.94.209.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897850/; classtype:trojan-activity;sid:84760950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.227.52.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897851/; classtype:trojan-activity;sid:84760951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.79.79"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897842/; classtype:trojan-activity;sid:84760942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.252.119"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897843/; classtype:trojan-activity;sid:84760943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.36.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897844/; classtype:trojan-activity;sid:84760944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.159.154.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897845/; classtype:trojan-activity;sid:84760945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897846/; classtype:trojan-activity;sid:84760946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.89.2"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897847/; classtype:trojan-activity;sid:84760947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.76.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897848/; classtype:trojan-activity;sid:84760948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.123.40.206"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897849/; classtype:trojan-activity;sid:84760949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.169.248.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897834/; classtype:trojan-activity;sid:84760934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.59.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897835/; classtype:trojan-activity;sid:84760935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.235.174.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897836/; classtype:trojan-activity;sid:84760936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897837/; classtype:trojan-activity;sid:84760937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.1.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897838/; classtype:trojan-activity;sid:84760938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.116.238.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897839/; classtype:trojan-activity;sid:84760939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897840/; classtype:trojan-activity;sid:84760940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.203.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897841/; classtype:trojan-activity;sid:84760941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.231.53"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897832/; classtype:trojan-activity;sid:84760932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.115.70.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897833/; classtype:trojan-activity;sid:84760933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.39.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897826/; classtype:trojan-activity;sid:84760926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.185.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897827/; classtype:trojan-activity;sid:84760927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.159.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897828/; classtype:trojan-activity;sid:84760928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.199.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897829/; classtype:trojan-activity;sid:84760929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.249.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897830/; classtype:trojan-activity;sid:84760930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897831/; classtype:trojan-activity;sid:84760931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/kal64"; depth:8; endswith; nocase; http.host; content:"194.59.31.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897820/; classtype:trojan-activity;sid:84760920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.77.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897821/; classtype:trojan-activity;sid:84760921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.29.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897822/; classtype:trojan-activity;sid:84760922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.188.2.208"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897823/; classtype:trojan-activity;sid:84760923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.239.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897824/; classtype:trojan-activity;sid:84760924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/amd64"; depth:8; endswith; nocase; http.host; content:"194.59.31.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897825/; classtype:trojan-activity;sid:84760925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"183.148.9.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897818/; classtype:trojan-activity;sid:84760918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.194.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897819/; classtype:trojan-activity;sid:84760919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.48.77"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897817/; classtype:trojan-activity;sid:84760917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.83.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897814/; classtype:trojan-activity;sid:84760914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.244.182"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897815/; classtype:trojan-activity;sid:84760915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.154.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897816/; classtype:trojan-activity;sid:84760916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.7.220.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897811/; classtype:trojan-activity;sid:84760911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.188.50"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897812/; classtype:trojan-activity;sid:84760912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.154.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897813/; classtype:trojan-activity;sid:84760913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.52.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897808/; classtype:trojan-activity;sid:84760908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.94.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897809/; classtype:trojan-activity;sid:84760909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.37.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897810/; classtype:trojan-activity;sid:84760910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.204.191"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897802/; classtype:trojan-activity;sid:84760902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.50.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897803/; classtype:trojan-activity;sid:84760903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.108.9.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897804/; classtype:trojan-activity;sid:84760904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.78.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897805/; classtype:trojan-activity;sid:84760905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.47.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897806/; classtype:trojan-activity;sid:84760906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.79.216"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897807/; classtype:trojan-activity;sid:84760907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.53.77.116"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897793/; classtype:trojan-activity;sid:84760893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.228.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897794/; classtype:trojan-activity;sid:84760894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897795/; classtype:trojan-activity;sid:84760895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.231.142.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897796/; classtype:trojan-activity;sid:84760896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"171.38.221.210"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897797/; classtype:trojan-activity;sid:84760897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.162.162"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897798/; classtype:trojan-activity;sid:84760898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.127.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897799/; classtype:trojan-activity;sid:84760899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.151.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897800/; classtype:trojan-activity;sid:84760900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.12.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897801/; classtype:trojan-activity;sid:84760901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.200.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897787/; classtype:trojan-activity;sid:84760887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"188.19.103.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897788/; classtype:trojan-activity;sid:84760888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.159.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897789/; classtype:trojan-activity;sid:84760889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.121.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897790/; classtype:trojan-activity;sid:84760890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.247.93"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897791/; classtype:trojan-activity;sid:84760891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.117.160.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897792/; classtype:trojan-activity;sid:84760892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.12.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897785/; classtype:trojan-activity;sid:84760885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.158.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897786/; classtype:trojan-activity;sid:84760886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.94.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897783/; classtype:trojan-activity;sid:84760883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.151.108"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897784/; classtype:trojan-activity;sid:84760884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.26.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897779/; classtype:trojan-activity;sid:84760879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.140.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897780/; classtype:trojan-activity;sid:84760880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.203.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897781/; classtype:trojan-activity;sid:84760881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.103.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897782/; classtype:trojan-activity;sid:84760882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.78.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897775/; classtype:trojan-activity;sid:84760875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.199.72.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897776/; classtype:trojan-activity;sid:84760876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/kal64"; depth:8; endswith; nocase; http.host; content:"194.59.31.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897777/; classtype:trojan-activity;sid:84760877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/amd64"; depth:8; endswith; nocase; http.host; content:"194.59.31.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897778/; classtype:trojan-activity;sid:84760878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.249.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897768/; classtype:trojan-activity;sid:84760868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.14.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897769/; classtype:trojan-activity;sid:84760869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.248.15.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897770/; classtype:trojan-activity;sid:84760870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.200.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897771/; classtype:trojan-activity;sid:84760871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.247.93"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897772/; classtype:trojan-activity;sid:84760872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.77.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897773/; classtype:trojan-activity;sid:84760873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.187.255.252"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897774/; classtype:trojan-activity;sid:84760874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.11.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897748/; classtype:trojan-activity;sid:84760848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.76.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897749/; classtype:trojan-activity;sid:84760849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897750/; classtype:trojan-activity;sid:84760850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.228.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897751/; classtype:trojan-activity;sid:84760851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.50.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897752/; classtype:trojan-activity;sid:84760852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.185.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897753/; classtype:trojan-activity;sid:84760853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.235.174.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897754/; classtype:trojan-activity;sid:84760854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.29.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897755/; classtype:trojan-activity;sid:84760855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.169.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897756/; classtype:trojan-activity;sid:84760856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.1.226.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897757/; classtype:trojan-activity;sid:84760857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897758/; classtype:trojan-activity;sid:84760858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.64.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897759/; classtype:trojan-activity;sid:84760859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.253.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897760/; classtype:trojan-activity;sid:84760860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.169.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897761/; classtype:trojan-activity;sid:84760861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.227.48.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897762/; classtype:trojan-activity;sid:84760862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.158.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897763/; classtype:trojan-activity;sid:84760863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.29.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897764/; classtype:trojan-activity;sid:84760864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/kswpad"; depth:9; endswith; nocase; http.host; content:"194.59.31.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897765/; classtype:trojan-activity;sid:84760865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/kswpad"; depth:9; endswith; nocase; http.host; content:"194.59.31.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897766/; classtype:trojan-activity;sid:84760866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.146.187"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897767/; classtype:trojan-activity;sid:84760867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.39.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897744/; classtype:trojan-activity;sid:84760844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.183.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897745/; classtype:trojan-activity;sid:84760845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"188.19.103.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897746/; classtype:trojan-activity;sid:84760846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.79.79"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897747/; classtype:trojan-activity;sid:84760847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.231.53"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897740/; classtype:trojan-activity;sid:84760840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"94.45.34.166"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897741/; classtype:trojan-activity;sid:84760841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.93.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897742/; classtype:trojan-activity;sid:84760842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"177.125.169.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897743/; classtype:trojan-activity;sid:84760843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.36.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897739/; classtype:trojan-activity;sid:84760839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.180.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897738/; classtype:trojan-activity;sid:84760838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.190.203.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897737/; classtype:trojan-activity;sid:84760837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.242.155.81"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897736/; classtype:trojan-activity;sid:84760836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.161.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897735/; classtype:trojan-activity;sid:84760835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.207.35.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897734/; classtype:trojan-activity;sid:84760834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.161.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897733/; classtype:trojan-activity;sid:84760833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.175.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897731/; classtype:trojan-activity;sid:84760831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.194.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897732/; classtype:trojan-activity;sid:84760832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.88.7.48"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897730/; classtype:trojan-activity;sid:84760830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.237.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897729/; classtype:trojan-activity;sid:84760829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.42.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897728/; classtype:trojan-activity;sid:84760828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.48.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897727/; classtype:trojan-activity;sid:84760827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.42.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897726/; classtype:trojan-activity;sid:84760826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.120.7.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897725/; classtype:trojan-activity;sid:84760825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3df873"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897713/; classtype:trojan-activity;sid:84760813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee130b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897714/; classtype:trojan-activity;sid:84760814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dd7bab"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897715/; classtype:trojan-activity;sid:84760815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e0b1f4"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897716/; classtype:trojan-activity;sid:84760816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f7dd3b"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897717/; classtype:trojan-activity;sid:84760817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dcc1f2"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897718/; classtype:trojan-activity;sid:84760818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ce80bf"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897719/; classtype:trojan-activity;sid:84760819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7d4623"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897720/; classtype:trojan-activity;sid:84760820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/204136"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897721/; classtype:trojan-activity;sid:84760821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cbb676"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897722/; classtype:trojan-activity;sid:84760822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b04d47"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897723/; classtype:trojan-activity;sid:84760823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c471bc"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897724/; classtype:trojan-activity;sid:84760824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.88.7.48"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897712/; classtype:trojan-activity;sid:84760812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thurs/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"orienttaxtile.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897711/; classtype:trojan-activity;sid:84760811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qjhpj"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897710/; classtype:trojan-activity;sid:84760810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wom.png"; depth:8; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897709/; classtype:trojan-activity;sid:84760809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_081556.png"; depth:15; endswith; nocase; http.host; content:"timestampasa.howto.rocks"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897708/; classtype:trojan-activity;sid:84760808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hgaoe"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897706/; classtype:trojan-activity;sid:84760806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_075249.png"; depth:15; endswith; nocase; http.host; content:"timestampasa.howto.rocks"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897707/; classtype:trojan-activity;sid:84760807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdxbp"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897705/; classtype:trojan-activity;sid:84760805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_131252.png"; depth:15; endswith; nocase; http.host; content:"sales.ifree.page"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897704/; classtype:trojan-activity;sid:84760804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.141.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897703/; classtype:trojan-activity;sid:84760803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/astillerohenry.com/imgnic_165817.png"; depth:37; endswith; nocase; http.host; content:"grupohenry1.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897702/; classtype:trojan-activity;sid:84760802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v0/b/julyendingapama.firebasestorage.app/o/img_140608.png|3f|alt=media|7c|26|7c|token=b5bd8e8c-f453-466e-8754-dcbea04e24cc"; depth:123; endswith; nocase; http.host; content:"firebasestorage.googleapis.com"; depth:30; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897701/; classtype:trojan-activity;sid:84760801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/astillerohenry.com/nmsi_pro.png"; depth:32; endswith; nocase; http.host; content:"grupohenry1.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897700/; classtype:trojan-activity;sid:84760800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yuoriginsmtp.png"; depth:17; endswith; nocase; http.host; content:"45.9.168.230"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897699/; classtype:trojan-activity;sid:84760799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chrome01.exe"; depth:13; endswith; nocase; http.host; content:"rcf.co.mz"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897698/; classtype:trojan-activity;sid:84760798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soldierman/64-bit-remcos_a.bin"; depth:31; endswith; nocase; http.host; content:"sumiko.vu"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897697/; classtype:trojan-activity;sid:84760797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.120.7.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897696/; classtype:trojan-activity;sid:84760796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_054840.png"; depth:15; endswith; nocase; http.host; content:"heajost.online"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897695/; classtype:trojan-activity;sid:84760795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t3swaz48/image/upload/v1785980358/img_213859_yxgjcm.jpg"; depth:56; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897694/; classtype:trojan-activity;sid:84760794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t3swaz48/image/upload/v1785980074/img_213402_mk57ex.jpg"; depth:56; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897693/; classtype:trojan-activity;sid:84760793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_haamlp2ndi.png"; depth:21; endswith; nocase; http.host; content:"zoredaye.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897692/; classtype:trojan-activity;sid:84760792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_yzybqoy6im.png"; depth:21; endswith; nocase; http.host; content:"zoredaye.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897691/; classtype:trojan-activity;sid:84760791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.92.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897690/; classtype:trojan-activity;sid:84760790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897689/; classtype:trojan-activity;sid:84760789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/8cn8u1bn3jb5gep/file"; depth:26; endswith; nocase; http.host; content:"www.mediafire.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897688/; classtype:trojan-activity;sid:84760788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897687/; classtype:trojan-activity;sid:84760787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.194.25.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897686/; classtype:trojan-activity;sid:84760786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b5a50f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897685/; classtype:trojan-activity;sid:84760785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ef4188"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897680/; classtype:trojan-activity;sid:84760780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efaa9e"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897681/; classtype:trojan-activity;sid:84760781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bb4476"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897682/; classtype:trojan-activity;sid:84760782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/126b61"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897683/; classtype:trojan-activity;sid:84760783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c61c40"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897684/; classtype:trojan-activity;sid:84760784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/911f2d"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897676/; classtype:trojan-activity;sid:84760776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/90a07f"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897677/; classtype:trojan-activity;sid:84760777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d237c8"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897678/; classtype:trojan-activity;sid:84760778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1cbba3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897679/; classtype:trojan-activity;sid:84760779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ca05d7"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897674/; classtype:trojan-activity;sid:84760774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1de3f3"; depth:7; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897675/; classtype:trojan-activity;sid:84760775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"146.168.191.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897673/; classtype:trojan-activity;sid:84760773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.201.146.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897672/; classtype:trojan-activity;sid:84760772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ok"; depth:3; endswith; nocase; http.host; content:"5.182.210.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897671/; classtype:trojan-activity;sid:84760771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897670/; classtype:trojan-activity;sid:84760770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"213.114.99.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897669/; classtype:trojan-activity;sid:84760769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.231.69.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897668/; classtype:trojan-activity;sid:84760768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.201.146.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897667/; classtype:trojan-activity;sid:84760767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.127.232.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897666/; classtype:trojan-activity;sid:84760766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.231.69.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897665/; classtype:trojan-activity;sid:84760765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.41.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897664/; classtype:trojan-activity;sid:84760764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.2.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897663/; classtype:trojan-activity;sid:84760763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.248.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897662/; classtype:trojan-activity;sid:84760762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.65.9"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897661/; classtype:trojan-activity;sid:84760761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.165.192.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897660/; classtype:trojan-activity;sid:84760760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"213.114.99.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897659/; classtype:trojan-activity;sid:84760759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_210844.png"; depth:19; endswith; nocase; http.host; content:"155.103.69.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897658/; classtype:trojan-activity;sid:84760758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.41.63"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897657/; classtype:trojan-activity;sid:84760757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45/wearebestforeverythingfrommegood.hta"; depth:40; endswith; nocase; http.host; content:"155.103.69.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897656/; classtype:trojan-activity;sid:84760756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.127.232.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897655/; classtype:trojan-activity;sid:84760755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.165.192.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897654/; classtype:trojan-activity;sid:84760754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.2.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897653/; classtype:trojan-activity;sid:84760753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.65.9"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897652/; classtype:trojan-activity;sid:84760752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86"; depth:7; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897645/; classtype:trojan-activity;sid:84760745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv5l"; depth:10; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897646/; classtype:trojan-activity;sid:84760746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/ppc"; depth:7; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897647/; classtype:trojan-activity;sid:84760747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86_64"; depth:10; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897648/; classtype:trojan-activity;sid:84760748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/m68k"; depth:8; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897649/; classtype:trojan-activity;sid:84760749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv4l"; depth:10; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897650/; classtype:trojan-activity;sid:84760750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/sparc"; depth:9; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897651/; classtype:trojan-activity;sid:84760751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/aarch64"; depth:11; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897642/; classtype:trojan-activity;sid:84760742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv6l"; depth:10; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897643/; classtype:trojan-activity;sid:84760743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/sh4"; depth:7; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897644/; classtype:trojan-activity;sid:84760744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv7l"; depth:10; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897641/; classtype:trojan-activity;sid:84760741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/img_202115.png"; depth:18; endswith; nocase; http.host; content:"192.255.159.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897640/; classtype:trojan-activity;sid:84760740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/goodthingswithbestsupportforme.hta"; depth:38; endswith; nocase; http.host; content:"192.255.159.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897639/; classtype:trojan-activity;sid:84760739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mpsl"; depth:8; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897637/; classtype:trojan-activity;sid:84760737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/lterouter"; depth:13; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897638/; classtype:trojan-activity;sid:84760738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mips"; depth:8; endswith; nocase; http.host; content:"191.96.11.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897636/; classtype:trojan-activity;sid:84760736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.63.8.194"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897635/; classtype:trojan-activity;sid:84760735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.98.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897634/; classtype:trojan-activity;sid:84760734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.180.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897633/; classtype:trojan-activity;sid:84760733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/33/img_190847.png"; depth:18; endswith; nocase; http.host; content:"216.9.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897632/; classtype:trojan-activity;sid:84760732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/33/weneedbestmagicalapproachforbesthings.hta"; depth:45; endswith; nocase; http.host; content:"216.9.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897631/; classtype:trojan-activity;sid:84760731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/56/goodthingswforbestfeelingsfromtheheartsesion.hta"; depth:52; endswith; nocase; http.host; content:"216.225.206.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897630/; classtype:trojan-activity;sid:84760730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8089/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897629/; classtype:trojan-activity;sid:84760729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/56/nn/bestgood.vbe"; depth:19; endswith; nocase; http.host; content:"216.225.206.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897628/; classtype:trojan-activity;sid:84760728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/img_182439.png"; depth:18; endswith; nocase; http.host; content:"204.44.93.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897627/; classtype:trojan-activity;sid:84760727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70/weneedbestthingsfromtheheartformeebest.hta"; depth:46; endswith; nocase; http.host; content:"204.44.93.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897626/; classtype:trojan-activity;sid:84760726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/27/blackmagicprotectiononthisfilewhathaving.hta"; depth:48; endswith; nocase; http.host; content:"107.173.47.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897625/; classtype:trojan-activity;sid:84760725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/img_180754.png"; depth:19; endswith; nocase; http.host; content:"107.173.47.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897624/; classtype:trojan-activity;sid:84760724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202608/05/jjeeavpl6blk3mkgej7i/image.png"; depth:41; endswith; nocase; http.host; content:"plain-wnam-prod-public.komododecks.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897623/; classtype:trojan-activity;sid:84760723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/city/rcx1.exe"; depth:14; endswith; nocase; http.host; content:"comumvidros.com.br"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897622/; classtype:trojan-activity;sid:84760722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.154.174.185"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897621/; classtype:trojan-activity;sid:84760721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.72.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897620/; classtype:trojan-activity;sid:84760720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm7"; depth:19; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897618/; classtype:trojan-activity;sid:84760718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mipsel"; depth:21; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897619/; classtype:trojan-activity;sid:84760719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nnn"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897613/; classtype:trojan-activity;sid:84760713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/h8u"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897614/; classtype:trojan-activity;sid:84760714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av0"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897615/; classtype:trojan-activity;sid:84760715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6wh"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897616/; classtype:trojan-activity;sid:84760716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f9f"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897617/; classtype:trojan-activity;sid:84760717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.215.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897612/; classtype:trojan-activity;sid:84760712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86"; depth:18; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897607/; classtype:trojan-activity;sid:84760707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.arm4"; depth:19; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897608/; classtype:trojan-activity;sid:84760708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.mips"; depth:19; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897609/; classtype:trojan-activity;sid:84760709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.aarch64"; depth:22; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897610/; classtype:trojan-activity;sid:84760710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disconnectraw.x86_64"; depth:21; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897611/; classtype:trojan-activity;sid:84760711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.98.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897606/; classtype:trojan-activity;sid:84760706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.72.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897605/; classtype:trojan-activity;sid:84760705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.58.190.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897604/; classtype:trojan-activity;sid:84760704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.215.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897603/; classtype:trojan-activity;sid:84760703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/discrete_69.7868.8_install.exe"; depth:31; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897602/; classtype:trojan-activity;sid:84760702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xx.exe"; depth:7; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897601/; classtype:trojan-activity;sid:84760701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stlr.exe"; depth:9; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897600/; classtype:trojan-activity;sid:84760700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dcvylmiq.exe"; depth:13; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897599/; classtype:trojan-activity;sid:84760699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom_bins/phantom.mips"; depth:26; endswith; nocase; http.host; content:"94.154.43.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897598/; classtype:trojan-activity;sid:84760698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/2.jpg"; depth:10; endswith; nocase; http.host; content:"192.210.186.206"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897597/; classtype:trojan-activity;sid:84760697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom_bins/phantom.arm"; depth:25; endswith; nocase; http.host; content:"94.154.43.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897594/; classtype:trojan-activity;sid:84760694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom_bash.sh"; depth:16; endswith; nocase; http.host; content:"94.154.43.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897595/; classtype:trojan-activity;sid:84760695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantom_bins/phantom.x86_64"; depth:28; endswith; nocase; http.host; content:"94.154.43.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897596/; classtype:trojan-activity;sid:84760696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/2.jpg"; depth:10; endswith; nocase; http.host; content:"107.173.9.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897593/; classtype:trojan-activity;sid:84760693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/2.jpg"; depth:10; endswith; nocase; http.host; content:"192.236.217.81"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897592/; classtype:trojan-activity;sid:84760692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.mpsl"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897590/; classtype:trojan-activity;sid:84760690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.arm6"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897591/; classtype:trojan-activity;sid:84760691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.mips"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897589/; classtype:trojan-activity;sid:84760689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.89.147"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897588/; classtype:trojan-activity;sid:84760688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.58.190.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897587/; classtype:trojan-activity;sid:84760687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sex.bin"; depth:8; endswith; nocase; http.host; content:"185.199.197.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897586/; classtype:trojan-activity;sid:84760686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.216.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897585/; classtype:trojan-activity;sid:84760685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_e958e6cb554d1c91.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897584/; classtype:trojan-activity;sid:84760684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"65.108.103.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897582/; classtype:trojan-activity;sid:84760682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"65.108.103.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897583/; classtype:trojan-activity;sid:84760683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.94.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897581/; classtype:trojan-activity;sid:84760681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_44bcabde68f83fab.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897579/; classtype:trojan-activity;sid:84760679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_6b7797e28badd65a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897580/; classtype:trojan-activity;sid:84760680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.199.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897578/; classtype:trojan-activity;sid:84760678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.206.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897577/; classtype:trojan-activity;sid:84760677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.179.45"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897576/; classtype:trojan-activity;sid:84760676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload/386/pikachu"; depth:20; endswith; nocase; http.host; content:"184.174.97.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897575/; classtype:trojan-activity;sid:84760675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipmiv2.xml"; depth:11; endswith; nocase; http.host; content:"94.154.43.118"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897574/; classtype:trojan-activity;sid:84760674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.229.94.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897573/; classtype:trojan-activity;sid:84760673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.199.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897572/; classtype:trojan-activity;sid:84760672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.196.205"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897571/; classtype:trojan-activity;sid:84760671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.54.54"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897570/; classtype:trojan-activity;sid:84760670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.170.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897569/; classtype:trojan-activity;sid:84760669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.199.243.13"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897568/; classtype:trojan-activity;sid:84760668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.202.25.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897567/; classtype:trojan-activity;sid:84760667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.170.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897566/; classtype:trojan-activity;sid:84760666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"80.67.33.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897565/; classtype:trojan-activity;sid:84760665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.35.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897564/; classtype:trojan-activity;sid:84760664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.150.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897563/; classtype:trojan-activity;sid:84760663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.230.18.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897562/; classtype:trojan-activity;sid:84760662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.29.22.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897561/; classtype:trojan-activity;sid:84760661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.255.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897560/; classtype:trojan-activity;sid:84760660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.52.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897559/; classtype:trojan-activity;sid:84760659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.182.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897558/; classtype:trojan-activity;sid:84760658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.25.188.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897557/; classtype:trojan-activity;sid:84760657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.255.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897556/; classtype:trojan-activity;sid:84760656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.78.208"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897555/; classtype:trojan-activity;sid:84760655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.85.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897554/; classtype:trojan-activity;sid:84760654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.56.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897553/; classtype:trojan-activity;sid:84760653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.25.188.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897552/; classtype:trojan-activity;sid:84760652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.102.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897551/; classtype:trojan-activity;sid:84760651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.56.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897550/; classtype:trojan-activity;sid:84760650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.244.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897549/; classtype:trojan-activity;sid:84760649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.145.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897548/; classtype:trojan-activity;sid:84760648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.180.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897547/; classtype:trojan-activity;sid:84760647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.146.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897546/; classtype:trojan-activity;sid:84760646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.4.82"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897545/; classtype:trojan-activity;sid:84760645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.21.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897544/; classtype:trojan-activity;sid:84760644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.4.82"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897543/; classtype:trojan-activity;sid:84760643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.244.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897542/; classtype:trojan-activity;sid:84760642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.23.173"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897541/; classtype:trojan-activity;sid:84760641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.240.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897540/; classtype:trojan-activity;sid:84760640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.23.173"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897539/; classtype:trojan-activity;sid:84760639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.163.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897538/; classtype:trojan-activity;sid:84760638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.240.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897537/; classtype:trojan-activity;sid:84760637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.115.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897536/; classtype:trojan-activity;sid:84760636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.250.40"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897535/; classtype:trojan-activity;sid:84760635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.35.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897534/; classtype:trojan-activity;sid:84760634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.74.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897533/; classtype:trojan-activity;sid:84760633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3a6c8cecc55c6ccf.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897532/; classtype:trojan-activity;sid:84760632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.95.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897531/; classtype:trojan-activity;sid:84760631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"171.38.221.210"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897530/; classtype:trojan-activity;sid:84760630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.126.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897529/; classtype:trojan-activity;sid:84760629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.60.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897528/; classtype:trojan-activity;sid:84760628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.126.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897526/; classtype:trojan-activity;sid:84760626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.131.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897527/; classtype:trojan-activity;sid:84760627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.85.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897525/; classtype:trojan-activity;sid:84760625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.54.54"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897524/; classtype:trojan-activity;sid:84760624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5ba49755e4182c02.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897523/; classtype:trojan-activity;sid:84760623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.60.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897522/; classtype:trojan-activity;sid:84760622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.109.170.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897521/; classtype:trojan-activity;sid:84760621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.9.132.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897520/; classtype:trojan-activity;sid:84760620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.57.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897519/; classtype:trojan-activity;sid:84760619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.34.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897518/; classtype:trojan-activity;sid:84760618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.56.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897517/; classtype:trojan-activity;sid:84760617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.202.25.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897516/; classtype:trojan-activity;sid:84760616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.85.239.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897515/; classtype:trojan-activity;sid:84760615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.9.132.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897514/; classtype:trojan-activity;sid:84760614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.109.170.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897513/; classtype:trojan-activity;sid:84760613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.34.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897512/; classtype:trojan-activity;sid:84760612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.57.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897511/; classtype:trojan-activity;sid:84760611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897510/; classtype:trojan-activity;sid:84760610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.56.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897509/; classtype:trojan-activity;sid:84760609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.219.74.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897508/; classtype:trojan-activity;sid:84760608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.214.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897507/; classtype:trojan-activity;sid:84760607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/24d379"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897495/; classtype:trojan-activity;sid:84760595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/14ef86"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897496/; classtype:trojan-activity;sid:84760596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/51c6dc"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897497/; classtype:trojan-activity;sid:84760597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/132db9"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897498/; classtype:trojan-activity;sid:84760598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4bd178"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897499/; classtype:trojan-activity;sid:84760599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/17f186"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897500/; classtype:trojan-activity;sid:84760600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/78c426"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897501/; classtype:trojan-activity;sid:84760601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fdf7b4"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897502/; classtype:trojan-activity;sid:84760602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c18c96"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897503/; classtype:trojan-activity;sid:84760603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7d759c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897504/; classtype:trojan-activity;sid:84760604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4a3a1c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897505/; classtype:trojan-activity;sid:84760605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cdbc52"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897506/; classtype:trojan-activity;sid:84760606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.147"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897494/; classtype:trojan-activity;sid:84760594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"106.40.240.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897493/; classtype:trojan-activity;sid:84760593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/08433c"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897469/; classtype:trojan-activity;sid:84760569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8a9f29"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897470/; classtype:trojan-activity;sid:84760570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/875901"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897471/; classtype:trojan-activity;sid:84760571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0f20b0"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897472/; classtype:trojan-activity;sid:84760572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5b1540"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897473/; classtype:trojan-activity;sid:84760573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/74fa12"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897474/; classtype:trojan-activity;sid:84760574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5201f2"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897475/; classtype:trojan-activity;sid:84760575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1cc880"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897476/; classtype:trojan-activity;sid:84760576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/74ef32"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897477/; classtype:trojan-activity;sid:84760577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/add00b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897478/; classtype:trojan-activity;sid:84760578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00fec1"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897479/; classtype:trojan-activity;sid:84760579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/226a79"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897480/; classtype:trojan-activity;sid:84760580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6ad4b4"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897481/; classtype:trojan-activity;sid:84760581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8c800e"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897482/; classtype:trojan-activity;sid:84760582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0bc7e1"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897483/; classtype:trojan-activity;sid:84760583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e088a7"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897484/; classtype:trojan-activity;sid:84760584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4bec62"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897485/; classtype:trojan-activity;sid:84760585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6705e6"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897486/; classtype:trojan-activity;sid:84760586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dd6ef1"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897487/; classtype:trojan-activity;sid:84760587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44612a"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897488/; classtype:trojan-activity;sid:84760588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2f1a34"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897489/; classtype:trojan-activity;sid:84760589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/04a1dc"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897490/; classtype:trojan-activity;sid:84760590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f5dd75"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897491/; classtype:trojan-activity;sid:84760591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b03001"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897492/; classtype:trojan-activity;sid:84760592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6mok"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897467/; classtype:trojan-activity;sid:84760567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dzqa"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897468/; classtype:trojan-activity;sid:84760568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/avwf"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897459/; classtype:trojan-activity;sid:84760559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ce3w"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897460/; classtype:trojan-activity;sid:84760560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lwac"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897461/; classtype:trojan-activity;sid:84760561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ubt5"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897462/; classtype:trojan-activity;sid:84760562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zmu"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897463/; classtype:trojan-activity;sid:84760563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5em"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897464/; classtype:trojan-activity;sid:84760564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kx8"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897465/; classtype:trojan-activity;sid:84760565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lxk"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897466/; classtype:trojan-activity;sid:84760566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.213.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897458/; classtype:trojan-activity;sid:84760558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.71.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897457/; classtype:trojan-activity;sid:84760557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.181.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897456/; classtype:trojan-activity;sid:84760556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"106.40.240.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897455/; classtype:trojan-activity;sid:84760555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.71.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897454/; classtype:trojan-activity;sid:84760554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.86.120.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897453/; classtype:trojan-activity;sid:84760553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.213.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897452/; classtype:trojan-activity;sid:84760552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897451/; classtype:trojan-activity;sid:84760551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897446/; classtype:trojan-activity;sid:84760546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897447/; classtype:trojan-activity;sid:84760547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897448/; classtype:trojan-activity;sid:84760548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897449/; classtype:trojan-activity;sid:84760549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897450/; classtype:trojan-activity;sid:84760550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897445/; classtype:trojan-activity;sid:84760545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897440/; classtype:trojan-activity;sid:84760540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897441/; classtype:trojan-activity;sid:84760541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897442/; classtype:trojan-activity;sid:84760542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897443/; classtype:trojan-activity;sid:84760543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897444/; classtype:trojan-activity;sid:84760544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/cat.sh"; depth:12; endswith; nocase; http.host; content:"31.77.227.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897439/; classtype:trojan-activity;sid:84760539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.242.20.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897438/; classtype:trojan-activity;sid:84760538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.245.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897437/; classtype:trojan-activity;sid:84760537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.78.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897436/; classtype:trojan-activity;sid:84760536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.236.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897435/; classtype:trojan-activity;sid:84760535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.239.254.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897434/; classtype:trojan-activity;sid:84760534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.245.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897433/; classtype:trojan-activity;sid:84760533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.236.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897432/; classtype:trojan-activity;sid:84760532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.86.120.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897431/; classtype:trojan-activity;sid:84760531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.18.96.224"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897430/; classtype:trojan-activity;sid:84760530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.96.224"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897429/; classtype:trojan-activity;sid:84760529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.95.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897427/; classtype:trojan-activity;sid:84760527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.93.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897428/; classtype:trojan-activity;sid:84760528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/63748/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897419/; classtype:trojan-activity;sid:84760519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/29039/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897420/; classtype:trojan-activity;sid:84760520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sike/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897421/; classtype:trojan-activity;sid:84760521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44/dc_00940404094404004_file.pdf"; depth:33; endswith; nocase; http.host; content:"216.225.206.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897422/; classtype:trojan-activity;sid:84760522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/55/notepad___files__document__004949596060.txt"; depth:47; endswith; nocase; http.host; content:"216.225.206.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897423/; classtype:trojan-activity;sid:84760523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44/createdbestnaturealsystemforbestentieryformebest.vbe"; depth:56; endswith; nocase; http.host; content:"216.225.206.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897424/; classtype:trojan-activity;sid:84760524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/55/wegivingbestthignswiththemforme.hta"; depth:39; endswith; nocase; http.host; content:"216.225.206.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897425/; classtype:trojan-activity;sid:84760525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zaheqn-h"; depth:9; endswith; nocase; http.host; content:"linktrap.co"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897426/; classtype:trojan-activity;sid:84760526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.93.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897418/; classtype:trojan-activity;sid:84760518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.170.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897417/; classtype:trojan-activity;sid:84760517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.170.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897416/; classtype:trojan-activity;sid:84760516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.95.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897415/; classtype:trojan-activity;sid:84760515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.156.139.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897414/; classtype:trojan-activity;sid:84760514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.16.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897413/; classtype:trojan-activity;sid:84760513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hayaalsi/aahhfdf.txt"; depth:21; endswith; nocase; http.host; content:"paymentautomations.biz"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897412/; classtype:trojan-activity;sid:84760512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.115.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897411/; classtype:trojan-activity;sid:84760511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.115.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897410/; classtype:trojan-activity;sid:84760510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.156.139.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897409/; classtype:trojan-activity;sid:84760509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.189.109.47"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897407/; classtype:trojan-activity;sid:84760507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.16.86"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897408/; classtype:trojan-activity;sid:84760508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.189.109.47"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897406/; classtype:trojan-activity;sid:84760506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.113.103"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897405/; classtype:trojan-activity;sid:84760505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897404/; classtype:trojan-activity;sid:84760504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897403/; classtype:trojan-activity;sid:84760503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.239.58"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897402/; classtype:trojan-activity;sid:84760502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.112.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897401/; classtype:trojan-activity;sid:84760501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r"; depth:2; endswith; nocase; http.host; content:"loosun.net"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897400/; classtype:trojan-activity;sid:84760500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897399/; classtype:trojan-activity;sid:84760499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.239.58"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897398/; classtype:trojan-activity;sid:84760498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_035345.png"; depth:15; endswith; nocase; http.host; content:"donal.gt.tc"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897397/; classtype:trojan-activity;sid:84760497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yjldq"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897396/; classtype:trojan-activity;sid:84760496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_033332.png"; depth:15; endswith; nocase; http.host; content:"deliverymailreport.co.za"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897395/; classtype:trojan-activity;sid:84760495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_010650.png"; depth:15; endswith; nocase; http.host; content:"deliverymailreport.co.za"; depth:24; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897394/; classtype:trojan-activity;sid:84760494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_qrl78zngn5.png"; depth:21; endswith; nocase; http.host; content:"canta-cn.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897393/; classtype:trojan-activity;sid:84760493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"140.237.38.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897392/; classtype:trojan-activity;sid:84760492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo2"; depth:7; endswith; nocase; http.host; content:"216.158.95.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897391/; classtype:trojan-activity;sid:84760491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897390/; classtype:trojan-activity;sid:84760490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897389/; classtype:trojan-activity;sid:84760489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897388/; classtype:trojan-activity;sid:84760488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897385/; classtype:trojan-activity;sid:84760485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm64"; depth:6; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897386/; classtype:trojan-activity;sid:84760486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i386"; depth:5; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897387/; classtype:trojan-activity;sid:84760487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897383/; classtype:trojan-activity;sid:84760483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/android_arm64"; depth:14; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897384/; classtype:trojan-activity;sid:84760484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.exe"; depth:8; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897382/; classtype:trojan-activity;sid:84760482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/android_arm"; depth:12; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897380/; classtype:trojan-activity;sid:84760480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amd64"; depth:6; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897381/; classtype:trojan-activity;sid:84760481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.59.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897379/; classtype:trojan-activity;sid:84760479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gmt/img_152749.png"; depth:19; endswith; nocase; http.host; content:"38.180.221.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897378/; classtype:trojan-activity;sid:84760478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vxmgp"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897377/; classtype:trojan-activity;sid:84760477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"140.237.38.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897376/; classtype:trojan-activity;sid:84760476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/|3f|e=v"; depth:8; endswith; nocase; http.host; content:"cqylt.net"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897375/; classtype:trojan-activity;sid:84760475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agenthype.exe"; depth:14; endswith; nocase; http.host; content:"download.ubua.online"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897374/; classtype:trojan-activity;sid:84760474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45/img_193442.png"; depth:18; endswith; nocase; http.host; content:"155.254.98.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897373/; classtype:trojan-activity;sid:84760473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202608/05/kk9ihq9ebt47mhmryher/image.png"; depth:41; endswith; nocase; http.host; content:"plain-wnam-prod-public.komododecks.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897372/; classtype:trojan-activity;sid:84760472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypted.ps1"; depth:12; endswith; nocase; http.host; content:"www.propertiesofcayman.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897371/; classtype:trojan-activity;sid:84760471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xz/genera-raw-fileupload.txt"; depth:29; endswith; nocase; http.host; content:"216.9.224.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897370/; classtype:trojan-activity;sid:84760470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/1.jpg"; depth:10; endswith; nocase; http.host; content:"192.255.195.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897369/; classtype:trojan-activity;sid:84760469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/updated-phantom.dat"; depth:24; endswith; nocase; http.host; content:"wp.ameyiando.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897368/; classtype:trojan-activity;sid:84760468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.11.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897367/; classtype:trojan-activity;sid:84760467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/theme-compat/gvewiny/wnfgzub/pzowjyv/msid_pro.png"; depth:62; endswith; nocase; http.host; content:"lion44.net"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897366/; classtype:trojan-activity;sid:84760466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/theme-compat/gvewiny/wnfgzub/pzowjyv/img_152245.png"; depth:64; endswith; nocase; http.host; content:"lion44.net"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897365/; classtype:trojan-activity;sid:84760465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"cla.stingold.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897364/; classtype:trojan-activity;sid:84760464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"5.175.140.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897363/; classtype:trojan-activity;sid:84760463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/systemd"; depth:8; endswith; nocase; http.host; content:"196.251.121.185"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897362/; classtype:trojan-activity;sid:84760462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/merry/64bit-remcos_a.bin"; depth:25; endswith; nocase; http.host; content:"hwykplqn.xyz"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897361/; classtype:trojan-activity;sid:84760461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o85pdfv8yi.png"; depth:15; endswith; nocase; http.host; content:"mrsweaterltd.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897360/; classtype:trojan-activity;sid:84760460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eguqava104.bin"; depth:15; endswith; nocase; http.host; content:"lenotecadiarqua.it"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897359/; classtype:trojan-activity;sid:84760459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lbskesl.u32"; depth:12; endswith; nocase; http.host; content:"lenotecadiarqua.it"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897358/; classtype:trojan-activity;sid:84760458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.104.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897357/; classtype:trojan-activity;sid:84760457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/astillerohenry.com/imglt_105404.png"; depth:36; endswith; nocase; http.host; content:"grupohenry1.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897356/; classtype:trojan-activity;sid:84760456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.11.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897355/; classtype:trojan-activity;sid:84760455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unselec.pfm"; depth:12; endswith; nocase; http.host; content:"lenotecadiarqua.it"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897354/; classtype:trojan-activity;sid:84760454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tiric"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897353/; classtype:trojan-activity;sid:84760453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phyllo.lzh"; depth:11; endswith; nocase; http.host; content:"lenotecadiarqua.it"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897352/; classtype:trojan-activity;sid:84760452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kiii.png"; depth:9; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897351/; classtype:trojan-activity;sid:84760451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chvwdtbpyyjtavvorehzda105.bin"; depth:30; endswith; nocase; http.host; content:"lenotecadiarqua.it"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897350/; classtype:trojan-activity;sid:84760450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_144534.png"; depth:15; endswith; nocase; http.host; content:"pocopaco.co.za"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897349/; classtype:trojan-activity;sid:84760449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vpceb"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897348/; classtype:trojan-activity;sid:84760448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/fokz7nq2fsq5eno3me0kr/update.bin|3f|rlkey=ew1j6qqw9bpl5i99yesrvya3o|7c|26|7c|dl=1"; depth:89; endswith; nocase; http.host; content:"dl.dropboxusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897347/; classtype:trojan-activity;sid:84760447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.231.63.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897346/; classtype:trojan-activity;sid:84760446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_172016.png"; depth:15; endswith; nocase; http.host; content:"crypter00.gt.tc"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897345/; classtype:trojan-activity;sid:84760445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kcbrc"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897342/; classtype:trojan-activity;sid:84760442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nqysh"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897343/; classtype:trojan-activity;sid:84760443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nima.png"; depth:9; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897344/; classtype:trojan-activity;sid:84760444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/770779.png"; depth:11; endswith; nocase; http.host; content:"pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897340/; classtype:trojan-activity;sid:84760440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cwgkw"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897341/; classtype:trojan-activity;sid:84760441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tpudp"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897338/; classtype:trojan-activity;sid:84760438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoop.png"; depth:9; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897339/; classtype:trojan-activity;sid:84760439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/astillerohenry.com/msi_pro.png"; depth:31; endswith; nocase; http.host; content:"grupohenry1.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897335/; classtype:trojan-activity;sid:84760435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yadzs"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897336/; classtype:trojan-activity;sid:84760436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202.png"; depth:8; endswith; nocase; http.host; content:"pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897337/; classtype:trojan-activity;sid:84760437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yyyy.bat"; depth:9; endswith; nocase; http.host; content:"amazom.my"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897334/; classtype:trojan-activity;sid:84760434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/ffr9scbddq76bjv/file"; depth:26; endswith; nocase; http.host; content:"www.mediafire.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897333/; classtype:trojan-activity;sid:84760433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.70.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897332/; classtype:trojan-activity;sid:84760432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.186.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897330/; classtype:trojan-activity;sid:84760430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"177.125.169.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897331/; classtype:trojan-activity;sid:84760431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/ffr9scbddq76bjv/file"; depth:26; endswith; nocase; http.host; content:"mediafire.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897329/; classtype:trojan-activity;sid:84760429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.139.55.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897328/; classtype:trojan-activity;sid:84760428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.231.63.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897327/; classtype:trojan-activity;sid:84760427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.164.199.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897326/; classtype:trojan-activity;sid:84760426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.78.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897325/; classtype:trojan-activity;sid:84760425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"94.27.153.78"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897324/; classtype:trojan-activity;sid:84760424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.164.199.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897323/; classtype:trojan-activity;sid:84760423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"94.27.153.78"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897322/; classtype:trojan-activity;sid:84760422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.148.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897321/; classtype:trojan-activity;sid:84760421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.162.112.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897320/; classtype:trojan-activity;sid:84760420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.52.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897319/; classtype:trojan-activity;sid:84760419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"179.108.89.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897318/; classtype:trojan-activity;sid:84760418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.145.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897317/; classtype:trojan-activity;sid:84760417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.178.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897316/; classtype:trojan-activity;sid:84760416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.25.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897315/; classtype:trojan-activity;sid:84760415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.246.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897314/; classtype:trojan-activity;sid:84760414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.181.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897313/; classtype:trojan-activity;sid:84760413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"179.108.89.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897312/; classtype:trojan-activity;sid:84760412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.177.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897311/; classtype:trojan-activity;sid:84760411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantomx.exe"; depth:13; endswith; nocase; http.host; content:"rcf.co.mz"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897310/; classtype:trojan-activity;sid:84760410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.89.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897309/; classtype:trojan-activity;sid:84760409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wordpress/wp-content/plugins/zxzxzx/stego_p0ci0zln28.png"; depth:57; endswith; nocase; http.host; content:"www.hqsblog.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897308/; classtype:trojan-activity;sid:84760408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.214.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897307/; classtype:trojan-activity;sid:84760407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.178.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897306/; classtype:trojan-activity;sid:84760406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.99.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897305/; classtype:trojan-activity;sid:84760405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.243.172.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897304/; classtype:trojan-activity;sid:84760404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.89.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897303/; classtype:trojan-activity;sid:84760403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.229.222.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897302/; classtype:trojan-activity;sid:84760402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.252.224.196"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897301/; classtype:trojan-activity;sid:84760401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.154.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897300/; classtype:trojan-activity;sid:84760400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.177.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897299/; classtype:trojan-activity;sid:84760399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.65.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897298/; classtype:trojan-activity;sid:84760398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.99.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897297/; classtype:trojan-activity;sid:84760397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.65.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897296/; classtype:trojan-activity;sid:84760396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.149.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897295/; classtype:trojan-activity;sid:84760395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.227.225.67"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897293/; classtype:trojan-activity;sid:84760393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.252.224.196"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897294/; classtype:trojan-activity;sid:84760394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.136.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897292/; classtype:trojan-activity;sid:84760392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.136.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897291/; classtype:trojan-activity;sid:84760391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.93.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897290/; classtype:trojan-activity;sid:84760390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hype/ws"; depth:8; endswith; nocase; http.host; content:"94.26.3.211"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897289/; classtype:trojan-activity;sid:84760389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackin.png"; depth:11; endswith; nocase; http.host; content:"192.109.139.93"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897288/; classtype:trojan-activity;sid:84760388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.157.169.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897287/; classtype:trojan-activity;sid:84760387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.143.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897286/; classtype:trojan-activity;sid:84760386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.143.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897285/; classtype:trojan-activity;sid:84760385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_pro3rd.png"; depth:15; endswith; nocase; http.host; content:"45.9.168.230"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897284/; classtype:trojan-activity;sid:84760384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rump31st.png"; depth:13; endswith; nocase; http.host; content:"45.9.168.230"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897282/; classtype:trojan-activity;sid:84760382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yuyufresh.png"; depth:14; endswith; nocase; http.host; content:"45.9.168.230"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897283/; classtype:trojan-activity;sid:84760383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dwsr.png"; depth:9; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897281/; classtype:trojan-activity;sid:84760381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/holding.png"; depth:12; endswith; nocase; http.host; content:"94.26.3.76"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897280/; classtype:trojan-activity;sid:84760380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_173002.png"; depth:15; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897277/; classtype:trojan-activity;sid:84760377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_as.png"; depth:11; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897278/; classtype:trojan-activity;sid:84760378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sirusjuly.png"; depth:14; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897279/; classtype:trojan-activity;sid:84760379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sirusjulymsi.png"; depth:17; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897276/; classtype:trojan-activity;sid:84760376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spaxworm.png"; depth:13; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897275/; classtype:trojan-activity;sid:84760375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ksir.png"; depth:9; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897274/; classtype:trojan-activity;sid:84760374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johnsmith.png"; depth:14; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897273/; classtype:trojan-activity;sid:84760373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_dw.png"; depth:11; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897271/; classtype:trojan-activity;sid:84760371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dxw.png"; depth:8; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897272/; classtype:trojan-activity;sid:84760372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xking.png"; depth:10; endswith; nocase; http.host; content:"103.75.189.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897270/; classtype:trojan-activity;sid:84760370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.109.227.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897269/; classtype:trojan-activity;sid:84760369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pg.exe"; depth:7; endswith; nocase; http.host; content:"153.80.249.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897268/; classtype:trojan-activity;sid:84760368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/conhost.exe"; depth:12; endswith; nocase; http.host; content:"89.208.97.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897266/; classtype:trojan-activity;sid:84760366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/windowsaudiograph.exe"; depth:22; endswith; nocase; http.host; content:"89.208.97.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897267/; classtype:trojan-activity;sid:84760367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/index.ps1"; depth:10; endswith; nocase; http.host; content:"89.208.97.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897265/; classtype:trojan-activity;sid:84760365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"190.109.227.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897264/; classtype:trojan-activity;sid:84760364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.119.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897263/; classtype:trojan-activity;sid:84760363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.53.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897262/; classtype:trojan-activity;sid:84760362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.exe"; depth:8; endswith; nocase; http.host; content:"cashblaq.fit"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897261/; classtype:trojan-activity;sid:84760361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897260/; classtype:trojan-activity;sid:84760360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897259/; classtype:trojan-activity;sid:84760359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897255/; classtype:trojan-activity;sid:84760355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897256/; classtype:trojan-activity;sid:84760356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897257/; classtype:trojan-activity;sid:84760357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897258/; classtype:trojan-activity;sid:84760358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897254/; classtype:trojan-activity;sid:84760354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897253/; classtype:trojan-activity;sid:84760353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.106.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897252/; classtype:trojan-activity;sid:84760352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.176.122.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897251/; classtype:trojan-activity;sid:84760351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6no"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897241/; classtype:trojan-activity;sid:84760341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jih"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897242/; classtype:trojan-activity;sid:84760342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoj3"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897243/; classtype:trojan-activity;sid:84760343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nw2"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897244/; classtype:trojan-activity;sid:84760344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kvjm"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897245/; classtype:trojan-activity;sid:84760345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crm"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897246/; classtype:trojan-activity;sid:84760346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/le1"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897247/; classtype:trojan-activity;sid:84760347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f9m"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897248/; classtype:trojan-activity;sid:84760348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i45"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897249/; classtype:trojan-activity;sid:84760349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vpxk"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897250/; classtype:trojan-activity;sid:84760350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fb275c"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897234/; classtype:trojan-activity;sid:84760334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8de3a6"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897235/; classtype:trojan-activity;sid:84760335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/638fad"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897236/; classtype:trojan-activity;sid:84760336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e4dp"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897237/; classtype:trojan-activity;sid:84760337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1h4"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897238/; classtype:trojan-activity;sid:84760338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d0c2ec"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897239/; classtype:trojan-activity;sid:84760339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7791ff"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897240/; classtype:trojan-activity;sid:84760340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6ea756"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897216/; classtype:trojan-activity;sid:84760316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6c4fae"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897217/; classtype:trojan-activity;sid:84760317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/24f787"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897218/; classtype:trojan-activity;sid:84760318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/44a0ad"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897219/; classtype:trojan-activity;sid:84760319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/46a708"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897220/; classtype:trojan-activity;sid:84760320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e47dad"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897221/; classtype:trojan-activity;sid:84760321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bfg"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897222/; classtype:trojan-activity;sid:84760322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dbc773"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897223/; classtype:trojan-activity;sid:84760323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20571e"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897224/; classtype:trojan-activity;sid:84760324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lfso"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897225/; classtype:trojan-activity;sid:84760325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0b9a70"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897226/; classtype:trojan-activity;sid:84760326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5a6354"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897227/; classtype:trojan-activity;sid:84760327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4efa5f"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897228/; classtype:trojan-activity;sid:84760328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5df8f3"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897229/; classtype:trojan-activity;sid:84760329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3fo"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897230/; classtype:trojan-activity;sid:84760330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/550a54"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897231/; classtype:trojan-activity;sid:84760331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/30312e"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897232/; classtype:trojan-activity;sid:84760332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3e6f4b"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897233/; classtype:trojan-activity;sid:84760333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/99f8fc"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897212/; classtype:trojan-activity;sid:84760312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/927543"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897213/; classtype:trojan-activity;sid:84760313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22204c"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897214/; classtype:trojan-activity;sid:84760314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/561c87"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897215/; classtype:trojan-activity;sid:84760315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x32"; depth:9; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897211/; classtype:trojan-activity;sid:84760311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897203/; classtype:trojan-activity;sid:84760303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897204/; classtype:trojan-activity;sid:84760304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897205/; classtype:trojan-activity;sid:84760305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm4"; depth:10; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897206/; classtype:trojan-activity;sid:84760306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897207/; classtype:trojan-activity;sid:84760307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897208/; classtype:trojan-activity;sid:84760308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897209/; classtype:trojan-activity;sid:84760309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897210/; classtype:trojan-activity;sid:84760310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897201/; classtype:trojan-activity;sid:84760301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mipsel"; depth:12; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897202/; classtype:trojan-activity;sid:84760302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/js/quis.exe"; depth:12; endswith; nocase; http.host; content:"muaklekcoop.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897200/; classtype:trojan-activity;sid:84760300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.53.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897199/; classtype:trojan-activity;sid:84760299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/90222a"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897187/; classtype:trojan-activity;sid:84760287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b08330"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897188/; classtype:trojan-activity;sid:84760288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5b5269"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897189/; classtype:trojan-activity;sid:84760289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ffde1c"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897190/; classtype:trojan-activity;sid:84760290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/468c35"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897191/; classtype:trojan-activity;sid:84760291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/671ca7"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897192/; classtype:trojan-activity;sid:84760292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/973ef6"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897193/; classtype:trojan-activity;sid:84760293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e1d96d"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897194/; classtype:trojan-activity;sid:84760294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/428e4b"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897195/; classtype:trojan-activity;sid:84760295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35dde7"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897196/; classtype:trojan-activity;sid:84760296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d2593a"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897197/; classtype:trojan-activity;sid:84760297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02c2ab"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897198/; classtype:trojan-activity;sid:84760298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.106.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897186/; classtype:trojan-activity;sid:84760286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_083253.png"; depth:15; endswith; nocase; http.host; content:"edisonmanotas.free.nf"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897185/; classtype:trojan-activity;sid:84760285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_095914.png"; depth:15; endswith; nocase; http.host; content:"edisonmanotas.free.nf"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897184/; classtype:trojan-activity;sid:84760284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.249.100.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897183/; classtype:trojan-activity;sid:84760283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.69.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897182/; classtype:trojan-activity;sid:84760282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897181/; classtype:trojan-activity;sid:84760281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg11"; depth:5; endswith; nocase; http.host; content:"94.154.43.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897180/; classtype:trojan-activity;sid:84760280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sys/a/1/c2b8.zip"; depth:17; endswith; nocase; http.host; content:"xiazaixitong8.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897179/; classtype:trojan-activity;sid:84760279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"113.236.100.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897177/; classtype:trojan-activity;sid:84760277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"182.113.35.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897178/; classtype:trojan-activity;sid:84760278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msedge.exe"; depth:11; endswith; nocase; http.host; content:"us.wind0ws.net"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897176/; classtype:trojan-activity;sid:84760276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897170/; classtype:trojan-activity;sid:84760270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897171/; classtype:trojan-activity;sid:84760271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897172/; classtype:trojan-activity;sid:84760272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897173/; classtype:trojan-activity;sid:84760273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cat.sh"; depth:7; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897174/; classtype:trojan-activity;sid:84760274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"165.22.69.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897175/; classtype:trojan-activity;sid:84760275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4cb34f212849e372.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897168/; classtype:trojan-activity;sid:84760268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_d79cb36c458e4dfe.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897169/; classtype:trojan-activity;sid:84760269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_d192fc150157d0b9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897165/; classtype:trojan-activity;sid:84760265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_177da9252d94df71.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897166/; classtype:trojan-activity;sid:84760266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ok"; depth:3; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897167/; classtype:trojan-activity;sid:84760267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.136.139"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897164/; classtype:trojan-activity;sid:84760264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.168.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897163/; classtype:trojan-activity;sid:84760263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.60.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897162/; classtype:trojan-activity;sid:84760262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.8.118.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897161/; classtype:trojan-activity;sid:84760261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.239.113.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897160/; classtype:trojan-activity;sid:84760260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897159/; classtype:trojan-activity;sid:84760259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.24.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897158/; classtype:trojan-activity;sid:84760258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.60.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897157/; classtype:trojan-activity;sid:84760257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.250.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897156/; classtype:trojan-activity;sid:84760256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.250.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897155/; classtype:trojan-activity;sid:84760255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.239.113.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897154/; classtype:trojan-activity;sid:84760254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.101.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897153/; classtype:trojan-activity;sid:84760253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.185.91.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897152/; classtype:trojan-activity;sid:84760252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.30.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897151/; classtype:trojan-activity;sid:84760251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.203.87.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897150/; classtype:trojan-activity;sid:84760250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.202.244.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897149/; classtype:trojan-activity;sid:84760249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.202.244.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897148/; classtype:trojan-activity;sid:84760248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.185.53"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897147/; classtype:trojan-activity;sid:84760247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897146/; classtype:trojan-activity;sid:84760246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lol"; depth:4; endswith; nocase; http.host; content:"45.152.198.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897145/; classtype:trojan-activity;sid:84760245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.82.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897144/; classtype:trojan-activity;sid:84760244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.122.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897143/; classtype:trojan-activity;sid:84760243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.22.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897142/; classtype:trojan-activity;sid:84760242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.22.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897141/; classtype:trojan-activity;sid:84760241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.82.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897140/; classtype:trojan-activity;sid:84760240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exodus.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897139/; classtype:trojan-activity;sid:84760239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.122.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897138/; classtype:trojan-activity;sid:84760238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.92.184"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897137/; classtype:trojan-activity;sid:84760237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.88.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897136/; classtype:trojan-activity;sid:84760236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897135/; classtype:trojan-activity;sid:84760235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.92.184"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897134/; classtype:trojan-activity;sid:84760234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/renzo.sh"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897133/; classtype:trojan-activity;sid:84760233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_totolink.sh"; depth:18; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897132/; classtype:trojan-activity;sid:84760232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/netgear"; depth:8; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897131/; classtype:trojan-activity;sid:84760231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897129/; classtype:trojan-activity;sid:84760229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897130/; classtype:trojan-activity;sid:84760230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897127/; classtype:trojan-activity;sid:84760227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897128/; classtype:trojan-activity;sid:84760228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.162.162"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897126/; classtype:trojan-activity;sid:84760226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.68.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897125/; classtype:trojan-activity;sid:84760225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897124/; classtype:trojan-activity;sid:84760224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.176.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897123/; classtype:trojan-activity;sid:84760223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.176.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897122/; classtype:trojan-activity;sid:84760222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.217.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897121/; classtype:trojan-activity;sid:84760221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.109.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897120/; classtype:trojan-activity;sid:84760220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/lterouter"; depth:13; endswith; nocase; http.host; content:"144.172.67.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897119/; classtype:trojan-activity;sid:84760219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.179.45"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897118/; classtype:trojan-activity;sid:84760218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.252.222.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897117/; classtype:trojan-activity;sid:84760217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86"; depth:7; endswith; nocase; http.host; content:"144.172.67.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897112/; classtype:trojan-activity;sid:84760212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/tbk"; depth:7; endswith; nocase; http.host; content:"144.172.67.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897113/; classtype:trojan-activity;sid:84760213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv5l"; depth:10; endswith; nocase; http.host; content:"144.172.67.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897114/; classtype:trojan-activity;sid:84760214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mips"; depth:8; endswith; nocase; http.host; content:"144.172.67.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897115/; classtype:trojan-activity;sid:84760215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mpsl"; depth:8; endswith; nocase; http.host; content:"144.172.67.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897116/; classtype:trojan-activity;sid:84760216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.217.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897111/; classtype:trojan-activity;sid:84760211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.246.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897110/; classtype:trojan-activity;sid:84760210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.252.222.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897109/; classtype:trojan-activity;sid:84760209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.2.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897108/; classtype:trojan-activity;sid:84760208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.211.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897107/; classtype:trojan-activity;sid:84760207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv6"; depth:11; endswith; nocase; http.host; content:"128.0.118.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897100/; classtype:trojan-activity;sid:84760200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv4"; depth:11; endswith; nocase; http.host; content:"128.0.118.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897101/; classtype:trojan-activity;sid:84760201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.armv5"; depth:11; endswith; nocase; http.host; content:"128.0.118.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897102/; classtype:trojan-activity;sid:84760202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mips"; depth:10; endswith; nocase; http.host; content:"128.0.118.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897103/; classtype:trojan-activity;sid:84760203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"128.0.118.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897104/; classtype:trojan-activity;sid:84760204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.x86_64"; depth:12; endswith; nocase; http.host; content:"128.0.118.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897105/; classtype:trojan-activity;sid:84760205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main.mipsel"; depth:12; endswith; nocase; http.host; content:"128.0.118.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897106/; classtype:trojan-activity;sid:84760206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.2.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897099/; classtype:trojan-activity;sid:84760199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.237.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897098/; classtype:trojan-activity;sid:84760198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.107.94.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897097/; classtype:trojan-activity;sid:84760197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.54.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897095/; classtype:trojan-activity;sid:84760195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.48.77"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897096/; classtype:trojan-activity;sid:84760196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.61.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897094/; classtype:trojan-activity;sid:84760194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.68.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897093/; classtype:trojan-activity;sid:84760193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.237.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897092/; classtype:trojan-activity;sid:84760192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.211.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897091/; classtype:trojan-activity;sid:84760191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"202.107.94.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897090/; classtype:trojan-activity;sid:84760190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.186.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897089/; classtype:trojan-activity;sid:84760189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.61.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897088/; classtype:trojan-activity;sid:84760188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.249.126.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897087/; classtype:trojan-activity;sid:84760187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.43.223"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897086/; classtype:trojan-activity;sid:84760186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897085/; classtype:trojan-activity;sid:84760185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newcat.exe"; depth:11; endswith; nocase; http.host; content:"104.239.66.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897084/; classtype:trojan-activity;sid:84760184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897076/; classtype:trojan-activity;sid:84760176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897077/; classtype:trojan-activity;sid:84760177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897078/; classtype:trojan-activity;sid:84760178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897079/; classtype:trojan-activity;sid:84760179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897080/; classtype:trojan-activity;sid:84760180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897081/; classtype:trojan-activity;sid:84760181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897082/; classtype:trojan-activity;sid:84760182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"45.135.193.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897083/; classtype:trojan-activity;sid:84760183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.189.30.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897075/; classtype:trojan-activity;sid:84760175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.144.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897074/; classtype:trojan-activity;sid:84760174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.43.223"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897073/; classtype:trojan-activity;sid:84760173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b6756c"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897071/; classtype:trojan-activity;sid:84760171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b1fcc2"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897072/; classtype:trojan-activity;sid:84760172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/792865"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897064/; classtype:trojan-activity;sid:84760164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/968d9d"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897065/; classtype:trojan-activity;sid:84760165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8ee0e6"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897066/; classtype:trojan-activity;sid:84760166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b6756c"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897067/; classtype:trojan-activity;sid:84760167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/df904c"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897068/; classtype:trojan-activity;sid:84760168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a8f148"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897069/; classtype:trojan-activity;sid:84760169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9e4ba1"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897070/; classtype:trojan-activity;sid:84760170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a01c2f"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897063/; classtype:trojan-activity;sid:84760163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/99f292"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897060/; classtype:trojan-activity;sid:84760160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6d60f1"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897061/; classtype:trojan-activity;sid:84760161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/316f75"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897062/; classtype:trojan-activity;sid:84760162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a00b40"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897043/; classtype:trojan-activity;sid:84760143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9e4ba1"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897044/; classtype:trojan-activity;sid:84760144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ca6491"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897045/; classtype:trojan-activity;sid:84760145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6d60f1"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897046/; classtype:trojan-activity;sid:84760146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fbeb13"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897047/; classtype:trojan-activity;sid:84760147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b1fcc2"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897048/; classtype:trojan-activity;sid:84760148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eab403"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897049/; classtype:trojan-activity;sid:84760149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a14f31"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897050/; classtype:trojan-activity;sid:84760150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/894e81"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897051/; classtype:trojan-activity;sid:84760151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/003f95"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897052/; classtype:trojan-activity;sid:84760152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/894e81"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897053/; classtype:trojan-activity;sid:84760153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e623fb"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897054/; classtype:trojan-activity;sid:84760154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a01c2f"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897055/; classtype:trojan-activity;sid:84760155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3f20ca"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897056/; classtype:trojan-activity;sid:84760156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f19d21"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897057/; classtype:trojan-activity;sid:84760157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5f5213"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897058/; classtype:trojan-activity;sid:84760158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8ee0e6"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897059/; classtype:trojan-activity;sid:84760159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.189.30.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897042/; classtype:trojan-activity;sid:84760142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.120.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897041/; classtype:trojan-activity;sid:84760141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.144.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897040/; classtype:trojan-activity;sid:84760140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.1.109"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897039/; classtype:trojan-activity;sid:84760139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.3.196"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897038/; classtype:trojan-activity;sid:84760138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.29.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897037/; classtype:trojan-activity;sid:84760137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.192.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897036/; classtype:trojan-activity;sid:84760136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.15.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897035/; classtype:trojan-activity;sid:84760135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.29.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897034/; classtype:trojan-activity;sid:84760134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.60.101"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897033/; classtype:trojan-activity;sid:84760133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.15.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897032/; classtype:trojan-activity;sid:84760132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.244.162"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897031/; classtype:trojan-activity;sid:84760131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.59.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897030/; classtype:trojan-activity;sid:84760130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.146.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897029/; classtype:trojan-activity;sid:84760129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.61.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897028/; classtype:trojan-activity;sid:84760128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ok"; depth:3; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897027/; classtype:trojan-activity;sid:84760127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.3.196"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897026/; classtype:trojan-activity;sid:84760126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.60.101"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897025/; classtype:trojan-activity;sid:84760125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm4"; depth:10; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897023/; classtype:trojan-activity;sid:84760123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_powerpc"; depth:13; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897024/; classtype:trojan-activity;sid:84760124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm7"; depth:10; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897022/; classtype:trojan-activity;sid:84760122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm6"; depth:10; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897021/; classtype:trojan-activity;sid:84760121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_arm5"; depth:10; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897020/; classtype:trojan-activity;sid:84760120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.178.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897019/; classtype:trojan-activity;sid:84760119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.178.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897018/; classtype:trojan-activity;sid:84760118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_x86_64"; depth:12; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897017/; classtype:trojan-activity;sid:84760117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.189.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897016/; classtype:trojan-activity;sid:84760116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.arm6"; depth:18; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897014/; classtype:trojan-activity;sid:84760114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.mpsl"; depth:18; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897015/; classtype:trojan-activity;sid:84760115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.58.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897013/; classtype:trojan-activity;sid:84760113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.arm7"; depth:18; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897011/; classtype:trojan-activity;sid:84760111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.mips"; depth:18; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897012/; classtype:trojan-activity;sid:84760112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.arm5"; depth:18; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897002/; classtype:trojan-activity;sid:84760102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.x86_64"; depth:20; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897003/; classtype:trojan-activity;sid:84760103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.sh4"; depth:17; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897004/; classtype:trojan-activity;sid:84760104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.x86"; depth:17; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897005/; classtype:trojan-activity;sid:84760105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.arc"; depth:17; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897006/; classtype:trojan-activity;sid:84760106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.ppc"; depth:17; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897007/; classtype:trojan-activity;sid:84760107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.m68k"; depth:18; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897008/; classtype:trojan-activity;sid:84760108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.spc"; depth:17; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897009/; classtype:trojan-activity;sid:84760109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/boatnet.arm"; depth:17; endswith; nocase; http.host; content:"94.154.43.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897010/; classtype:trojan-activity;sid:84760110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.105.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897001/; classtype:trojan-activity;sid:84760101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.189.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3897000/; classtype:trojan-activity;sid:84760100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.220.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896999/; classtype:trojan-activity;sid:84760099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.220.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896998/; classtype:trojan-activity;sid:84760098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.0.203"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896997/; classtype:trojan-activity;sid:84760097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.105.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896996/; classtype:trojan-activity;sid:84760096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.144.217"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896995/; classtype:trojan-activity;sid:84760095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.186.204.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896994/; classtype:trojan-activity;sid:84760094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.127.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896993/; classtype:trojan-activity;sid:84760093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.144.217"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896992/; classtype:trojan-activity;sid:84760092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.132.16"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896991/; classtype:trojan-activity;sid:84760091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.9.216"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896990/; classtype:trojan-activity;sid:84760090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.121.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896989/; classtype:trojan-activity;sid:84760089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.137.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896988/; classtype:trojan-activity;sid:84760088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.9.216"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896987/; classtype:trojan-activity;sid:84760087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/968d9d"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896986/; classtype:trojan-activity;sid:84760086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3f20ca"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896978/; classtype:trojan-activity;sid:84760078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eab403"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896979/; classtype:trojan-activity;sid:84760079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/792865"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896980/; classtype:trojan-activity;sid:84760080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fbeb13"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896981/; classtype:trojan-activity;sid:84760081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e623fb"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896982/; classtype:trojan-activity;sid:84760082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ca6491"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896983/; classtype:trojan-activity;sid:84760083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a00b40"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896984/; classtype:trojan-activity;sid:84760084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a14f31"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896985/; classtype:trojan-activity;sid:84760085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896966/; classtype:trojan-activity;sid:84760066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86"; depth:7; endswith; nocase; http.host; content:"176.65.148.145.ptr.pfcloud.network"; depth:34; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896967/; classtype:trojan-activity;sid:84760067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a8f148"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896968/; classtype:trojan-activity;sid:84760068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389b2e"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896969/; classtype:trojan-activity;sid:84760069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/99f292"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896970/; classtype:trojan-activity;sid:84760070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/003f95"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896971/; classtype:trojan-activity;sid:84760071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/316f75"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896972/; classtype:trojan-activity;sid:84760072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5f5213"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896973/; classtype:trojan-activity;sid:84760073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv5l"; depth:10; endswith; nocase; http.host; content:"176.65.148.145.ptr.pfcloud.network"; depth:34; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896974/; classtype:trojan-activity;sid:84760074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/df904c"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896975/; classtype:trojan-activity;sid:84760075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f19d21"; depth:7; endswith; nocase; http.host; content:"45.135.194.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896976/; classtype:trojan-activity;sid:84760076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/389b2e"; depth:7; endswith; nocase; http.host; content:"45.135.194.70.ptr.pfcloud.network"; depth:33; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896977/; classtype:trojan-activity;sid:84760077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"72.255.3.147"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896965/; classtype:trojan-activity;sid:84760065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kaizen.mpsl"; depth:17; endswith; nocase; http.host; content:"176.65.149.168.ptr.pfcloud.network"; depth:34; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896964/; classtype:trojan-activity;sid:84760064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t"; depth:2; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896963/; classtype:trojan-activity;sid:84760063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parc"; depth:10; endswith; nocase; http.host; content:"94.154.43.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896954/; classtype:trojan-activity;sid:84760054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896955/; classtype:trojan-activity;sid:84760055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896956/; classtype:trojan-activity;sid:84760056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896957/; classtype:trojan-activity;sid:84760057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm64"; depth:12; endswith; nocase; http.host; content:"94.154.43.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896958/; classtype:trojan-activity;sid:84760058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parm7"; depth:6; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896959/; classtype:trojan-activity;sid:84760059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.mpsl"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896960/; classtype:trojan-activity;sid:84760060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.spc"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896961/; classtype:trojan-activity;sid:84760061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t"; depth:2; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896962/; classtype:trojan-activity;sid:84760062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896953/; classtype:trojan-activity;sid:84760053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/tbk"; depth:7; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896952/; classtype:trojan-activity;sid:84760052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/tbk"; depth:7; endswith; nocase; http.host; content:"176.65.148.145.ptr.pfcloud.network"; depth:34; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896951/; classtype:trojan-activity;sid:84760051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86_64"; depth:10; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896950/; classtype:trojan-activity;sid:84760050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv7l"; depth:10; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896945/; classtype:trojan-activity;sid:84760045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv5l"; depth:10; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896946/; classtype:trojan-activity;sid:84760046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/m68k"; depth:8; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896947/; classtype:trojan-activity;sid:84760047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/sh4"; depth:7; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896948/; classtype:trojan-activity;sid:84760048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/sparc"; depth:9; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896949/; classtype:trojan-activity;sid:84760049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv6l"; depth:10; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896939/; classtype:trojan-activity;sid:84760039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/armv4l"; depth:10; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896940/; classtype:trojan-activity;sid:84760040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/ppc"; depth:7; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896941/; classtype:trojan-activity;sid:84760041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/aarch64"; depth:11; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896942/; classtype:trojan-activity;sid:84760042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mips64"; depth:10; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896943/; classtype:trojan-activity;sid:84760043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/x86"; depth:7; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896944/; classtype:trojan-activity;sid:84760044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.133.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896938/; classtype:trojan-activity;sid:84760038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.35.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896937/; classtype:trojan-activity;sid:84760037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mpsl"; depth:8; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896936/; classtype:trojan-activity;sid:84760036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/lterouter"; depth:13; endswith; nocase; http.host; content:"176.65.148.145.ptr.pfcloud.network"; depth:34; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896935/; classtype:trojan-activity;sid:84760035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mips"; depth:8; endswith; nocase; http.host; content:"176.65.148.145.ptr.pfcloud.network"; depth:34; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896934/; classtype:trojan-activity;sid:84760034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mpsl"; depth:8; endswith; nocase; http.host; content:"176.65.148.145.ptr.pfcloud.network"; depth:34; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896933/; classtype:trojan-activity;sid:84760033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/mips"; depth:8; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896932/; classtype:trojan-activity;sid:84760032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2/lterouter"; depth:13; endswith; nocase; http.host; content:"176.65.148.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896931/; classtype:trojan-activity;sid:84760031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.206.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896930/; classtype:trojan-activity;sid:84760030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.106.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896929/; classtype:trojan-activity;sid:84760029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.91.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896928/; classtype:trojan-activity;sid:84760028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.91.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896927/; classtype:trojan-activity;sid:84760027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.244.162"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896926/; classtype:trojan-activity;sid:84760026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896925/; classtype:trojan-activity;sid:84760025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.6.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896924/; classtype:trojan-activity;sid:84760024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896923/; classtype:trojan-activity;sid:84760023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.6.102"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896922/; classtype:trojan-activity;sid:84760022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"106.58.21.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896921/; classtype:trojan-activity;sid:84760021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dv/ugo_050448.png"; depth:18; endswith; nocase; http.host; content:"133.18.106.222"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896920/; classtype:trojan-activity;sid:84760020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibcws"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896919/; classtype:trojan-activity;sid:84760019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_010539.png"; depth:15; endswith; nocase; http.host; content:"crypter.gt.tc"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896918/; classtype:trojan-activity;sid:84760018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.134.162.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896917/; classtype:trojan-activity;sid:84760017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/x1pruzo/housct1/afeygxd/fan/crypted.ps1"; depth:47; endswith; nocase; http.host; content:"yd.lyjt.cc"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896916/; classtype:trojan-activity;sid:84760016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.134.162.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896915/; classtype:trojan-activity;sid:84760015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keizr"; depth:6; endswith; nocase; http.host; content:"misty-cherry-cea3.uploadsimg.workers.dev"; depth:40; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896914/; classtype:trojan-activity;sid:84760014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reverse0100/xc/refs/heads/main/test.exe"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896913/; classtype:trojan-activity;sid:84760013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypted.ps1"; depth:12; endswith; nocase; http.host; content:"217.60.241.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896911/; classtype:trojan-activity;sid:84760011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.173.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896912/; classtype:trojan-activity;sid:84760012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/ofelia.dat"; depth:13; endswith; nocase; http.host; content:"89.23.107.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896910/; classtype:trojan-activity;sid:84760010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.48.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896909/; classtype:trojan-activity;sid:84760009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.165.187.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896908/; classtype:trojan-activity;sid:84760008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clarored5g.apk"; depth:15; endswith; nocase; http.host; content:"actualiza-red5g.app"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896907/; classtype:trojan-activity;sid:84760007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_14de5020f1706d7b.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896906/; classtype:trojan-activity;sid:84760006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl/a7ec41c89a3dc6bf3de47264b4a3013134c7273dd1aa379859c2149b7517f0b2"; depth:70; endswith; nocase; http.host; content:"ferncurrent14.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896905/; classtype:trojan-activity;sid:84760005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_15dd8c97bdb470a5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896904/; classtype:trojan-activity;sid:84760004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.59.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896903/; classtype:trojan-activity;sid:84760003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/weneedsomethingperfectformbetterplace.vbe"; depth:45; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896902/; classtype:trojan-activity;sid:84760002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.152.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896901/; classtype:trojan-activity;sid:84760001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.152.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896900/; classtype:trojan-activity;sid:84760000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaze.exe"; depth:9; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896898/; classtype:trojan-activity;sid:84759998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r843.exe"; depth:9; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896899/; classtype:trojan-activity;sid:84759999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.arm"; depth:12; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896895/; classtype:trojan-activity;sid:84759995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.m68k"; depth:13; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896896/; classtype:trojan-activity;sid:84759996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oo3q"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896897/; classtype:trojan-activity;sid:84759997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.i686"; depth:13; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896889/; classtype:trojan-activity;sid:84759989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.arm7"; depth:13; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896890/; classtype:trojan-activity;sid:84759990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.mips"; depth:13; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896891/; classtype:trojan-activity;sid:84759991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.ppc"; depth:12; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896892/; classtype:trojan-activity;sid:84759992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.sh4"; depth:12; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896893/; classtype:trojan-activity;sid:84759993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.x86_64"; depth:15; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896894/; classtype:trojan-activity;sid:84759994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.spc"; depth:12; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896878/; classtype:trojan-activity;sid:84759978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.arm5"; depth:13; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896879/; classtype:trojan-activity;sid:84759979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.arc"; depth:12; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896880/; classtype:trojan-activity;sid:84759980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3jhm"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896881/; classtype:trojan-activity;sid:84759981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.arm6"; depth:13; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896882/; classtype:trojan-activity;sid:84759982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crrx"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896883/; classtype:trojan-activity;sid:84759983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.mpsl"; depth:13; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896884/; classtype:trojan-activity;sid:84759984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/l2l"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896885/; classtype:trojan-activity;sid:84759985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.i468"; depth:13; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896886/; classtype:trojan-activity;sid:84759986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbi/bot.x86"; depth:12; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896887/; classtype:trojan-activity;sid:84759987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xum"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896888/; classtype:trojan-activity;sid:84759988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.165.187.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896877/; classtype:trojan-activity;sid:84759977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.138.173.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896876/; classtype:trojan-activity;sid:84759976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.59.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896875/; classtype:trojan-activity;sid:84759975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.39.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896874/; classtype:trojan-activity;sid:84759974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.127.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896873/; classtype:trojan-activity;sid:84759973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.236.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896872/; classtype:trojan-activity;sid:84759972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.59.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896871/; classtype:trojan-activity;sid:84759971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.39.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896870/; classtype:trojan-activity;sid:84759970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.94.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896869/; classtype:trojan-activity;sid:84759969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.236.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896868/; classtype:trojan-activity;sid:84759968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.117.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896867/; classtype:trojan-activity;sid:84759967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.59.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896866/; classtype:trojan-activity;sid:84759966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.117.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896865/; classtype:trojan-activity;sid:84759965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.0.156"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896864/; classtype:trojan-activity;sid:84759964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.232.178"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896863/; classtype:trojan-activity;sid:84759963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.exe"; depth:8; endswith; nocase; http.host; content:"79.137.194.83"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896862/; classtype:trojan-activity;sid:84759962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.0.130"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896861/; classtype:trojan-activity;sid:84759961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.0.156"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896860/; classtype:trojan-activity;sid:84759960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.26.202.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896859/; classtype:trojan-activity;sid:84759959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.180.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896858/; classtype:trojan-activity;sid:84759958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.95.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896857/; classtype:trojan-activity;sid:84759957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7782139129/knuyeb0.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896856/; classtype:trojan-activity;sid:84759956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.180.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896855/; classtype:trojan-activity;sid:84759955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/q092390mb/crypted.ps1"; depth:22; endswith; nocase; http.host; content:"213.165.78.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896854/; classtype:trojan-activity;sid:84759954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60/verygoodepeoplesaroundonemylifeforme.vbe"; depth:44; endswith; nocase; http.host; content:"107.175.202.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896853/; classtype:trojan-activity;sid:84759953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_205427.png"; depth:15; endswith; nocase; http.host; content:"dungeonfive.rf.gd"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896852/; classtype:trojan-activity;sid:84759952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_082638.png"; depth:15; endswith; nocase; http.host; content:"dungeonfive.rf.gd"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896851/; classtype:trojan-activity;sid:84759951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.26.202.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896850/; classtype:trojan-activity;sid:84759950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt.ps1"; depth:10; endswith; nocase; http.host; content:"217.60.241.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896849/; classtype:trojan-activity;sid:84759949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grace/outsplen.pfb"; depth:19; endswith; nocase; http.host; content:"104.161.46.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896848/; classtype:trojan-activity;sid:84759948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.254.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896847/; classtype:trojan-activity;sid:84759947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.135.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896846/; classtype:trojan-activity;sid:84759946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grace/umoralsk.lzh"; depth:19; endswith; nocase; http.host; content:"104.161.46.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896842/; classtype:trojan-activity;sid:84759942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grace/bjcumbu57.bin"; depth:20; endswith; nocase; http.host; content:"104.161.46.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896843/; classtype:trojan-activity;sid:84759943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grace/pqmunhpxpna71.bin"; depth:24; endswith; nocase; http.host; content:"104.161.46.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896844/; classtype:trojan-activity;sid:84759944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grace/kaaqgvfm226.bin"; depth:22; endswith; nocase; http.host; content:"104.161.46.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896845/; classtype:trojan-activity;sid:84759945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rr/crypted.ps1"; depth:15; endswith; nocase; http.host; content:"217.60.241.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896841/; classtype:trojan-activity;sid:84759941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tc/crypted.ps1"; depth:15; endswith; nocase; http.host; content:"217.60.241.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896838/; classtype:trojan-activity;sid:84759938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bs/crypted.ps1"; depth:15; endswith; nocase; http.host; content:"217.60.241.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896839/; classtype:trojan-activity;sid:84759939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rk/crypted.ps1"; depth:15; endswith; nocase; http.host; content:"217.60.241.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896840/; classtype:trojan-activity;sid:84759940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.84.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896837/; classtype:trojan-activity;sid:84759937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spmm/187.txt"; depth:13; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896834/; classtype:trojan-activity;sid:84759934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ot/2598.txt"; depth:12; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896835/; classtype:trojan-activity;sid:84759935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spm/53.txt"; depth:11; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896836/; classtype:trojan-activity;sid:84759936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spmm/6168.txt"; depth:14; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896833/; classtype:trojan-activity;sid:84759933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spmm/n.txt"; depth:11; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896826/; classtype:trojan-activity;sid:84759926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ot/n.txt"; depth:9; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896827/; classtype:trojan-activity;sid:84759927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spmmm/n.txt"; depth:12; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896828/; classtype:trojan-activity;sid:84759928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spm/n.txt"; depth:10; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896829/; classtype:trojan-activity;sid:84759929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/us/n.txt"; depth:9; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896830/; classtype:trojan-activity;sid:84759930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/us/18109.txt"; depth:13; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896831/; classtype:trojan-activity;sid:84759931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spmmm/215.txt"; depth:14; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896832/; classtype:trojan-activity;sid:84759932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clp.exe"; depth:8; endswith; nocase; http.host; content:"62.60.226.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896825/; classtype:trojan-activity;sid:84759925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.144.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896824/; classtype:trojan-activity;sid:84759924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b5x"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896823/; classtype:trojan-activity;sid:84759923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.254.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896822/; classtype:trojan-activity;sid:84759922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.222.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896821/; classtype:trojan-activity;sid:84759921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/js/chunk.sh"; depth:19; endswith; nocase; http.host; content:"94.154.43.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896818/; classtype:trojan-activity;sid:84759918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896819/; classtype:trojan-activity;sid:84759919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.84.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896820/; classtype:trojan-activity;sid:84759920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_194702.png"; depth:15; endswith; nocase; http.host; content:"pub-ce02802067934e0eb072f69bf6427bf6.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896815/; classtype:trojan-activity;sid:84759915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.242.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896816/; classtype:trojan-activity;sid:84759916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dfify"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896817/; classtype:trojan-activity;sid:84759917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/v/refs/heads/main/fhdohmm.txt"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896814/; classtype:trojan-activity;sid:84759914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eac"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896811/; classtype:trojan-activity;sid:84759911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fko"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896812/; classtype:trojan-activity;sid:84759912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s4cq"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896813/; classtype:trojan-activity;sid:84759913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ywy4"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896809/; classtype:trojan-activity;sid:84759909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.129.144.190"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896810/; classtype:trojan-activity;sid:84759910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/tr/refs/heads/main/jkiakks.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896804/; classtype:trojan-activity;sid:84759904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/ng/refs/heads/main/apndffe.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896805/; classtype:trojan-activity;sid:84759905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/rw/refs/heads/main/mfidfai.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896806/; classtype:trojan-activity;sid:84759906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/bv/refs/heads/main/emgkjhm.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896807/; classtype:trojan-activity;sid:84759907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/dsf/refs/heads/main/masdpne.txt"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896808/; classtype:trojan-activity;sid:84759908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/dfe/refs/heads/main/adsjfas.txt"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896803/; classtype:trojan-activity;sid:84759903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/tea/refs/heads/main/purchase%20order07202025.txt"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896791/; classtype:trojan-activity;sid:84759891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/game/refs/heads/main/eipideg.txt"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896792/; classtype:trojan-activity;sid:84759892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/df/refs/heads/main/enmkbdd.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896793/; classtype:trojan-activity;sid:84759893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/ja/refs/heads/main/mrnfomk.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896794/; classtype:trojan-activity;sid:84759894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/nhg/refs/heads/main/fniiacd.txt"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896795/; classtype:trojan-activity;sid:84759895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/hy/refs/heads/main/agjgjrm.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896796/; classtype:trojan-activity;sid:84759896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/ds/refs/heads/main/kkmshfk.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896797/; classtype:trojan-activity;sid:84759897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/jh/refs/heads/main/isiieef.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896798/; classtype:trojan-activity;sid:84759898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/sa/refs/heads/main/ibrdrno.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896799/; classtype:trojan-activity;sid:84759899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/de/refs/heads/main/ncdoiek.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896800/; classtype:trojan-activity;sid:84759900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/team/refs/heads/main/imrhfbb.txt"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896801/; classtype:trojan-activity;sid:84759901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/re/refs/heads/main/ksfgkki.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896802/; classtype:trojan-activity;sid:84759902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/dc/refs/heads/main/dpakpnj.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896790/; classtype:trojan-activity;sid:84759890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/1.jpg"; depth:10; endswith; nocase; http.host; content:"209.54.103.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896789/; classtype:trojan-activity;sid:84759889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_071628.png"; depth:15; endswith; nocase; http.host; content:"cxxz.co.za"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896787/; classtype:trojan-activity;sid:84759887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_071655.png"; depth:15; endswith; nocase; http.host; content:"cxxz.co.za"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896788/; classtype:trojan-activity;sid:84759888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgalliebuilder/hd/refs/heads/main/knardhg.txt"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896786/; classtype:trojan-activity;sid:84759886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_lqp9mlpgdd.png"; depth:21; endswith; nocase; http.host; content:"ahad-cn.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896785/; classtype:trojan-activity;sid:84759885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plvoa"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896783/; classtype:trojan-activity;sid:84759883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ja06813kda.png"; depth:15; endswith; nocase; http.host; content:"lomiva.vu"; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896784/; classtype:trojan-activity;sid:84759884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/bin.dat"; depth:13; endswith; nocase; http.host; content:"hjha.ao"; depth:7; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896782/; classtype:trojan-activity;sid:84759882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/znicb"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896781/; classtype:trojan-activity;sid:84759881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.87.161.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896780/; classtype:trojan-activity;sid:84759880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_231339.png"; depth:15; endswith; nocase; http.host; content:"simplejack.lovestoblog.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896779/; classtype:trojan-activity;sid:84759879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.129.144.190"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896778/; classtype:trojan-activity;sid:84759878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.144.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896777/; classtype:trojan-activity;sid:84759877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.135.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896776/; classtype:trojan-activity;sid:84759876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896767/; classtype:trojan-activity;sid:84759867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896768/; classtype:trojan-activity;sid:84759868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896769/; classtype:trojan-activity;sid:84759869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896770/; classtype:trojan-activity;sid:84759870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896771/; classtype:trojan-activity;sid:84759871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896772/; classtype:trojan-activity;sid:84759872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896773/; classtype:trojan-activity;sid:84759873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896774/; classtype:trojan-activity;sid:84759874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_d92c6432e98f51c4.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896775/; classtype:trojan-activity;sid:84759875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.86.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896765/; classtype:trojan-activity;sid:84759865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.96.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896766/; classtype:trojan-activity;sid:84759866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.51"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896764/; classtype:trojan-activity;sid:84759864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.112.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896763/; classtype:trojan-activity;sid:84759863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.131.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896762/; classtype:trojan-activity;sid:84759862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.150.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896761/; classtype:trojan-activity;sid:84759861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.157.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896758/; classtype:trojan-activity;sid:84759858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.83.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896759/; classtype:trojan-activity;sid:84759859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.42.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896760/; classtype:trojan-activity;sid:84759860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.63.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896757/; classtype:trojan-activity;sid:84759857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.245.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896756/; classtype:trojan-activity;sid:84759856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896755/; classtype:trojan-activity;sid:84759855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.14.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896753/; classtype:trojan-activity;sid:84759853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.24.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896754/; classtype:trojan-activity;sid:84759854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.203.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896752/; classtype:trojan-activity;sid:84759852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12345/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"107.173.62.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896751/; classtype:trojan-activity;sid:84759851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkk.png"; depth:8; endswith; nocase; http.host; content:"pub-3bc1de741f8149f49bdbafa703067f24.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896750/; classtype:trojan-activity;sid:84759850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_005044.png"; depth:15; endswith; nocase; http.host; content:"savannahadventureslimited.com"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896749/; classtype:trojan-activity;sid:84759849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juaags.png"; depth:11; endswith; nocase; http.host; content:"pub-3bc1de741f8149f49bdbafa703067f24.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896747/; classtype:trojan-activity;sid:84759847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pzkgg"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896748/; classtype:trojan-activity;sid:84759848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a2.png"; depth:7; endswith; nocase; http.host; content:"pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896746/; classtype:trojan-activity;sid:84759846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_003709.png"; depth:15; endswith; nocase; http.host; content:"savannahadventureslimited.com"; depth:29; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896745/; classtype:trojan-activity;sid:84759845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/buuxh"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896744/; classtype:trojan-activity;sid:84759844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fy123.png"; depth:10; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896743/; classtype:trojan-activity;sid:84759843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xeuhv"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896742/; classtype:trojan-activity;sid:84759842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.mpsl"; depth:14; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896741/; classtype:trojan-activity;sid:84759841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.arm5"; depth:14; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896732/; classtype:trojan-activity;sid:84759832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.arm6"; depth:14; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896733/; classtype:trojan-activity;sid:84759833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.x86_32"; depth:16; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896734/; classtype:trojan-activity;sid:84759834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.x86_64"; depth:16; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896735/; classtype:trojan-activity;sid:84759835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.ppc64le"; depth:17; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896736/; classtype:trojan-activity;sid:84759836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.armhf"; depth:15; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896737/; classtype:trojan-activity;sid:84759837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.arm7"; depth:14; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896738/; classtype:trojan-activity;sid:84759838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.mips"; depth:14; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896739/; classtype:trojan-activity;sid:84759839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.sh4"; depth:13; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896740/; classtype:trojan-activity;sid:84759840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.arm"; depth:13; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896730/; classtype:trojan-activity;sid:84759830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.ppc"; depth:13; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896731/; classtype:trojan-activity;sid:84759831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.i486"; depth:14; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896726/; classtype:trojan-activity;sid:84759826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.aarch64"; depth:17; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896727/; classtype:trojan-activity;sid:84759827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.ppc64"; depth:15; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896728/; classtype:trojan-activity;sid:84759828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumminer.m68k"; depth:14; endswith; nocase; http.host; content:"94.154.43.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896729/; classtype:trojan-activity;sid:84759829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896725/; classtype:trojan-activity;sid:84759825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896721/; classtype:trojan-activity;sid:84759821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896722/; classtype:trojan-activity;sid:84759822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896723/; classtype:trojan-activity;sid:84759823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896724/; classtype:trojan-activity;sid:84759824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896720/; classtype:trojan-activity;sid:84759820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896719/; classtype:trojan-activity;sid:84759819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896715/; classtype:trojan-activity;sid:84759815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896716/; classtype:trojan-activity;sid:84759816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896717/; classtype:trojan-activity;sid:84759817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"94.154.43.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896718/; classtype:trojan-activity;sid:84759818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.125.17.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896714/; classtype:trojan-activity;sid:84759814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.28.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896713/; classtype:trojan-activity;sid:84759813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.28.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896712/; classtype:trojan-activity;sid:84759812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.53.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896711/; classtype:trojan-activity;sid:84759811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.exe"; depth:6; endswith; nocase; http.host; content:"62.60.226.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896710/; classtype:trojan-activity;sid:84759810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svchost.exe"; depth:12; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896709/; classtype:trojan-activity;sid:84759809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4.exe"; depth:6; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896708/; classtype:trojan-activity;sid:84759808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_082432.png"; depth:15; endswith; nocase; http.host; content:"deliozmabrano.site.je"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896707/; classtype:trojan-activity;sid:84759807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/general/bind.ps1"; depth:17; endswith; nocase; http.host; content:"31.57.219.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896704/; classtype:trojan-activity;sid:84759804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/general/lincoln.ps1"; depth:20; endswith; nocase; http.host; content:"31.57.219.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896705/; classtype:trojan-activity;sid:84759805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/general/crypted.ps1"; depth:20; endswith; nocase; http.host; content:"31.57.219.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896706/; classtype:trojan-activity;sid:84759806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.125.17.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896703/; classtype:trojan-activity;sid:84759803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/general/general.ps1"; depth:20; endswith; nocase; http.host; content:"31.57.219.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896702/; classtype:trojan-activity;sid:84759802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.53.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896701/; classtype:trojan-activity;sid:84759801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.exe"; depth:6; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896699/; classtype:trojan-activity;sid:84759799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.exe"; depth:6; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896700/; classtype:trojan-activity;sid:84759800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896698/; classtype:trojan-activity;sid:84759798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.7.exe"; depth:8; endswith; nocase; http.host; content:"62.60.226.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896696/; classtype:trojan-activity;sid:84759796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"62.60.226.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896697/; classtype:trojan-activity;sid:84759797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1lwriyvalqhr4vbrajyyukuxtoczjbdoq"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896695/; classtype:trojan-activity;sid:84759795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x.sh"; depth:5; endswith; nocase; http.host; content:"176.124.207.93"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896693/; classtype:trojan-activity;sid:84759793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pearl-miner"; depth:12; endswith; nocase; http.host; content:"176.124.207.93"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896694/; classtype:trojan-activity;sid:84759794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9876567890/crypted.ps1"; depth:23; endswith; nocase; http.host; content:"213.165.78.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896692/; classtype:trojan-activity;sid:84759792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/36/ecc/iwantsomethingbetterformegetbackgoodthings.vbe"; depth:54; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896691/; classtype:trojan-activity;sid:84759791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roy"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896686/; classtype:trojan-activity;sid:84759786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fue0"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896687/; classtype:trojan-activity;sid:84759787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oi5j"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896688/; classtype:trojan-activity;sid:84759788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rky"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896689/; classtype:trojan-activity;sid:84759789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yu9"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896690/; classtype:trojan-activity;sid:84759790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ph/velogs.exe"; depth:14; endswith; nocase; http.host; content:"172.245.95.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896685/; classtype:trojan-activity;sid:84759785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/semberrt/crypted.ps1"; depth:21; endswith; nocase; http.host; content:"213.165.78.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896683/; classtype:trojan-activity;sid:84759783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35/eas/niceworking.vbe"; depth:23; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896684/; classtype:trojan-activity;sid:84759784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cloudflare"; depth:11; endswith; nocase; http.host; content:"2.27.160.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896681/; classtype:trojan-activity;sid:84759781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app/039f4a65f430/hurma.ps1"; depth:27; endswith; nocase; http.host; content:"2.27.160.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896682/; classtype:trojan-activity;sid:84759782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.115.177.84"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896680/; classtype:trojan-activity;sid:84759780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.130.103"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896679/; classtype:trojan-activity;sid:84759779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"182.126.198.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896678/; classtype:trojan-activity;sid:84759778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"42.232.238.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896677/; classtype:trojan-activity;sid:84759777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.arc"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896675/; classtype:trojan-activity;sid:84759775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.i468"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896676/; classtype:trojan-activity;sid:84759776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.239.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896674/; classtype:trojan-activity;sid:84759774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.180.122.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896673/; classtype:trojan-activity;sid:84759773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.x86"; depth:25; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896672/; classtype:trojan-activity;sid:84759772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.x86"; depth:13; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896670/; classtype:trojan-activity;sid:84759770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.aarch64"; depth:17; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896671/; classtype:trojan-activity;sid:84759771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.sh4"; depth:25; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896664/; classtype:trojan-activity;sid:84759764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.arm7"; depth:26; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896665/; classtype:trojan-activity;sid:84759765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.arm4"; depth:26; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896666/; classtype:trojan-activity;sid:84759766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.mips"; depth:26; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896667/; classtype:trojan-activity;sid:84759767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.arm6"; depth:26; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896668/; classtype:trojan-activity;sid:84759768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.m68k"; depth:26; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896669/; classtype:trojan-activity;sid:84759769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.arm4"; depth:14; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896663/; classtype:trojan-activity;sid:84759763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.arm7"; depth:14; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896662/; classtype:trojan-activity;sid:84759762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.mpsl"; depth:26; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896657/; classtype:trojan-activity;sid:84759757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.x86_64"; depth:16; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896658/; classtype:trojan-activity;sid:84759758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.ppc"; depth:25; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896659/; classtype:trojan-activity;sid:84759759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandoras_box/pandora.arm5"; depth:26; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896660/; classtype:trojan-activity;sid:84759760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.mips"; depth:14; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896661/; classtype:trojan-activity;sid:84759761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbotx.mipsel"; depth:16; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896656/; classtype:trojan-activity;sid:84759756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.mipsl"; depth:19; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896654/; classtype:trojan-activity;sid:84759754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.x86_32"; depth:20; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896651/; classtype:trojan-activity;sid:84759751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896652/; classtype:trojan-activity;sid:84759752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.m68k"; depth:18; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896653/; classtype:trojan-activity;sid:84759753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896645/; classtype:trojan-activity;sid:84759745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896646/; classtype:trojan-activity;sid:84759746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.ppc"; depth:17; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896647/; classtype:trojan-activity;sid:84759747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.i686"; depth:18; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896648/; classtype:trojan-activity;sid:84759748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896649/; classtype:trojan-activity;sid:84759749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandora.sh"; depth:11; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896650/; classtype:trojan-activity;sid:84759750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896624/; classtype:trojan-activity;sid:84759724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896625/; classtype:trojan-activity;sid:84759725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896626/; classtype:trojan-activity;sid:84759726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896627/; classtype:trojan-activity;sid:84759727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jen.sh"; depth:7; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896628/; classtype:trojan-activity;sid:84759728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0day.sh"; depth:8; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896629/; classtype:trojan-activity;sid:84759729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arm5"; depth:18; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896630/; classtype:trojan-activity;sid:84759730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896631/; classtype:trojan-activity;sid:84759731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.mips"; depth:18; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896632/; classtype:trojan-activity;sid:84759732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896633/; classtype:trojan-activity;sid:84759733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi.sh"; depth:7; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896634/; classtype:trojan-activity;sid:84759734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.i486"; depth:18; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896635/; classtype:trojan-activity;sid:84759735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arm6"; depth:18; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896636/; classtype:trojan-activity;sid:84759736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896637/; classtype:trojan-activity;sid:84759737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896638/; classtype:trojan-activity;sid:84759738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.ppc440"; depth:20; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896639/; classtype:trojan-activity;sid:84759739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.sh4"; depth:17; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896640/; classtype:trojan-activity;sid:84759740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896641/; classtype:trojan-activity;sid:84759741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arc"; depth:17; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896642/; classtype:trojan-activity;sid:84759742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arm"; depth:17; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896643/; classtype:trojan-activity;sid:84759743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.spc"; depth:17; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896644/; classtype:trojan-activity;sid:84759744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.75.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896623/; classtype:trojan-activity;sid:84759723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stc-pg-cr.exe"; depth:14; endswith; nocase; http.host; content:"193.111.117.6"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896622/; classtype:trojan-activity;sid:84759722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/50/ecc/asd.hta"; depth:15; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896621/; classtype:trojan-activity;sid:84759721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/36/goodthingswithbestfeaturesformebetterformegood.hta"; depth:54; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896620/; classtype:trojan-activity;sid:84759720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35/goodthingsarecomingfromthebestplacescomingforme.hta"; depth:55; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896618/; classtype:trojan-activity;sid:84759718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/09890/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"57.129.23.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896619/; classtype:trojan-activity;sid:84759719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shell/crypted.ps1"; depth:18; endswith; nocase; http.host; content:"107.175.202.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896617/; classtype:trojan-activity;sid:84759717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/95/uun/goodthingsarecomingfromtheheartforu.hta"; depth:47; endswith; nocase; http.host; content:"107.175.202.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896616/; classtype:trojan-activity;sid:84759716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laberuntime.exe"; depth:16; endswith; nocase; http.host; content:"62.60.244.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896615/; classtype:trojan-activity;sid:84759715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/revoconsole.exe"; depth:16; endswith; nocase; http.host; content:"62.60.244.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896614/; classtype:trojan-activity;sid:84759714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.75.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896613/; classtype:trojan-activity;sid:84759713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.68.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896612/; classtype:trojan-activity;sid:84759712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mipsel"; depth:11; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896610/; classtype:trojan-activity;sid:84759710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; depth:32; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896611/; classtype:trojan-activity;sid:84759711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896599/; classtype:trojan-activity;sid:84759699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.i686"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896600/; classtype:trojan-activity;sid:84759700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896601/; classtype:trojan-activity;sid:84759701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896602/; classtype:trojan-activity;sid:84759702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896603/; classtype:trojan-activity;sid:84759703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896604/; classtype:trojan-activity;sid:84759704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnarmv7xnxn"; depth:31; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896605/; classtype:trojan-activity;sid:84759705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnx86xnxn"; depth:29; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896606/; classtype:trojan-activity;sid:84759706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; depth:33; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896607/; classtype:trojan-activity;sid:84759707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnmipselxnxn"; depth:32; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896608/; classtype:trojan-activity;sid:84759708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.aarch64"; depth:12; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896609/; classtype:trojan-activity;sid:84759709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; depth:30; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896598/; classtype:trojan-activity;sid:84759698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896597/; classtype:trojan-activity;sid:84759697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896595/; classtype:trojan-activity;sid:84759695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896596/; classtype:trojan-activity;sid:84759696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896587/; classtype:trojan-activity;sid:84759687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896588/; classtype:trojan-activity;sid:84759688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"94.154.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896589/; classtype:trojan-activity;sid:84759689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.x86_64"; depth:20; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896590/; classtype:trojan-activity;sid:84759690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896591/; classtype:trojan-activity;sid:84759691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arm7"; depth:18; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896592/; classtype:trojan-activity;sid:84759692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896593/; classtype:trojan-activity;sid:84759693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896594/; classtype:trojan-activity;sid:84759694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/debug.dbg"; depth:10; endswith; nocase; http.host; content:"180.93.116.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896586/; classtype:trojan-activity;sid:84759686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896585/; classtype:trojan-activity;sid:84759685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896584/; classtype:trojan-activity;sid:84759684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i686"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896582/; classtype:trojan-activity;sid:84759682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc"; depth:8; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896583/; classtype:trojan-activity;sid:84759683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arc"; depth:8; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896580/; classtype:trojan-activity;sid:84759680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.m68k"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896581/; classtype:trojan-activity;sid:84759681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mpsl"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896579/; classtype:trojan-activity;sid:84759679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896577/; classtype:trojan-activity;sid:84759677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.sh4"; depth:8; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896578/; classtype:trojan-activity;sid:84759678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i468"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896576/; classtype:trojan-activity;sid:84759676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm6"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896573/; classtype:trojan-activity;sid:84759673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm5"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896574/; classtype:trojan-activity;sid:84759674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.spc"; depth:8; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896575/; classtype:trojan-activity;sid:84759675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f8e54fc83cce4649"; depth:17; endswith; nocase; http.host; content:"enter-pverif-code.info"; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896572/; classtype:trojan-activity;sid:84759672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.aarch64"; depth:14; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896571/; classtype:trojan-activity;sid:84759671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c1wn"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896551/; classtype:trojan-activity;sid:84759651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dln"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896552/; classtype:trojan-activity;sid:84759652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bsli"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896553/; classtype:trojan-activity;sid:84759653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joe0"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896554/; classtype:trojan-activity;sid:84759654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f2m"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896555/; classtype:trojan-activity;sid:84759655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p3b"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896556/; classtype:trojan-activity;sid:84759656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ktjt"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896557/; classtype:trojan-activity;sid:84759657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sg2s"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896558/; classtype:trojan-activity;sid:84759658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bkg"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896559/; classtype:trojan-activity;sid:84759659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vje"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896560/; classtype:trojan-activity;sid:84759660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/l9a"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896561/; classtype:trojan-activity;sid:84759661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5gd"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896562/; classtype:trojan-activity;sid:84759662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mztw"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896563/; classtype:trojan-activity;sid:84759663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uzpl"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896564/; classtype:trojan-activity;sid:84759664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muu"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896565/; classtype:trojan-activity;sid:84759665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ijr"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896566/; classtype:trojan-activity;sid:84759666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qzf"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896567/; classtype:trojan-activity;sid:84759667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bm88"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896568/; classtype:trojan-activity;sid:84759668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3y9c"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896569/; classtype:trojan-activity;sid:84759669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0thb"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896570/; classtype:trojan-activity;sid:84759670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0x83911d24fx.sh"; depth:16; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896549/; classtype:trojan-activity;sid:84759649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/icon/js/greppts3.sh"; depth:20; endswith; nocase; http.host; content:"119.194.153.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896550/; classtype:trojan-activity;sid:84759650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896548/; classtype:trojan-activity;sid:84759648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unifi"; depth:6; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896547/; classtype:trojan-activity;sid:84759647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/systemd"; depth:8; endswith; nocase; http.host; content:"91.188.254.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896545/; classtype:trojan-activity;sid:84759645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d.sh"; depth:5; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896544/; classtype:trojan-activity;sid:84759644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b74843ad95bef0e9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896543/; classtype:trojan-activity;sid:84759643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896540/; classtype:trojan-activity;sid:84759640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896541/; classtype:trojan-activity;sid:84759641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efe1ca.sh"; depth:10; endswith; nocase; http.host; content:"87.120.196.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896539/; classtype:trojan-activity;sid:84759639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_e3935e16789d1c43.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896537/; classtype:trojan-activity;sid:84759637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//bot.x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896538/; classtype:trojan-activity;sid:84759638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896536/; classtype:trojan-activity;sid:84759636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896535/; classtype:trojan-activity;sid:84759635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896531/; classtype:trojan-activity;sid:84759631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896532/; classtype:trojan-activity;sid:84759632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i686"; depth:10; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896533/; classtype:trojan-activity;sid:84759633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896534/; classtype:trojan-activity;sid:84759634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/printspoofer64.exe"; depth:19; endswith; nocase; http.host; content:"217.217.97.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896530/; classtype:trojan-activity;sid:84759630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896529/; classtype:trojan-activity;sid:84759629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896527/; classtype:trojan-activity;sid:84759627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riscv64"; depth:8; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896528/; classtype:trojan-activity;sid:84759628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896516/; classtype:trojan-activity;sid:84759616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips64"; depth:7; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896517/; classtype:trojan-activity;sid:84759617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896518/; classtype:trojan-activity;sid:84759618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896519/; classtype:trojan-activity;sid:84759619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc64"; depth:6; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896520/; classtype:trojan-activity;sid:84759620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896521/; classtype:trojan-activity;sid:84759621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896522/; classtype:trojan-activity;sid:84759622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s390x"; depth:6; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896523/; classtype:trojan-activity;sid:84759623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896524/; classtype:trojan-activity;sid:84759624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896525/; classtype:trojan-activity;sid:84759625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"31.56.209.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896526/; classtype:trojan-activity;sid:84759626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896515/; classtype:trojan-activity;sid:84759615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mipsrouter"; depth:16; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896514/; classtype:trojan-activity;sid:84759614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/ppc"; depth:14; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896513/; classtype:trojan-activity;sid:84759613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/i686"; depth:15; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896509/; classtype:trojan-activity;sid:84759609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896510/; classtype:trojan-activity;sid:84759610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/mips"; depth:15; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896511/; classtype:trojan-activity;sid:84759611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896512/; classtype:trojan-activity;sid:84759612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896489/; classtype:trojan-activity;sid:84759589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i686"; depth:10; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896490/; classtype:trojan-activity;sid:84759590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896491/; classtype:trojan-activity;sid:84759591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896492/; classtype:trojan-activity;sid:84759592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896493/; classtype:trojan-activity;sid:84759593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896494/; classtype:trojan-activity;sid:84759594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/x86"; depth:14; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896495/; classtype:trojan-activity;sid:84759595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896496/; classtype:trojan-activity;sid:84759596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/x86_64"; depth:17; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896497/; classtype:trojan-activity;sid:84759597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/sh4"; depth:14; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896498/; classtype:trojan-activity;sid:84759598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896499/; classtype:trojan-activity;sid:84759599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/mpsl"; depth:15; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896500/; classtype:trojan-activity;sid:84759600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896501/; classtype:trojan-activity;sid:84759601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/arm7"; depth:15; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896502/; classtype:trojan-activity;sid:84759602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/arm6"; depth:15; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896503/; classtype:trojan-activity;sid:84759603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896504/; classtype:trojan-activity;sid:84759604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/arm4"; depth:15; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896505/; classtype:trojan-activity;sid:84759605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/m68k"; depth:15; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896506/; classtype:trojan-activity;sid:84759606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896507/; classtype:trojan-activity;sid:84759607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896508/; classtype:trojan-activity;sid:84759608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896488/; classtype:trojan-activity;sid:84759588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896486/; classtype:trojan-activity;sid:84759586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896487/; classtype:trojan-activity;sid:84759587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dbg"; depth:9; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896478/; classtype:trojan-activity;sid:84759578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/arm5"; depth:15; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896479/; classtype:trojan-activity;sid:84759579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896480/; classtype:trojan-activity;sid:84759580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896481/; classtype:trojan-activity;sid:84759581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896482/; classtype:trojan-activity;sid:84759582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896483/; classtype:trojan-activity;sid:84759583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896484/; classtype:trojan-activity;sid:84759584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896485/; classtype:trojan-activity;sid:84759585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm4"; depth:10; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896477/; classtype:trojan-activity;sid:84759577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896475/; classtype:trojan-activity;sid:84759575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dbg"; depth:4; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896476/; classtype:trojan-activity;sid:84759576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"176.65.148.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896474/; classtype:trojan-activity;sid:84759574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"176.65.148.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896472/; classtype:trojan-activity;sid:84759572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"176.65.148.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896473/; classtype:trojan-activity;sid:84759573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mimi.exe"; depth:9; endswith; nocase; http.host; content:"217.217.97.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896471/; classtype:trojan-activity;sid:84759571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tyler-v6.iso"; depth:13; endswith; nocase; http.host; content:"195.177.94.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896470/; classtype:trojan-activity;sid:84759570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shellc.bin"; depth:11; endswith; nocase; http.host; content:"195.177.94.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896469/; classtype:trojan-activity;sid:84759569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shell.jsp"; depth:10; endswith; nocase; http.host; content:"217.217.97.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896468/; classtype:trojan-activity;sid:84759568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v.exe"; depth:6; endswith; nocase; http.host; content:"217.217.97.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896467/; classtype:trojan-activity;sid:84759567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p.ps1"; depth:6; endswith; nocase; http.host; content:"217.217.97.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896466/; classtype:trojan-activity;sid:84759566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.11.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896465/; classtype:trojan-activity;sid:84759565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.11.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896464/; classtype:trojan-activity;sid:84759564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896463/; classtype:trojan-activity;sid:84759563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896457/; classtype:trojan-activity;sid:84759557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896458/; classtype:trojan-activity;sid:84759558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896459/; classtype:trojan-activity;sid:84759559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896460/; classtype:trojan-activity;sid:84759560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896461/; classtype:trojan-activity;sid:84759561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"220.158.234.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896462/; classtype:trojan-activity;sid:84759562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.203.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896456/; classtype:trojan-activity;sid:84759556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.38.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896455/; classtype:trojan-activity;sid:84759555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.156.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896454/; classtype:trojan-activity;sid:84759554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.48.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896453/; classtype:trojan-activity;sid:84759553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.115.229.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896452/; classtype:trojan-activity;sid:84759552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.50.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896451/; classtype:trojan-activity;sid:84759551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.64.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896450/; classtype:trojan-activity;sid:84759550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.38.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896449/; classtype:trojan-activity;sid:84759549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.48.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896448/; classtype:trojan-activity;sid:84759548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.168.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896447/; classtype:trojan-activity;sid:84759547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.177.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896446/; classtype:trojan-activity;sid:84759546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.52.29.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896445/; classtype:trojan-activity;sid:84759545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"94.244.36.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896444/; classtype:trojan-activity;sid:84759544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.177.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896443/; classtype:trojan-activity;sid:84759543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.131.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896442/; classtype:trojan-activity;sid:84759542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.168.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896441/; classtype:trojan-activity;sid:84759541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.52.29.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896440/; classtype:trojan-activity;sid:84759540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.40.245"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896439/; classtype:trojan-activity;sid:84759539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"94.244.36.34"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896438/; classtype:trojan-activity;sid:84759538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"216.126.86.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896437/; classtype:trojan-activity;sid:84759537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"216.126.86.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896436/; classtype:trojan-activity;sid:84759536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.75.168"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896435/; classtype:trojan-activity;sid:84759535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.120.89"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896434/; classtype:trojan-activity;sid:84759534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.207.114.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896433/; classtype:trojan-activity;sid:84759533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"31.129.3.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896432/; classtype:trojan-activity;sid:84759532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mips"; depth:10; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896431/; classtype:trojan-activity;sid:84759531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mipsel"; depth:12; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896430/; classtype:trojan-activity;sid:84759530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbc"; depth:4; endswith; nocase; http.host; content:"45.38.249.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896429/; classtype:trojan-activity;sid:84759529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.130.210.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896428/; classtype:trojan-activity;sid:84759528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.111.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896427/; classtype:trojan-activity;sid:84759527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.85.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896426/; classtype:trojan-activity;sid:84759526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.37.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896425/; classtype:trojan-activity;sid:84759525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.130.210.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896424/; classtype:trojan-activity;sid:84759524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.211.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896423/; classtype:trojan-activity;sid:84759523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.234.239.113"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896422/; classtype:trojan-activity;sid:84759522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.111.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896421/; classtype:trojan-activity;sid:84759521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.211.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896420/; classtype:trojan-activity;sid:84759520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.85.103"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896419/; classtype:trojan-activity;sid:84759519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.0.209"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896418/; classtype:trojan-activity;sid:84759518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896416/; classtype:trojan-activity;sid:84759516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896417/; classtype:trojan-activity;sid:84759517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896415/; classtype:trojan-activity;sid:84759515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896412/; classtype:trojan-activity;sid:84759512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i686"; depth:10; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896413/; classtype:trojan-activity;sid:84759513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896414/; classtype:trojan-activity;sid:84759514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896408/; classtype:trojan-activity;sid:84759508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896409/; classtype:trojan-activity;sid:84759509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896410/; classtype:trojan-activity;sid:84759510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c2"; depth:3; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896411/; classtype:trojan-activity;sid:84759511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.152.136"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896407/; classtype:trojan-activity;sid:84759507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896405/; classtype:trojan-activity;sid:84759505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896406/; classtype:trojan-activity;sid:84759506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c1"; depth:3; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896401/; classtype:trojan-activity;sid:84759501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896402/; classtype:trojan-activity;sid:84759502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896403/; classtype:trojan-activity;sid:84759503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dbg"; depth:9; endswith; nocase; http.host; content:"94.154.43.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896404/; classtype:trojan-activity;sid:84759504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896400/; classtype:trojan-activity;sid:84759500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896398/; classtype:trojan-activity;sid:84759498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c2"; depth:3; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896399/; classtype:trojan-activity;sid:84759499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c1"; depth:3; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896397/; classtype:trojan-activity;sid:84759497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/spc"; depth:9; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896396/; classtype:trojan-activity;sid:84759496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896395/; classtype:trojan-activity;sid:84759495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.234.239.113"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896393/; classtype:trojan-activity;sid:84759493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm"; depth:9; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896394/; classtype:trojan-activity;sid:84759494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/dbg"; depth:9; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896392/; classtype:trojan-activity;sid:84759492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/i686"; depth:10; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896391/; classtype:trojan-activity;sid:84759491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896388/; classtype:trojan-activity;sid:84759488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896389/; classtype:trojan-activity;sid:84759489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896390/; classtype:trojan-activity;sid:84759490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896387/; classtype:trojan-activity;sid:84759487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mpsl"; depth:10; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896384/; classtype:trojan-activity;sid:84759484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896385/; classtype:trojan-activity;sid:84759485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"193.233.82.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896386/; classtype:trojan-activity;sid:84759486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.164.115.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896383/; classtype:trojan-activity;sid:84759483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.187.30.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896382/; classtype:trojan-activity;sid:84759482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.58.176.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896381/; classtype:trojan-activity;sid:84759481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.58.176.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896380/; classtype:trojan-activity;sid:84759480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.187.30.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896379/; classtype:trojan-activity;sid:84759479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.195.146"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896378/; classtype:trojan-activity;sid:84759478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.125.24.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896377/; classtype:trojan-activity;sid:84759477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.125.24.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896376/; classtype:trojan-activity;sid:84759476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.3.13"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896375/; classtype:trojan-activity;sid:84759475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.74.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896374/; classtype:trojan-activity;sid:84759474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.226.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896373/; classtype:trojan-activity;sid:84759473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.255.4"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896372/; classtype:trojan-activity;sid:84759472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.226.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896371/; classtype:trojan-activity;sid:84759471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.140.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896370/; classtype:trojan-activity;sid:84759470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.140.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896369/; classtype:trojan-activity;sid:84759469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.159.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896368/; classtype:trojan-activity;sid:84759468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.18.81.147"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896367/; classtype:trojan-activity;sid:84759467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.203.62.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896366/; classtype:trojan-activity;sid:84759466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.106.136"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896365/; classtype:trojan-activity;sid:84759465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.81.147"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896364/; classtype:trojan-activity;sid:84759464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ww.adyen.comknowledge-hubpayment-gatewaymsclkid=0dcc9c9da58815369da2f6a715a7654d|7c|26|7c|utm_source=bing|7c|26|7c|utm_medium=cpc|7c|26|7c|utm_camiii.php"; depth:154; endswith; nocase; http.host; content:"107.172.235.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896363/; classtype:trojan-activity;sid:84759463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.89.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896362/; classtype:trojan-activity;sid:84759462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.205.208.217"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896361/; classtype:trojan-activity;sid:84759461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.156.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896360/; classtype:trojan-activity;sid:84759460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.18.100.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896359/; classtype:trojan-activity;sid:84759459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.229.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896358/; classtype:trojan-activity;sid:84759458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.spc"; depth:21; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896357/; classtype:trojan-activity;sid:84759457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.205.208.217"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896356/; classtype:trojan-activity;sid:84759456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.mpsl"; depth:22; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896355/; classtype:trojan-activity;sid:84759455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.x86"; depth:21; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896354/; classtype:trojan-activity;sid:84759454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.i686"; depth:22; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896345/; classtype:trojan-activity;sid:84759445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm"; depth:21; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896346/; classtype:trojan-activity;sid:84759446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm5"; depth:22; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896347/; classtype:trojan-activity;sid:84759447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lkxstress.sh"; depth:13; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896348/; classtype:trojan-activity;sid:84759448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.sh4"; depth:21; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896349/; classtype:trojan-activity;sid:84759449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm7"; depth:22; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896350/; classtype:trojan-activity;sid:84759450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.x86_64"; depth:24; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896351/; classtype:trojan-activity;sid:84759451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.mips"; depth:22; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896352/; classtype:trojan-activity;sid:84759452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.ppc"; depth:21; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896353/; classtype:trojan-activity;sid:84759453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.arm6"; depth:22; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896343/; classtype:trojan-activity;sid:84759443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xlumen/lkxstress.m68k"; depth:22; endswith; nocase; http.host; content:"204.10.194.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896344/; classtype:trojan-activity;sid:84759444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.100.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896342/; classtype:trojan-activity;sid:84759442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.55.213.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896341/; classtype:trojan-activity;sid:84759441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/70878efbc582"; depth:15; endswith; nocase; http.host; content:"kaiwyrey.eu.cc"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896340/; classtype:trojan-activity;sid:84759440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/ac516096c285"; depth:15; endswith; nocase; http.host; content:"kaiwyrey.eu.cc"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896339/; classtype:trojan-activity;sid:84759439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20260729074327.zip"; depth:19; endswith; nocase; http.host; content:"yfghrey-1433552157.cos.ap-hongkong.myqcloud.com"; depth:47; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896338/; classtype:trojan-activity;sid:84759438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20260729213603.zip"; depth:19; endswith; nocase; http.host; content:"tdfhdser-1433552157.cos.ap-hongkong.myqcloud.com"; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896337/; classtype:trojan-activity;sid:84759437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/6f025f85e3c0"; depth:15; endswith; nocase; http.host; content:"kaiwyrey.eu.cc"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896334/; classtype:trojan-activity;sid:84759434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/bdc9637e70c2"; depth:15; endswith; nocase; http.host; content:"kaiwyrey.eu.cc"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896335/; classtype:trojan-activity;sid:84759435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cl/rllxixswv8iks9awzyqx.gteiy.dfpltrpy013hmjghjiqnpzyu0.3grfdjuvkq6te_brewyxijycce5tvenoe3kbutwvcdtiu2bdhwxzs0x1w9uo0ivh.1qngrtx1fchw7ragf7rgebqpkgahtmo9pnvobfpz6zwewwmf.a8wcbwexrfhkajhlsixt2nztt0u74bljpjjsehoma6bax63e8owmzhpihcbw2sq~~--2ijbf9qxryunjzju--8oh.0r5jkh3jzkgt7hz3yq~~"; depth:280; endswith; nocase; http.host; content:"mt-link.qdhuzf.cc"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896336/; classtype:trojan-activity;sid:84759436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cl/a5uyfw_dao7l4uk02y5e3t4rkwwlaq7x5fxatyv8o3ujaut_k5ia0vibwvrxblxmngzek9whhahsqfobqqcupkzzinkihgmggocp1yiigbo6jupzwhm0ybf._jurp0lhkb4wt0m5h1gyc3ag149v2da397unky11uvn30sf8dgjjmiztmjs_ugzti_jqupelruzgnwj2gvsmsoq9_0idavjwlmubiwllphaogxqn4ckh--rczgx49rzqev4ixm--n6cy14rgi..inc2atg5k9g~~"; depth:284; endswith; nocase; http.host; content:"mt-link.qdhuzf.cc"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896333/; classtype:trojan-activity;sid:84759433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cl/1ti4_qy7dcebkeln5kmk9jrsozkvcgnqofof.bp_ka4knqy51he4r8irtwhlz2i_o_2nu1kmvvszh_zv7baowqdlryyzqpe8r_qsdciqel3f70u7skywz.3b98zvfhcxcdzmsyed7ruj5.hif56qvuda9tu0yyihnps9u9frmfrupufu4wnzg58wpv.jzgunkfksrvpkboquhgjkbiytgq_rfpm.1ldbjbc~--nucyngcfq.n1c.5q--k8navtprtztzg9ygwu3p8g~~"; depth:276; endswith; nocase; http.host; content:"mt-link.hxnxajp.club"; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896331/; classtype:trojan-activity;sid:84759431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cl/xytkjx7q1dal2bgntd9ws4rxd2jm6drs81i6p9oiabezdaou.hkbv4jowbgjmpug1r7lqfsw.yctlhgoryhj2sup3sfxpiv6xdccbg0rxrfrl7uhgfuoxto2my_is7qkqfe3qq9hi3lz8yxj6vnogu8mxreaxoa9fexd3dtakboplmzs2ywrhmscedns3nlzl3bu53l9rtzb6rmz2xwlslh_ypqfymfui0e7ac9xkg.c0r8~--qdlygjpqkgnky9es--_czsqbw_5cv2hhl6j7dr3w~~"; depth:288; endswith; nocase; http.host; content:"mt-link.jiosjcjp.club"; depth:21; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896332/; classtype:trojan-activity;sid:84759432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.85.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896330/; classtype:trojan-activity;sid:84759430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.110.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896329/; classtype:trojan-activity;sid:84759429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mips"; depth:23; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896328/; classtype:trojan-activity;sid:84759428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm5"; depth:23; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896321/; classtype:trojan-activity;sid:84759421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm6"; depth:23; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896322/; classtype:trojan-activity;sid:84759422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.spc"; depth:22; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896323/; classtype:trojan-activity;sid:84759423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.sh4"; depth:22; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896324/; classtype:trojan-activity;sid:84759424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arc"; depth:22; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896325/; classtype:trojan-activity;sid:84759425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mpsl"; depth:23; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896326/; classtype:trojan-activity;sid:84759426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86"; depth:22; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896327/; classtype:trojan-activity;sid:84759427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.ppc"; depth:22; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896319/; classtype:trojan-activity;sid:84759419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.m68k"; depth:23; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896320/; classtype:trojan-activity;sid:84759420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896318/; classtype:trojan-activity;sid:84759418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dropper.sh"; depth:11; endswith; nocase; http.host; content:"31.56.53.172"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896316/; classtype:trojan-activity;sid:84759416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lateral.sh"; depth:11; endswith; nocase; http.host; content:"31.56.53.172"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896317/; classtype:trojan-activity;sid:84759417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/840a26"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896314/; classtype:trojan-activity;sid:84759414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/62a003"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896315/; classtype:trojan-activity;sid:84759415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d98224"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896304/; classtype:trojan-activity;sid:84759404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7913a0"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896305/; classtype:trojan-activity;sid:84759405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4065fb"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896306/; classtype:trojan-activity;sid:84759406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8ae148"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896307/; classtype:trojan-activity;sid:84759407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c47fe3"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896308/; classtype:trojan-activity;sid:84759408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eb0d2c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896309/; classtype:trojan-activity;sid:84759409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/21dfaa"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896310/; classtype:trojan-activity;sid:84759410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0df871"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896311/; classtype:trojan-activity;sid:84759411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/04f878"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896312/; classtype:trojan-activity;sid:84759412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1b57b5"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896313/; classtype:trojan-activity;sid:84759413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gwpu"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896302/; classtype:trojan-activity;sid:84759402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12uj"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896303/; classtype:trojan-activity;sid:84759403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asc"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896299/; classtype:trojan-activity;sid:84759399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bl1"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896300/; classtype:trojan-activity;sid:84759400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1qy"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896301/; classtype:trojan-activity;sid:84759401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.188.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896298/; classtype:trojan-activity;sid:84759398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.93.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896297/; classtype:trojan-activity;sid:84759397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4072615b88cd97cd.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896296/; classtype:trojan-activity;sid:84759396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.0.130"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896295/; classtype:trojan-activity;sid:84759395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_efb288a237bc2863.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896294/; classtype:trojan-activity;sid:84759394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.93.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896293/; classtype:trojan-activity;sid:84759393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.168.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896292/; classtype:trojan-activity;sid:84759392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"31.129.3.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896291/; classtype:trojan-activity;sid:84759391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.168.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896290/; classtype:trojan-activity;sid:84759390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.45.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896289/; classtype:trojan-activity;sid:84759389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.50.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896288/; classtype:trojan-activity;sid:84759388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirai.x86_64"; depth:13; endswith; nocase; http.host; content:"147.45.69.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896287/; classtype:trojan-activity;sid:84759387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot"; depth:4; endswith; nocase; http.host; content:"45.207.157.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896286/; classtype:trojan-activity;sid:84759386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"c2.strikec2.wtf"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896283/; classtype:trojan-activity;sid:84759383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iot"; depth:4; endswith; nocase; http.host; content:"103.90.161.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896284/; classtype:trojan-activity;sid:84759384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da"; depth:3; endswith; nocase; http.host; content:"213.139.77.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896285/; classtype:trojan-activity;sid:84759385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.44.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896282/; classtype:trojan-activity;sid:84759382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test.sh"; depth:8; endswith; nocase; http.host; content:"77.0.42.76"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896281/; classtype:trojan-activity;sid:84759381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w3.sh"; depth:6; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896279/; classtype:trojan-activity;sid:84759379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/okf"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896264/; classtype:trojan-activity;sid:84759364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bll"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896265/; classtype:trojan-activity;sid:84759365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/549"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896266/; classtype:trojan-activity;sid:84759366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtj"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896267/; classtype:trojan-activity;sid:84759367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z3ev"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896268/; classtype:trojan-activity;sid:84759368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gmz"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896269/; classtype:trojan-activity;sid:84759369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o9u"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896270/; classtype:trojan-activity;sid:84759370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e3f"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896271/; classtype:trojan-activity;sid:84759371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cufu"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896272/; classtype:trojan-activity;sid:84759372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qpr"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896273/; classtype:trojan-activity;sid:84759373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5cfo"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896274/; classtype:trojan-activity;sid:84759374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w7zd"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896275/; classtype:trojan-activity;sid:84759375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jzyv"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896276/; classtype:trojan-activity;sid:84759376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mkno"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896277/; classtype:trojan-activity;sid:84759377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qjn"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896278/; classtype:trojan-activity;sid:84759378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.44.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896263/; classtype:trojan-activity;sid:84759363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.142.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896262/; classtype:trojan-activity;sid:84759362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_934c72e242692247.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896261/; classtype:trojan-activity;sid:84759361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.85.99.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896260/; classtype:trojan-activity;sid:84759360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1092093/crypted.ps1"; depth:20; endswith; nocase; http.host; content:"213.165.78.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896259/; classtype:trojan-activity;sid:84759359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60/document_picture_0994950005995.jpg/verygoodthingsarecomingentiretimeforbest.hta"; depth:83; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896258/; classtype:trojan-activity;sid:84759358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60/goodthingsarebestformehappeninggood.vbe"; depth:43; endswith; nocase; http.host; content:"217.154.188.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896257/; classtype:trojan-activity;sid:84759357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.142.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896256/; classtype:trojan-activity;sid:84759356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.127.202"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896255/; classtype:trojan-activity;sid:84759355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.206.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896254/; classtype:trojan-activity;sid:84759354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.68.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896253/; classtype:trojan-activity;sid:84759353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_18fb177cfd368a59.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896250/; classtype:trojan-activity;sid:84759350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5b5f34227ffcdc5a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896251/; classtype:trojan-activity;sid:84759351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_662bb93ff2f209d8.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896252/; classtype:trojan-activity;sid:84759352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.113.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896249/; classtype:trojan-activity;sid:84759349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.206.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896248/; classtype:trojan-activity;sid:84759348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.73.232.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896247/; classtype:trojan-activity;sid:84759347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.252.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896246/; classtype:trojan-activity;sid:84759346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.209.65.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896245/; classtype:trojan-activity;sid:84759345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.29.22.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896244/; classtype:trojan-activity;sid:84759344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.88.7.48"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896243/; classtype:trojan-activity;sid:84759343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.73.232.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896242/; classtype:trojan-activity;sid:84759342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.249.77.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896241/; classtype:trojan-activity;sid:84759341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.252.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896240/; classtype:trojan-activity;sid:84759340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.29.22.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896239/; classtype:trojan-activity;sid:84759339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.209.65.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896238/; classtype:trojan-activity;sid:84759338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.206.197.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896237/; classtype:trojan-activity;sid:84759337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.160.188.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896236/; classtype:trojan-activity;sid:84759336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.198.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896235/; classtype:trojan-activity;sid:84759335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.204.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896234/; classtype:trojan-activity;sid:84759334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.204.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896233/; classtype:trojan-activity;sid:84759333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.160.188.158"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896232/; classtype:trojan-activity;sid:84759332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.86.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896231/; classtype:trojan-activity;sid:84759331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.114.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896230/; classtype:trojan-activity;sid:84759330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"204.116.34.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896229/; classtype:trojan-activity;sid:84759329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.41.54"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896228/; classtype:trojan-activity;sid:84759328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.89.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896223/; classtype:trojan-activity;sid:84759323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.212.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896224/; classtype:trojan-activity;sid:84759324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.95.220.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896225/; classtype:trojan-activity;sid:84759325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.85.99.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896226/; classtype:trojan-activity;sid:84759326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.177.33.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896227/; classtype:trojan-activity;sid:84759327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.236.150.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896203/; classtype:trojan-activity;sid:84759303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.142.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896204/; classtype:trojan-activity;sid:84759304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.49.184"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896205/; classtype:trojan-activity;sid:84759305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.23.201.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896206/; classtype:trojan-activity;sid:84759306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.148.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896207/; classtype:trojan-activity;sid:84759307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.52.141.118"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896208/; classtype:trojan-activity;sid:84759308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.14.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896209/; classtype:trojan-activity;sid:84759309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.240.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896210/; classtype:trojan-activity;sid:84759310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.206.197.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896211/; classtype:trojan-activity;sid:84759311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"106.110.208.117"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896212/; classtype:trojan-activity;sid:84759312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.227.205"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896213/; classtype:trojan-activity;sid:84759313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.86.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896214/; classtype:trojan-activity;sid:84759314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.86.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896215/; classtype:trojan-activity;sid:84759315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"79.106.74.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896216/; classtype:trojan-activity;sid:84759316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"190.109.227.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896217/; classtype:trojan-activity;sid:84759317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.37.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896218/; classtype:trojan-activity;sid:84759318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.73.120.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896219/; classtype:trojan-activity;sid:84759319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.137.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896220/; classtype:trojan-activity;sid:84759320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.93.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896221/; classtype:trojan-activity;sid:84759321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.89.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896222/; classtype:trojan-activity;sid:84759322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.134.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896199/; classtype:trojan-activity;sid:84759299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.76.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896200/; classtype:trojan-activity;sid:84759300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.215.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896201/; classtype:trojan-activity;sid:84759301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.93.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896202/; classtype:trojan-activity;sid:84759302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.52.156.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896194/; classtype:trojan-activity;sid:84759294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.134.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896195/; classtype:trojan-activity;sid:84759295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.55.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896196/; classtype:trojan-activity;sid:84759296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.38.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896197/; classtype:trojan-activity;sid:84759297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.100.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896198/; classtype:trojan-activity;sid:84759298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.177.33.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896191/; classtype:trojan-activity;sid:84759291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.14.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896192/; classtype:trojan-activity;sid:84759292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.127.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896193/; classtype:trojan-activity;sid:84759293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.86.96.126"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896182/; classtype:trojan-activity;sid:84759282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.234.174"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896183/; classtype:trojan-activity;sid:84759283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.142.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896184/; classtype:trojan-activity;sid:84759284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.3.13"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896185/; classtype:trojan-activity;sid:84759285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.10.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896186/; classtype:trojan-activity;sid:84759286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.57.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896187/; classtype:trojan-activity;sid:84759287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.38.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896188/; classtype:trojan-activity;sid:84759288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.57.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896189/; classtype:trojan-activity;sid:84759289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.247.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896190/; classtype:trojan-activity;sid:84759290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.188.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896164/; classtype:trojan-activity;sid:84759264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.76.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896165/; classtype:trojan-activity;sid:84759265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.230.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896166/; classtype:trojan-activity;sid:84759266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.219.74.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896167/; classtype:trojan-activity;sid:84759267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.177.161.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896168/; classtype:trojan-activity;sid:84759268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.218.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896169/; classtype:trojan-activity;sid:84759269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.148.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896170/; classtype:trojan-activity;sid:84759270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.88.248.179"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896171/; classtype:trojan-activity;sid:84759271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.211.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896172/; classtype:trojan-activity;sid:84759272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.181.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896173/; classtype:trojan-activity;sid:84759273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.211.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896174/; classtype:trojan-activity;sid:84759274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"82.114.178.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896175/; classtype:trojan-activity;sid:84759275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"180.243.251.152"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896176/; classtype:trojan-activity;sid:84759276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.60.21"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896177/; classtype:trojan-activity;sid:84759277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.45.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896178/; classtype:trojan-activity;sid:84759278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.176.122.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896179/; classtype:trojan-activity;sid:84759279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.35.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896180/; classtype:trojan-activity;sid:84759280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.93.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896181/; classtype:trojan-activity;sid:84759281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.190.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896161/; classtype:trojan-activity;sid:84759261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.74.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896162/; classtype:trojan-activity;sid:84759262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.178.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896163/; classtype:trojan-activity;sid:84759263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896159/; classtype:trojan-activity;sid:84759259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.177.161.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896160/; classtype:trojan-activity;sid:84759260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.92.89.190"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896147/; classtype:trojan-activity;sid:84759247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.229.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896148/; classtype:trojan-activity;sid:84759248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.37.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896149/; classtype:trojan-activity;sid:84759249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.linux_amd64"; depth:16; endswith; nocase; http.host; content:"147.45.69.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896150/; classtype:trojan-activity;sid:84759250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.251.43"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896151/; classtype:trojan-activity;sid:84759251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.35.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896152/; classtype:trojan-activity;sid:84759252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.85.98"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896153/; classtype:trojan-activity;sid:84759253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.29.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896154/; classtype:trojan-activity;sid:84759254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.76.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896155/; classtype:trojan-activity;sid:84759255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.238.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896156/; classtype:trojan-activity;sid:84759256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.244.182"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896157/; classtype:trojan-activity;sid:84759257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.181.221"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896158/; classtype:trojan-activity;sid:84759258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.146.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896131/; classtype:trojan-activity;sid:84759231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.59.227.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896132/; classtype:trojan-activity;sid:84759232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.202.77.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896133/; classtype:trojan-activity;sid:84759233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.176.248.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896134/; classtype:trojan-activity;sid:84759234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.79.136"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896135/; classtype:trojan-activity;sid:84759235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.57.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896136/; classtype:trojan-activity;sid:84759236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.177.33.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896137/; classtype:trojan-activity;sid:84759237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.253.159"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896138/; classtype:trojan-activity;sid:84759238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"82.114.178.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896139/; classtype:trojan-activity;sid:84759239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"77.79.160.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896140/; classtype:trojan-activity;sid:84759240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.52.141.118"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896141/; classtype:trojan-activity;sid:84759241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.232.123"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896142/; classtype:trojan-activity;sid:84759242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.109.227.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896143/; classtype:trojan-activity;sid:84759243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.57.251"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896144/; classtype:trojan-activity;sid:84759244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.247.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896145/; classtype:trojan-activity;sid:84759245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.238.126"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896146/; classtype:trojan-activity;sid:84759246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.236.150.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896129/; classtype:trojan-activity;sid:84759229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.113.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896130/; classtype:trojan-activity;sid:84759230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.177.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896127/; classtype:trojan-activity;sid:84759227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.35.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896128/; classtype:trojan-activity;sid:84759228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.138.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896111/; classtype:trojan-activity;sid:84759211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.188.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896112/; classtype:trojan-activity;sid:84759212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"161.8.195.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896113/; classtype:trojan-activity;sid:84759213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"106.110.208.117"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896114/; classtype:trojan-activity;sid:84759214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.57.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896115/; classtype:trojan-activity;sid:84759215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.171.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896116/; classtype:trojan-activity;sid:84759216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.218.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896117/; classtype:trojan-activity;sid:84759217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.86.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896118/; classtype:trojan-activity;sid:84759218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.138.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896119/; classtype:trojan-activity;sid:84759219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.129.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896120/; classtype:trojan-activity;sid:84759220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.23.78.208"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896121/; classtype:trojan-activity;sid:84759221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.230.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896122/; classtype:trojan-activity;sid:84759222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.47.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896123/; classtype:trojan-activity;sid:84759223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.190.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896124/; classtype:trojan-activity;sid:84759224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.243.172.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896125/; classtype:trojan-activity;sid:84759225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.148.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896126/; classtype:trojan-activity;sid:84759226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.86.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896096/; classtype:trojan-activity;sid:84759196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.59.227.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896097/; classtype:trojan-activity;sid:84759197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.253.159"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896098/; classtype:trojan-activity;sid:84759198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.87.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896099/; classtype:trojan-activity;sid:84759199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.255.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896100/; classtype:trojan-activity;sid:84759200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.79.160.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896101/; classtype:trojan-activity;sid:84759201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.58.142.224"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896102/; classtype:trojan-activity;sid:84759202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.158.139"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896103/; classtype:trojan-activity;sid:84759203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.32.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896104/; classtype:trojan-activity;sid:84759204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.186.204.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896105/; classtype:trojan-activity;sid:84759205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.151.74.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896106/; classtype:trojan-activity;sid:84759206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.149.90.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896107/; classtype:trojan-activity;sid:84759207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.134.162.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896108/; classtype:trojan-activity;sid:84759208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.201.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896109/; classtype:trojan-activity;sid:84759209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.255.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896110/; classtype:trojan-activity;sid:84759210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"79.106.74.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896095/; classtype:trojan-activity;sid:84759195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/duba"; depth:5; endswith; nocase; http.host; content:"213.139.77.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896094/; classtype:trojan-activity;sid:84759194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.54.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896093/; classtype:trojan-activity;sid:84759193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/de6ae97040d70645/doc-c48ttx.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896092/; classtype:trojan-activity;sid:84759192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.86.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896089/; classtype:trojan-activity;sid:84759189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/2ee833cf831a2e12/doc-sjdpwm.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896090/; classtype:trojan-activity;sid:84759190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/ff9f445b71d0b3da/doc-p45l2e.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896091/; classtype:trojan-activity;sid:84759191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/ad2983a808f2a9bf/doc-3lp3sb.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896085/; classtype:trojan-activity;sid:84759185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/6bfeadb34cbedd3e/doc-ynu42x.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896086/; classtype:trojan-activity;sid:84759186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/bd928354771474af/doc-cqzs5j.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896087/; classtype:trojan-activity;sid:84759187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/012a0ac6cea53ce6/a3asesor-0ajjh5.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896088/; classtype:trojan-activity;sid:84759188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.212.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896084/; classtype:trojan-activity;sid:84759184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.160.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896083/; classtype:trojan-activity;sid:84759183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/106c8bac09338256/a3asesor-rt3wit.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896082/; classtype:trojan-activity;sid:84759182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/7d1a154e9ff17961/doc-h20m3h.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896064/; classtype:trojan-activity;sid:84759164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/8a96f01cd3ec30d7/a3asesor-4q6jlh.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896065/; classtype:trojan-activity;sid:84759165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/6f7d3f22f135f9d9/a3asesor-xwgkqg.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896066/; classtype:trojan-activity;sid:84759166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/964fe86d097a3943/cegidprimavera-l6ls9z.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896067/; classtype:trojan-activity;sid:84759167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/d121198256b48b89/doc-vn70yb.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896068/; classtype:trojan-activity;sid:84759168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/a926caa190b0fb45/a3asesor-xj2xjq.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896069/; classtype:trojan-activity;sid:84759169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/85f0ab4910d9bbf8/a3asesor-lz8zjs.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896070/; classtype:trojan-activity;sid:84759170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/15fc190a8866d70a/cegidprimavera-npvued.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896071/; classtype:trojan-activity;sid:84759171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/9269770e87da1062/a3asesor-ez5jnn.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896072/; classtype:trojan-activity;sid:84759172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/93b88b152a864318/a3asesor-kdeyla.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896073/; classtype:trojan-activity;sid:84759173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/4d4ef3bb42146443/a3asesor-e0mus8.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896074/; classtype:trojan-activity;sid:84759174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/783fdf63b7bcbb83/doc-b3qw6k.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896075/; classtype:trojan-activity;sid:84759175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/1c6dd7a5c8acb43d/doc-86emcl.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896076/; classtype:trojan-activity;sid:84759176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/45043870efc2fe50/a3asesor-7fj5gj.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896077/; classtype:trojan-activity;sid:84759177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/ab03c500914c9e8e/doc-eu6mqg.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896078/; classtype:trojan-activity;sid:84759178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/671c89790e112d73/doc-crdz7j.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896079/; classtype:trojan-activity;sid:84759179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/250c9ea0c1bb5720/doc-2g1qx4.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896080/; classtype:trojan-activity;sid:84759180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/1821139060fb51a5/a3asesor-j88kia.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896081/; classtype:trojan-activity;sid:84759181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b7033c78cb98bdaa/a3asesor-5duie9.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896060/; classtype:trojan-activity;sid:84759160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/536480423e2e0af5/cegidprimavera-0kx6je.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896061/; classtype:trojan-activity;sid:84759161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b395a4f299bcb26c/a3asesor-jmzkn2.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896062/; classtype:trojan-activity;sid:84759162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/7aade6df83f7bcde/a3asesor-wzw54v.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896063/; classtype:trojan-activity;sid:84759163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/29924f9344fe145f/a3asesor-nsv3do.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896053/; classtype:trojan-activity;sid:84759153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/41ea2f9594451db9/a3asesor-36i6au.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896054/; classtype:trojan-activity;sid:84759154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/020aecbc1be6b536/doc-dqgyoc.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896055/; classtype:trojan-activity;sid:84759155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/ba99dcc4511ffcf2/doc-lsg798.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896056/; classtype:trojan-activity;sid:84759156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/7406de35e923c48a/cegidprimavera-85yqfn.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896057/; classtype:trojan-activity;sid:84759157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/a68a9f0fae1352df/a3asesor-q0xhxw.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896058/; classtype:trojan-activity;sid:84759158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/726d7d7709fa7c5d/a3asesor-kw4zlq.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896059/; classtype:trojan-activity;sid:84759159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/7953d313cce72c14/a3asesor-kvex26.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896050/; classtype:trojan-activity;sid:84759150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/9e8d797798cf7173/a3asesor-yv7474.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896051/; classtype:trojan-activity;sid:84759151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/847aa2af581192b0/doc-mpyknu.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896052/; classtype:trojan-activity;sid:84759152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/24b4201f1f77d59c/a3asesor-0zc65m.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896048/; classtype:trojan-activity;sid:84759148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b8373b58a32fe94b/a3asesor-9sazbm.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896049/; classtype:trojan-activity;sid:84759149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/72f8b3e7821f6323/doc-9x5xj8.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896046/; classtype:trojan-activity;sid:84759146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/73a696c15ff75a87/a3asesor-ljccdu.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896047/; classtype:trojan-activity;sid:84759147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/2d016bbb087a992b/doc-iv6rji.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896042/; classtype:trojan-activity;sid:84759142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/6ccc976bde4687cb/doc-e8wzem.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896043/; classtype:trojan-activity;sid:84759143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/7e15e440cb700a28/doc-vbr6cn.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896044/; classtype:trojan-activity;sid:84759144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/13fdccffb36cf04d/doc-a7kj1d.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896045/; classtype:trojan-activity;sid:84759145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/f7c3f5b852d41179/doc-4owg8u.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896039/; classtype:trojan-activity;sid:84759139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/957990a7ce5223f5/doc-rcxbuq.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896040/; classtype:trojan-activity;sid:84759140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b7b7e398e14186ac/cegidprimavera-411vzm.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896041/; classtype:trojan-activity;sid:84759141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/aaf4653c452fde83/a3asesor-ep3dp4.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896034/; classtype:trojan-activity;sid:84759134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/82265bbe160078c3/doc-p2pv5t.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896035/; classtype:trojan-activity;sid:84759135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/db6d55236b8256d4/doc-v20s1s.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896036/; classtype:trojan-activity;sid:84759136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/b3f7003091a6c133/doc-3n7hvp.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896037/; classtype:trojan-activity;sid:84759137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/4bc491ad4422cbf5/a3asesor-opwpot.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896038/; classtype:trojan-activity;sid:84759138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/41bd33078d507a5c/doc-o0afq8.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896024/; classtype:trojan-activity;sid:84759124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/f28f88c1306b1de7/doc-6g8761.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896025/; classtype:trojan-activity;sid:84759125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/9a38964318a3b733/cegidprimavera-4wxo4d.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896026/; classtype:trojan-activity;sid:84759126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/7667e38f3e501b67/a3asesor-3lhjy2.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896027/; classtype:trojan-activity;sid:84759127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/2d16fadd4fc633fc/a3asesor-g20iyi.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896028/; classtype:trojan-activity;sid:84759128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/9f8eb49b4b7ea088/a3asesor-0g02vo.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896029/; classtype:trojan-activity;sid:84759129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/10951a53a13839aa/a3asesor-naojzq.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896030/; classtype:trojan-activity;sid:84759130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/b556be871d7a36fb/doc-dvjz7m.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896031/; classtype:trojan-activity;sid:84759131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/2376c74a556f6c2f/doc-b8p5pf.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896032/; classtype:trojan-activity;sid:84759132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/4224f2fb458e2402/a3asesor-3rztj8.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896033/; classtype:trojan-activity;sid:84759133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/05a2ae1ad0bdaa17/a3asesor-zeg74f.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896017/; classtype:trojan-activity;sid:84759117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/91418e59d0136ce5/a3asesor-i6velq.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896018/; classtype:trojan-activity;sid:84759118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/c8d18064de526c4c/doc-94xxeq.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896019/; classtype:trojan-activity;sid:84759119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/1abe3434b2650a4d/cegidprimavera-o34xlq.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896020/; classtype:trojan-activity;sid:84759120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b559ee8b5b9f77b9/a3asesor-funw7u.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896021/; classtype:trojan-activity;sid:84759121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/2a29bad26afdc5c6/a3asesor-yqf8nj.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896022/; classtype:trojan-activity;sid:84759122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/4b51d93146a4c248/doc-rseoie.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896023/; classtype:trojan-activity;sid:84759123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/bdfd88ce5d020953/doc-kjgd80.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896014/; classtype:trojan-activity;sid:84759114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/a93e29c464f3f857/a3asesor-sdwskl.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896015/; classtype:trojan-activity;sid:84759115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/adaab8299c77cfcb/a3asesor-7968b8.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896016/; classtype:trojan-activity;sid:84759116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/a20c45947f63b389/a3asesor-2j6mcv.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896013/; classtype:trojan-activity;sid:84759113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b61ed13bb351fa76/a3asesor-qdghzu.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896011/; classtype:trojan-activity;sid:84759111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/3a2afa2bdee7f562/cegidprimavera-8kajlc.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896012/; classtype:trojan-activity;sid:84759112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/a900a70bad1150f4/a3asesor-ay5ah4.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896006/; classtype:trojan-activity;sid:84759106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/65687d2153381e90/a3asesor-wr695q.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896007/; classtype:trojan-activity;sid:84759107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/3d80288a4492d4e4/doc-6pya49.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896008/; classtype:trojan-activity;sid:84759108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/81737cacf7e74c42/doc-66yexh.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896009/; classtype:trojan-activity;sid:84759109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/23f4721b3f98b47f/doc-tvul19.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896010/; classtype:trojan-activity;sid:84759110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/d74b41b667692d79/doc-b332xz.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896004/; classtype:trojan-activity;sid:84759104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/2027dd24f3ce47a3/a3asesor-b4wyyd.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896005/; classtype:trojan-activity;sid:84759105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/529c494c385a2106/doc-le6bur.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896000/; classtype:trojan-activity;sid:84759100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/79690dc1cb6a47ef/doc-ug78ew.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896001/; classtype:trojan-activity;sid:84759101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/698dc160ef718f69/doc-5vcfnn.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896002/; classtype:trojan-activity;sid:84759102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/fcd598f9c282fd5b/doc-381m5x.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896003/; classtype:trojan-activity;sid:84759103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/90c21c022542be7c/doc-5v43cl.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895996/; classtype:trojan-activity;sid:84759096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/94a3212f66204376/doc-jcgbt0.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895997/; classtype:trojan-activity;sid:84759097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/2b673cedcdd82496/doc-8fmghx.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895998/; classtype:trojan-activity;sid:84759098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/2a76a33414cf058f/a3asesor-y73g2s.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895999/; classtype:trojan-activity;sid:84759099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/af1fb13fad1352c1/doc-wtussl.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895983/; classtype:trojan-activity;sid:84759083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/f8ae57262c6c5102/doc-yxrhq1.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895984/; classtype:trojan-activity;sid:84759084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/73981155b6f64c78/a3asesor-498cwd.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895985/; classtype:trojan-activity;sid:84759085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/414bd9bc12930697/a3asesor-9h02ge.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895986/; classtype:trojan-activity;sid:84759086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/11514ad6f7fda402/doc-st8nx5.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895987/; classtype:trojan-activity;sid:84759087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/89ac650116208a39/a3asesor-a21y17.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895988/; classtype:trojan-activity;sid:84759088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/5e2944e86be72f87/a3asesor-ggepnv.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895989/; classtype:trojan-activity;sid:84759089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/28a04e3c89edf55e/cegidprimavera-m2y659.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895990/; classtype:trojan-activity;sid:84759090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/635b6e6896cd671d/a3asesor-q1bxzr.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895991/; classtype:trojan-activity;sid:84759091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/5b75e86206b0e32e/cegidprimavera-o3wq8e.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895992/; classtype:trojan-activity;sid:84759092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/208d4a9ba65edac8/doc-frhdy9.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895993/; classtype:trojan-activity;sid:84759093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/53d79904ceb51ab8/doc-4batis.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895994/; classtype:trojan-activity;sid:84759094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/765e1cceaea464f7/a3asesor-gzat1h.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895995/; classtype:trojan-activity;sid:84759095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/64641b223b8259ae/a3asesor-h9yeg2.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895977/; classtype:trojan-activity;sid:84759077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/e766d77611cb2bbe/doc-3106pf.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895978/; classtype:trojan-activity;sid:84759078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/a0e9e5ea77605736/cegidprimavera-5xryi0.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895979/; classtype:trojan-activity;sid:84759079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/3956b4b09ab795dc/doc-yfebs0.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895980/; classtype:trojan-activity;sid:84759080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/b47b61a9ffa8778a/doc-td1om4.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895981/; classtype:trojan-activity;sid:84759081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/63ffc6e3be027808/a3asesor-fl32f5.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895982/; classtype:trojan-activity;sid:84759082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/3458391a069a7005/a3asesor-a7ptd2.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895975/; classtype:trojan-activity;sid:84759075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/359bea161e3e1933/doc-ixhipj.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895976/; classtype:trojan-activity;sid:84759076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/48e57af635643b6e/doc-o9qwn7.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895972/; classtype:trojan-activity;sid:84759072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/4041bc1b8ca04bda/cegidprimavera-5n2tr9.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895973/; classtype:trojan-activity;sid:84759073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/1e597b1b3e102c65/a3asesor-wmvp0q.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895974/; classtype:trojan-activity;sid:84759074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/3eb5d6a896a94c3e/doc-z1wo3p.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895969/; classtype:trojan-activity;sid:84759069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/fcd598f9c282fd5b/doc-37aj3g.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895970/; classtype:trojan-activity;sid:84759070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b5265186044113a4/cegidprimavera-8z8ays.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895971/; classtype:trojan-activity;sid:84759071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/4cbc4e10172a7197/a3asesor-fh534z.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895966/; classtype:trojan-activity;sid:84759066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/5faac36698745ef4/a3asesor-ygjx5c.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895967/; classtype:trojan-activity;sid:84759067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/40a771f3881d8e8b/doc-1l1vxv.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895968/; classtype:trojan-activity;sid:84759068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/56f8b005c1a7f9f3/a3asesor-4io5vc.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895960/; classtype:trojan-activity;sid:84759060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/af39e277feec0f9f/a3asesor-ghpi27.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895961/; classtype:trojan-activity;sid:84759061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/987f8d00cd43f240/a3asesor-62cuor.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895962/; classtype:trojan-activity;sid:84759062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/c5a9538bb01132eb/doc-y6p3rh.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895963/; classtype:trojan-activity;sid:84759063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b22e821f152bdfa2/a3asesor-j74qst.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895964/; classtype:trojan-activity;sid:84759064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/3869a4aa32585ccb/a3asesor-cr2ld4.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895965/; classtype:trojan-activity;sid:84759065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/876a601e72c4d534/a3asesor-zy28gi.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895955/; classtype:trojan-activity;sid:84759055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/0be2ef93996c4161/a3asesor-m59vrr.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895956/; classtype:trojan-activity;sid:84759056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/8ed93bb7e1a712b8/a3asesor-iyzfma.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895957/; classtype:trojan-activity;sid:84759057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/4c07881c8f1d64c9/a3asesor-8yo16s.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895958/; classtype:trojan-activity;sid:84759058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/0217c99c22c33f8a/a3asesor-709vs0.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895959/; classtype:trojan-activity;sid:84759059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/04e8d68f244eef0e/a3asesor-ay2bba.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895941/; classtype:trojan-activity;sid:84759041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b2194bb5e45a7b83/a3asesor-zmwes2.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895942/; classtype:trojan-activity;sid:84759042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/344cb24e208770da/cegidprimavera-wpnqml.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895943/; classtype:trojan-activity;sid:84759043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/fcd598f9c282fd5b/doc-ipu3gc.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895944/; classtype:trojan-activity;sid:84759044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/6c746cb660195722/a3asesor-dzl7kt.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895945/; classtype:trojan-activity;sid:84759045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/e9939e24587dabfd/doc-3hugmd.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895946/; classtype:trojan-activity;sid:84759046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/7474a9ed00e94839/doc-hds6sb.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895947/; classtype:trojan-activity;sid:84759047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/c6a32135fc1a7da1/doc-zc9k6h.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895948/; classtype:trojan-activity;sid:84759048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/822b1ca98fe0286d/a3asesor-8matbr.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895949/; classtype:trojan-activity;sid:84759049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/fcd598f9c282fd5b/doc-o0dyef.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895950/; classtype:trojan-activity;sid:84759050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/a00d65b6420920a3/a3asesor-v8oge0.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895951/; classtype:trojan-activity;sid:84759051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/be8ed8ae9d798cca/cegidprimavera-ihspvt.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895952/; classtype:trojan-activity;sid:84759052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/5bb44fbe56106539/cegidprimavera-5fwnuj.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895953/; classtype:trojan-activity;sid:84759053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/2b510b33f652ea9b/a3asesor-7yp02w.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895954/; classtype:trojan-activity;sid:84759054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/38eb628df7601ae7/a3asesor-f4pdqb.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895936/; classtype:trojan-activity;sid:84759036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/23e84af68c424ddb/cegidprimavera-o86sd9.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895937/; classtype:trojan-activity;sid:84759037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/49270289234657b9/a3asesor-2chopi.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895938/; classtype:trojan-activity;sid:84759038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/f37424d50368388d/a3asesor-nb3x4b.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895939/; classtype:trojan-activity;sid:84759039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/6bd0fe97cc940e5e/a3asesor-9cr0cy.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895940/; classtype:trojan-activity;sid:84759040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/8514fd016bbc75f3/a3asesor-3y29r7.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895934/; classtype:trojan-activity;sid:84759034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b47c35fa72c99654/a3asesor-ze24ug.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895935/; classtype:trojan-activity;sid:84759035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/cce4bc0c73c324d0/doc-b2fr9t.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895932/; classtype:trojan-activity;sid:84759032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/5a3e730b4717652d/a3asesor-kics9e.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895933/; classtype:trojan-activity;sid:84759033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/554fe1e3f841c963/a3asesor-1yt6rd.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895931/; classtype:trojan-activity;sid:84759031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/223c2b8701a6c1a9/doc-lcwy6b.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895930/; classtype:trojan-activity;sid:84759030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/ac0709b5fe8cb676/cegidprimavera-40p15h.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895924/; classtype:trojan-activity;sid:84759024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/f51518729a122262/doc-l52aia.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895925/; classtype:trojan-activity;sid:84759025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/58e786dc84ac6ce4/a3asesor-mvmpsz.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895926/; classtype:trojan-activity;sid:84759026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/72b70a5a6b9361af/a3asesor-rv0soa.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895927/; classtype:trojan-activity;sid:84759027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/8c85593948f32cfd/a3asesor-4ag5hh.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895928/; classtype:trojan-activity;sid:84759028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/c947868e94387ecb/doc-6yzdny.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895929/; classtype:trojan-activity;sid:84759029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/91c2afb9e42a8056/a3asesor-x2v1kp.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895908/; classtype:trojan-activity;sid:84759008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/034eefa11b149c96/cegidprimavera-1if3mn.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895909/; classtype:trojan-activity;sid:84759009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/44b125cc6227c51e/a3asesor-8psvvd.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895910/; classtype:trojan-activity;sid:84759010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/2a09aa1834a94203/a3asesor-7rwaf9.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895911/; classtype:trojan-activity;sid:84759011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/bb20c34642e7b6a0/a3asesor-bkzy46.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895912/; classtype:trojan-activity;sid:84759012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/27494dcdccfe6d48/a3asesor-zmle3a.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895913/; classtype:trojan-activity;sid:84759013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/d5b6fbd4d594321f/doc-v03ok6.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895914/; classtype:trojan-activity;sid:84759014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/58af89f2ed3c842f/doc-ffe2bj.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895915/; classtype:trojan-activity;sid:84759015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/11c629f58976c699/a3asesor-cm4tpw.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895916/; classtype:trojan-activity;sid:84759016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/03bb18fd3d82295e/doc-dnacae.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895917/; classtype:trojan-activity;sid:84759017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/7d960ca54092ff0a/a3asesor-jx9pr2.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895918/; classtype:trojan-activity;sid:84759018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/0ac8a60f35f92da8/doc-c7tpxw.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895919/; classtype:trojan-activity;sid:84759019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/58e786dc84ac6ce4/a3asesor-syhote.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895920/; classtype:trojan-activity;sid:84759020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/84b052833668e069/cegidprimavera-4hlh7e.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895921/; classtype:trojan-activity;sid:84759021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/73a64c0013f795aa/a3asesor-1igfr9.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895922/; classtype:trojan-activity;sid:84759022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/63efadd8c6fe2b07/a3asesor-ggvw32.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895923/; classtype:trojan-activity;sid:84759023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/08519b97beb1ce6e/a3asesor-dqz4wq.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895898/; classtype:trojan-activity;sid:84758998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/371b097cbaf5be58/a3asesor-vwj4b4.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895899/; classtype:trojan-activity;sid:84758999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/8a1736b5f705d776/a3asesor-i10l8x.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895900/; classtype:trojan-activity;sid:84759000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/600cf7a76b81f22f/a3asesor-v8bhx2.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895901/; classtype:trojan-activity;sid:84759001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/3519058095acc344/a3asesor-47nyj1.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895902/; classtype:trojan-activity;sid:84759002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/0d5e3231ddd6bb1c/doc-etneer.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895903/; classtype:trojan-activity;sid:84759003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/362a6f120f9d1bb9/doc-9qcfje.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895904/; classtype:trojan-activity;sid:84759004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/19ddbf4978a5977c/doc-42vl1i.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895905/; classtype:trojan-activity;sid:84759005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/4d61f58a302f5cb2/doc-ztekuw.zip"; depth:58; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895906/; classtype:trojan-activity;sid:84759006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/b851b5d5dfe4eb86/a3asesor-6c7854.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895907/; classtype:trojan-activity;sid:84759007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/478b76e2b58fe359/a3asesor-k4gsjo.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895897/; classtype:trojan-activity;sid:84758997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.7"; depth:7; endswith; nocase; http.host; content:"151.233.179.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895896/; classtype:trojan-activity;sid:84758996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.190.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895895/; classtype:trojan-activity;sid:84758995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check3.sh"; depth:10; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895894/; classtype:trojan-activity;sid:84758994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c61de16702ab9449/cegidprimavera-8hqn9m.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895893/; classtype:trojan-activity;sid:84758993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c02ced092e010c51/a3asesor-t86oz7.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895890/; classtype:trojan-activity;sid:84758990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/e9fe5bde9bc2a799/a3asesor-pm13m1.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895891/; classtype:trojan-activity;sid:84758991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/fcd598f9c282fd5b/doc-u8piza.zip"; depth:53; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895892/; classtype:trojan-activity;sid:84758992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/e4c235c651c6378b/a3asesor-w4rqei.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895882/; classtype:trojan-activity;sid:84758982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c5b9487eac6fd723/a3asesor-4ggqe6.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895883/; classtype:trojan-activity;sid:84758983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c7c23c49b700933d/cegidprimavera-jrf75b.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895884/; classtype:trojan-activity;sid:84758984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/d317f208e1bacab6/a3asesor-6hlmnm.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895885/; classtype:trojan-activity;sid:84758985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/bdafe1912b525a67/a3asesor-hdvlot.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895886/; classtype:trojan-activity;sid:84758986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/f777a74094f7ff21/a3asesor-jv5lpe.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895887/; classtype:trojan-activity;sid:84758987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/f7c553a1e8d54f47/a3asesor-hi1r9y.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895888/; classtype:trojan-activity;sid:84758988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/eba123fa8f2735f7/cegidprimavera-v8xdlb.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895889/; classtype:trojan-activity;sid:84758989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/d753bdd23c9170fb/a3asesor-jww4f8.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895856/; classtype:trojan-activity;sid:84758956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/cc3b1d54fa362f2d/cegidprimavera-4v6atg.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895857/; classtype:trojan-activity;sid:84758957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/f7fd7bec467efd89/a3asesor-qwsy4u.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895858/; classtype:trojan-activity;sid:84758958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/fbbe49675c1f00db/a3asesor-jf4k4a.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895859/; classtype:trojan-activity;sid:84758959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/ed156982d94aa3e4/cegidprimavera-7hrgel.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895860/; classtype:trojan-activity;sid:84758960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/eabef4ae3fc3c1b6/a3asesor-5todnc.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895861/; classtype:trojan-activity;sid:84758961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/d76a42c00a00d943/a3asesor-czvh1h.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895862/; classtype:trojan-activity;sid:84758962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/d86d7574dcb1e1d2/a3asesor-rwbprl.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895863/; classtype:trojan-activity;sid:84758963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/cc277898d4ffda4b/a3asesor-moa9b9.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895864/; classtype:trojan-activity;sid:84758964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/e2c172dc7a9bbd7e/a3asesor-n1aojg.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895865/; classtype:trojan-activity;sid:84758965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c005ef46da9a93bf/a3asesor-6se6kg.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895866/; classtype:trojan-activity;sid:84758966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/e221e17d2027ddc9/a3asesor-9g9lr4.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895867/; classtype:trojan-activity;sid:84758967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/e86a0e1a1707dfe2/a3asesor-45q8nn.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895868/; classtype:trojan-activity;sid:84758968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/cf87e4d59c81a8fe/a3asesor-xddy7n.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895869/; classtype:trojan-activity;sid:84758969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c2b8e18d3ec4caca/a3asesor-3jtyra.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895870/; classtype:trojan-activity;sid:84758970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c404ac150f354816/a3asesor-hpt6ki.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895871/; classtype:trojan-activity;sid:84758971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c5648cacb98ec56a/a3asesor-8tjn8t.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895872/; classtype:trojan-activity;sid:84758972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/cfbcdd793545af2f/a3asesor-vrjg7p.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895873/; classtype:trojan-activity;sid:84758973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c4f530e4f0b0e7f9/cegidprimavera-tpf3eg.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895874/; classtype:trojan-activity;sid:84758974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/fdab66be91708746/a3asesor-unpgvl.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895875/; classtype:trojan-activity;sid:84758975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/c9733791d9ecdfcc/a3asesor-gntk21.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895876/; classtype:trojan-activity;sid:84758976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/ee679e4da32ba608/a3asesor-qlaqgb.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895877/; classtype:trojan-activity;sid:84758977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/d6f2b9c7fcc5e3f0/a3asesor-cxhpyv.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895878/; classtype:trojan-activity;sid:84758978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/db32500a085793c4/a3asesor-t0lgo4.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895879/; classtype:trojan-activity;sid:84758979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/f4a78efd7f243daf/a3asesor-4ccg6i.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895880/; classtype:trojan-activity;sid:84758980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/d2cef7885969904f/a3asesor-zjm7hp.zip"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895881/; classtype:trojan-activity;sid:84758981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/fff2b3ce90b79e95/cegidprimavera-i2emhb.zip"; depth:62; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895854/; classtype:trojan-activity;sid:84758954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a3asesor.lat/bd1e2792ce520221/a3asesor-hswrf6.lnk"; depth:56; endswith; nocase; http.host; content:"dn-pdflite.lat"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895855/; classtype:trojan-activity;sid:84758955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.249.100.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895853/; classtype:trojan-activity;sid:84758953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"81.225.195.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895852/; classtype:trojan-activity;sid:84758952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"88.249.100.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895851/; classtype:trojan-activity;sid:84758951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.14.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895850/; classtype:trojan-activity;sid:84758950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.202.181"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895849/; classtype:trojan-activity;sid:84758949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.229.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895848/; classtype:trojan-activity;sid:84758948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.234.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895847/; classtype:trojan-activity;sid:84758947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.234.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895846/; classtype:trojan-activity;sid:84758946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.14.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895845/; classtype:trojan-activity;sid:84758945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.32.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895844/; classtype:trojan-activity;sid:84758944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.227.205"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895843/; classtype:trojan-activity;sid:84758943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895842/; classtype:trojan-activity;sid:84758942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895835/; classtype:trojan-activity;sid:84758935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895836/; classtype:trojan-activity;sid:84758936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895837/; classtype:trojan-activity;sid:84758937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895838/; classtype:trojan-activity;sid:84758938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895839/; classtype:trojan-activity;sid:84758939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895840/; classtype:trojan-activity;sid:84758940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895841/; classtype:trojan-activity;sid:84758941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895830/; classtype:trojan-activity;sid:84758930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895831/; classtype:trojan-activity;sid:84758931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm64"; depth:6; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895832/; classtype:trojan-activity;sid:84758932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895833/; classtype:trojan-activity;sid:84758933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895834/; classtype:trojan-activity;sid:84758934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895829/; classtype:trojan-activity;sid:84758929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_0f73d6c3370dd989.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895828/; classtype:trojan-activity;sid:84758928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.177.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895827/; classtype:trojan-activity;sid:84758927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.217.176.113"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895826/; classtype:trojan-activity;sid:84758926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895825/; classtype:trojan-activity;sid:84758925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.177.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895824/; classtype:trojan-activity;sid:84758924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.217.176.113"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895823/; classtype:trojan-activity;sid:84758923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"104.249.10.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895822/; classtype:trojan-activity;sid:84758922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895821/; classtype:trojan-activity;sid:84758921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"104.249.10.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895820/; classtype:trojan-activity;sid:84758920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.239.66.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895819/; classtype:trojan-activity;sid:84758919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.239.66.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895818/; classtype:trojan-activity;sid:84758918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"104.239.66.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895817/; classtype:trojan-activity;sid:84758917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895816/; classtype:trojan-activity;sid:84758916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.176"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895815/; classtype:trojan-activity;sid:84758915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895814/; classtype:trojan-activity;sid:84758914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"104.249.10.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895813/; classtype:trojan-activity;sid:84758913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895812/; classtype:trojan-activity;sid:84758912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895811/; classtype:trojan-activity;sid:84758911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.239.66.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895810/; classtype:trojan-activity;sid:84758910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.76"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895809/; classtype:trojan-activity;sid:84758909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"104.249.10.76"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895808/; classtype:trojan-activity;sid:84758908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.235.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895807/; classtype:trojan-activity;sid:84758907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895806/; classtype:trojan-activity;sid:84758906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"104.249.10.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895805/; classtype:trojan-activity;sid:84758905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"158.94.211.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895804/; classtype:trojan-activity;sid:84758904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"158.94.211.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895803/; classtype:trojan-activity;sid:84758903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv7l"; depth:13; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895796/; classtype:trojan-activity;sid:84758896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.x86_64"; depth:13; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895797/; classtype:trojan-activity;sid:84758897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mipsel"; depth:13; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895798/; classtype:trojan-activity;sid:84758898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv5l"; depth:13; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895799/; classtype:trojan-activity;sid:84758899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv6l"; depth:13; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895800/; classtype:trojan-activity;sid:84758900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.armv4l"; depth:13; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895801/; classtype:trojan-activity;sid:84758901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miron.mips"; depth:11; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895802/; classtype:trojan-activity;sid:84758902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895795/; classtype:trojan-activity;sid:84758895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895794/; classtype:trojan-activity;sid:84758894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895793/; classtype:trojan-activity;sid:84758893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895792/; classtype:trojan-activity;sid:84758892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"195.177.94.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895791/; classtype:trojan-activity;sid:84758891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"195.177.94.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895790/; classtype:trojan-activity;sid:84758890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.36.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895789/; classtype:trojan-activity;sid:84758889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.36.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895788/; classtype:trojan-activity;sid:84758888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895787/; classtype:trojan-activity;sid:84758887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.155.68"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895786/; classtype:trojan-activity;sid:84758886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.217.97.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895785/; classtype:trojan-activity;sid:84758885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.217.97.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895784/; classtype:trojan-activity;sid:84758884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"45.83.28.88"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895783/; classtype:trojan-activity;sid:84758883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"45.83.28.88"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895782/; classtype:trojan-activity;sid:84758882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.101.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895781/; classtype:trojan-activity;sid:84758881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.237.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895780/; classtype:trojan-activity;sid:84758880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.101.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895779/; classtype:trojan-activity;sid:84758879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.149.90.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895778/; classtype:trojan-activity;sid:84758878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.229.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895777/; classtype:trojan-activity;sid:84758877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.231.77.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895776/; classtype:trojan-activity;sid:84758876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895775/; classtype:trojan-activity;sid:84758875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.249.68.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895774/; classtype:trojan-activity;sid:84758874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.252.252.201"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895773/; classtype:trojan-activity;sid:84758873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nets.zip"; depth:9; endswith; nocase; http.host; content:"89.34.90.203"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895772/; classtype:trojan-activity;sid:84758872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/l.sh"; depth:5; endswith; nocase; http.host; content:"37.49.227.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895771/; classtype:trojan-activity;sid:84758871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.65.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895769/; classtype:trojan-activity;sid:84758869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.174.1.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895770/; classtype:trojan-activity;sid:84758870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_dbb696e0e28bde4c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895768/; classtype:trojan-activity;sid:84758868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.208.116.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895767/; classtype:trojan-activity;sid:84758867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.16.164.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895766/; classtype:trojan-activity;sid:84758866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.231.77.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895765/; classtype:trojan-activity;sid:84758865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.0.112"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895764/; classtype:trojan-activity;sid:84758864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.0.112"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895763/; classtype:trojan-activity;sid:84758863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.116.107"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895762/; classtype:trojan-activity;sid:84758862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.16.164.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895761/; classtype:trojan-activity;sid:84758861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.23.194.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895760/; classtype:trojan-activity;sid:84758860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.sh"; depth:5; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895759/; classtype:trojan-activity;sid:84758859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.177.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895758/; classtype:trojan-activity;sid:84758858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.174.1.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895757/; classtype:trojan-activity;sid:84758857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.252.252.201"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895756/; classtype:trojan-activity;sid:84758856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.251.225.244"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895755/; classtype:trojan-activity;sid:84758855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.253.13.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895754/; classtype:trojan-activity;sid:84758854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.38.205"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895753/; classtype:trojan-activity;sid:84758853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.229.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895752/; classtype:trojan-activity;sid:84758852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.50.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895751/; classtype:trojan-activity;sid:84758851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.177.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895750/; classtype:trojan-activity;sid:84758850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.8.221"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895749/; classtype:trojan-activity;sid:84758849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.229.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895748/; classtype:trojan-activity;sid:84758848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.70.109.13"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895747/; classtype:trojan-activity;sid:84758847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.134.162.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895746/; classtype:trojan-activity;sid:84758846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.54.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895745/; classtype:trojan-activity;sid:84758845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.132.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895744/; classtype:trojan-activity;sid:84758844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.76.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895743/; classtype:trojan-activity;sid:84758843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.84.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895742/; classtype:trojan-activity;sid:84758842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.70.109.13"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895741/; classtype:trojan-activity;sid:84758841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.177.23.241"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895740/; classtype:trojan-activity;sid:84758840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.148.224"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895739/; classtype:trojan-activity;sid:84758839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895738/; classtype:trojan-activity;sid:84758838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895730/; classtype:trojan-activity;sid:84758830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mipsel"; depth:11; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895731/; classtype:trojan-activity;sid:84758831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86"; depth:8; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895732/; classtype:trojan-activity;sid:84758832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.armv5te"; depth:12; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895733/; classtype:trojan-activity;sid:84758833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.armv7-a"; depth:12; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895734/; classtype:trojan-activity;sid:84758834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.powerpc"; depth:12; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895735/; classtype:trojan-activity;sid:84758835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.armv6"; depth:10; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895736/; classtype:trojan-activity;sid:84758836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.aarch64"; depth:12; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895737/; classtype:trojan-activity;sid:84758837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.249.77.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895729/; classtype:trojan-activity;sid:84758829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.148.224"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895728/; classtype:trojan-activity;sid:84758828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader.sh"; depth:10; endswith; nocase; http.host; content:"95.164.53.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895727/; classtype:trojan-activity;sid:84758827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.29.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895726/; classtype:trojan-activity;sid:84758826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.247.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895725/; classtype:trojan-activity;sid:84758825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.160.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895724/; classtype:trojan-activity;sid:84758824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.29.60"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895723/; classtype:trojan-activity;sid:84758823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.145.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895722/; classtype:trojan-activity;sid:84758822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.247.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895721/; classtype:trojan-activity;sid:84758821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.12.217.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895720/; classtype:trojan-activity;sid:84758820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.64.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895719/; classtype:trojan-activity;sid:84758819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p"; depth:2; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895714/; classtype:trojan-activity;sid:84758814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sm4"; depth:4; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895715/; classtype:trojan-activity;sid:84758815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lil"; depth:4; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895716/; classtype:trojan-activity;sid:84758816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pkr"; depth:4; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895717/; classtype:trojan-activity;sid:84758817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vjx"; depth:4; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895718/; classtype:trojan-activity;sid:84758818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.130.103"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895713/; classtype:trojan-activity;sid:84758813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qtj"; depth:4; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895711/; classtype:trojan-activity;sid:84758811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mkno"; depth:5; endswith; nocase; http.host; content:"92.38.167.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895712/; classtype:trojan-activity;sid:84758812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"188.121.201.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895710/; classtype:trojan-activity;sid:84758810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.145.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895709/; classtype:trojan-activity;sid:84758809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.20.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3895708/; classtype:trojan-activity;sid:84758808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.191.32.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895707/; classtype:trojan-activity;sid:84758807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.63.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895706/; classtype:trojan-activity;sid:84758806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.137.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895705/; classtype:trojan-activity;sid:84758805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.112.33.200"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895704/; classtype:trojan-activity;sid:84758804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.159.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895703/; classtype:trojan-activity;sid:84758803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm4"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895699/; classtype:trojan-activity;sid:84758799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.x64"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895700/; classtype:trojan-activity;sid:84758800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm7n"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895701/; classtype:trojan-activity;sid:84758801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.x86-64"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895702/; classtype:trojan-activity;sid:84758802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm5n"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895693/; classtype:trojan-activity;sid:84758793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mipsel"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895694/; classtype:trojan-activity;sid:84758794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.i686"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895695/; classtype:trojan-activity;sid:84758795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm4n"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895696/; classtype:trojan-activity;sid:84758796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.powerpc"; depth:13; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895697/; classtype:trojan-activity;sid:84758797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hnap"; depth:5; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895698/; classtype:trojan-activity;sid:84758798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/g.mips"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895690/; classtype:trojan-activity;sid:84758790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/g.mpsl"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895691/; classtype:trojan-activity;sid:84758791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mips64"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895692/; classtype:trojan-activity;sid:84758792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv7l"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895683/; classtype:trojan-activity;sid:84758783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.i586"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895684/; classtype:trojan-activity;sid:84758784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.i386"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895685/; classtype:trojan-activity;sid:84758785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm6n"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895686/; classtype:trojan-activity;sid:84758786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.i486"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895687/; classtype:trojan-activity;sid:84758787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.x86_64"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895688/; classtype:trojan-activity;sid:84758788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv6l"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895689/; classtype:trojan-activity;sid:84758789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gpon"; depth:5; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895679/; classtype:trojan-activity;sid:84758779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.ppc440fp"; depth:14; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895680/; classtype:trojan-activity;sid:84758780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.superh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895681/; classtype:trojan-activity;sid:84758781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.x86"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895682/; classtype:trojan-activity;sid:84758782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv4l"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895673/; classtype:trojan-activity;sid:84758773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv5l"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895674/; classtype:trojan-activity;sid:84758774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.armv7"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895675/; classtype:trojan-activity;sid:84758775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.sparc"; depth:11; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895676/; classtype:trojan-activity;sid:84758776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huawei"; depth:7; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895677/; classtype:trojan-activity;sid:84758777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek"; depth:8; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895678/; classtype:trojan-activity;sid:84758778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.137.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895672/; classtype:trojan-activity;sid:84758772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"88.112.33.200"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895671/; classtype:trojan-activity;sid:84758771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.191.32.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895670/; classtype:trojan-activity;sid:84758770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.146.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895669/; classtype:trojan-activity;sid:84758769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.39.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895668/; classtype:trojan-activity;sid:84758768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.159.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895667/; classtype:trojan-activity;sid:84758767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.39.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895666/; classtype:trojan-activity;sid:84758766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.213.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895665/; classtype:trojan-activity;sid:84758765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.16.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895664/; classtype:trojan-activity;sid:84758764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.16.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895663/; classtype:trojan-activity;sid:84758763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.31.228.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895662/; classtype:trojan-activity;sid:84758762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.148.103.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895661/; classtype:trojan-activity;sid:84758761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.200.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895660/; classtype:trojan-activity;sid:84758760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.246.83"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895659/; classtype:trojan-activity;sid:84758759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.148.103.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895658/; classtype:trojan-activity;sid:84758758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.213.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895657/; classtype:trojan-activity;sid:84758757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.4.67.131"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895656/; classtype:trojan-activity;sid:84758756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.246.83"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895655/; classtype:trojan-activity;sid:84758755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.199.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895654/; classtype:trojan-activity;sid:84758754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.233.97.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895653/; classtype:trojan-activity;sid:84758753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.60.21"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895652/; classtype:trojan-activity;sid:84758752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.202.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895651/; classtype:trojan-activity;sid:84758751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.138.247.7"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895650/; classtype:trojan-activity;sid:84758750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/cekizsafu"; depth:15; endswith; nocase; http.host; content:"31.77.227.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895649/; classtype:trojan-activity;sid:84758749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.202.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895648/; classtype:trojan-activity;sid:84758748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.138.247.7"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895647/; classtype:trojan-activity;sid:84758747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.114.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895646/; classtype:trojan-activity;sid:84758746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895645/; classtype:trojan-activity;sid:84758745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.205.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895644/; classtype:trojan-activity;sid:84758744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/systemd"; depth:8; endswith; nocase; http.host; content:"195.137.245.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895643/; classtype:trojan-activity;sid:84758743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.25.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895642/; classtype:trojan-activity;sid:84758742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.34.56.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895641/; classtype:trojan-activity;sid:84758741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.205.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895640/; classtype:trojan-activity;sid:84758740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.253.8.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895639/; classtype:trojan-activity;sid:84758739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.83.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895638/; classtype:trojan-activity;sid:84758738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.248.15.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895637/; classtype:trojan-activity;sid:84758737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.83.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895636/; classtype:trojan-activity;sid:84758736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.32.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895635/; classtype:trojan-activity;sid:84758735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"185.248.15.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895634/; classtype:trojan-activity;sid:84758734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.x86_64"; depth:15; endswith; nocase; http.host; content:"eclipsebible.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895632/; classtype:trojan-activity;sid:84758732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eclipse.x86_64"; depth:15; endswith; nocase; http.host; content:"2.26.48.37"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895633/; classtype:trojan-activity;sid:84758733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader.sh"; depth:10; endswith; nocase; http.host; content:"eclipsebible.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895631/; classtype:trojan-activity;sid:84758731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.151.204.81"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895630/; classtype:trojan-activity;sid:84758730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.64.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895629/; classtype:trojan-activity;sid:84758729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.133.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895628/; classtype:trojan-activity;sid:84758728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.151.204.81"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895627/; classtype:trojan-activity;sid:84758727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.133.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895626/; classtype:trojan-activity;sid:84758726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.230.160.24"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895625/; classtype:trojan-activity;sid:84758725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.107.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895624/; classtype:trojan-activity;sid:84758724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.116.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895623/; classtype:trojan-activity;sid:84758723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.46.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895622/; classtype:trojan-activity;sid:84758722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.20.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895621/; classtype:trojan-activity;sid:84758721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.20.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895620/; classtype:trojan-activity;sid:84758720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.107.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895618/; classtype:trojan-activity;sid:84758718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"210.208.110.51"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895619/; classtype:trojan-activity;sid:84758719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.31.184.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895617/; classtype:trojan-activity;sid:84758717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.46.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895616/; classtype:trojan-activity;sid:84758716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/fl9uweistzcccua040lmj/hinge.exe|3f|rlkey=60h76wonw3lfo89vu7epcmgwr|7c|26|7c|st=9o0gib4o|7c|26|7c|dl=1"; depth:109; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895615/; classtype:trojan-activity;sid:84758715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.244.68.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895614/; classtype:trojan-activity;sid:84758714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.244.68.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895613/; classtype:trojan-activity;sid:84758713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.31.184.132"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895612/; classtype:trojan-activity;sid:84758712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895611/; classtype:trojan-activity;sid:84758711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.112.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895610/; classtype:trojan-activity;sid:84758710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm"; depth:22; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895609/; classtype:trojan-activity;sid:84758709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm7"; depth:23; endswith; nocase; http.host; content:"31.77.227.111"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895608/; classtype:trojan-activity;sid:84758708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_2406cf76a7ca34ca.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895606/; classtype:trojan-activity;sid:84758706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_bbcbeb2966f48fd6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895607/; classtype:trojan-activity;sid:84758707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.243.251.152"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895605/; classtype:trojan-activity;sid:84758705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.32.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895604/; classtype:trojan-activity;sid:84758704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f/5239f7a9c7ae.exe"; depth:19; endswith; nocase; http.host; content:"directdownloadl.ink"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895603/; classtype:trojan-activity;sid:84758703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f/aca7ebab32cd.bat"; depth:19; endswith; nocase; http.host; content:"directdownloadl.ink"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895602/; classtype:trojan-activity;sid:84758702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f/0713a6e9e059.apk"; depth:19; endswith; nocase; http.host; content:"directdownloadl.ink"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895601/; classtype:trojan-activity;sid:84758701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f/452f5657e973.zip"; depth:19; endswith; nocase; http.host; content:"directdownloadl.ink"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895600/; classtype:trojan-activity;sid:84758700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/6a4b9d67c109e.exe"; depth:26; endswith; nocase; http.host; content:"safeuploadz.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895599/; classtype:trojan-activity;sid:84758699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/msdt.exe"; depth:15; endswith; nocase; http.host; content:"file.tugou.com.co"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895598/; classtype:trojan-activity;sid:84758698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.windows.dll"; depth:30; endswith; nocase; http.host; content:"thenewcoffeshop.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895597/; classtype:trojan-activity;sid:84758697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/powershell.exe"; depth:21; endswith; nocase; http.host; content:"file.tugou.com.co"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895595/; classtype:trojan-activity;sid:84758695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.core.dll"; depth:27; endswith; nocase; http.host; content:"thenewcoffeshop.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895596/; classtype:trojan-activity;sid:84758696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/route.exe"; depth:16; endswith; nocase; http.host; content:"file.tugou.com.co"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895594/; classtype:trojan-activity;sid:84758694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/adobe%20acrobat%20reader.exe"; depth:35; endswith; nocase; http.host; content:"file.tugou.com.co"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895591/; classtype:trojan-activity;sid:84758691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.windowsbackstageshell.exe"; depth:44; endswith; nocase; http.host; content:"thenewcoffeshop.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895592/; classtype:trojan-activity;sid:84758692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.windowsclient.exe"; depth:36; endswith; nocase; http.host; content:"thenewcoffeshop.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895593/; classtype:trojan-activity;sid:84758693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientservice.exe"; depth:36; endswith; nocase; http.host; content:"thenewcoffeshop.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895586/; classtype:trojan-activity;sid:84758686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.windowsfilemanager.exe"; depth:41; endswith; nocase; http.host; content:"thenewcoffeshop.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895587/; classtype:trojan-activity;sid:84758687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"178.16.55.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895588/; classtype:trojan-activity;sid:84758688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lc/1.exe"; depth:9; endswith; nocase; http.host; content:"158.94.209.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895589/; classtype:trojan-activity;sid:84758689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.client.dll"; depth:29; endswith; nocase; http.host; content:"thenewcoffeshop.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895590/; classtype:trojan-activity;sid:84758690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"178.16.55.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895582/; classtype:trojan-activity;sid:84758682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lc/2.exe"; depth:9; endswith; nocase; http.host; content:"158.94.209.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895583/; classtype:trojan-activity;sid:84758683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lc/3.exe"; depth:9; endswith; nocase; http.host; content:"158.94.209.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895584/; classtype:trojan-activity;sid:84758684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientservice.dll"; depth:36; endswith; nocase; http.host; content:"thenewcoffeshop.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895585/; classtype:trojan-activity;sid:84758685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig.exe"; depth:10; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895581/; classtype:trojan-activity;sid:84758681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tejkpnj.exe"; depth:12; endswith; nocase; http.host; content:"letsgobok.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895580/; classtype:trojan-activity;sid:84758680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.windows.dll"; depth:30; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895578/; classtype:trojan-activity;sid:84758678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f/a7118141be1f.exe"; depth:19; endswith; nocase; http.host; content:"directdownloadl.ink"; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895579/; classtype:trojan-activity;sid:84758679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.windowsclient.exe"; depth:36; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895575/; classtype:trojan-activity;sid:84758675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.client.dll"; depth:29; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895576/; classtype:trojan-activity;sid:84758676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.core.dll"; depth:27; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895577/; classtype:trojan-activity;sid:84758677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.windowsbackstageshell.exe"; depth:44; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895571/; classtype:trojan-activity;sid:84758671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.windowsfilemanager.exe"; depth:41; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895572/; classtype:trojan-activity;sid:84758672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientservice.dll"; depth:36; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895573/; classtype:trojan-activity;sid:84758673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientservice.exe"; depth:36; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895574/; classtype:trojan-activity;sid:84758674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_2eb5775665263b24.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895564/; classtype:trojan-activity;sid:84758664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_218826de3f5a5bb4.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895565/; classtype:trojan-activity;sid:84758665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_0a5c6aecd2079cf9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895567/; classtype:trojan-activity;sid:84758667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_8911b671beb49a6a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895568/; classtype:trojan-activity;sid:84758668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b725112f82065785.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895569/; classtype:trojan-activity;sid:84758669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.104.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895563/; classtype:trojan-activity;sid:84758663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.165.9.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895562/; classtype:trojan-activity;sid:84758662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.229.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895561/; classtype:trojan-activity;sid:84758661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.59.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895560/; classtype:trojan-activity;sid:84758660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.35.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895559/; classtype:trojan-activity;sid:84758659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.6.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895558/; classtype:trojan-activity;sid:84758658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.227.184.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895556/; classtype:trojan-activity;sid:84758656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.6.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895557/; classtype:trojan-activity;sid:84758657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.246.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895555/; classtype:trojan-activity;sid:84758655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.66.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895554/; classtype:trojan-activity;sid:84758654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.exe"; depth:6; endswith; nocase; http.host; content:"cim-kolea.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895553/; classtype:trojan-activity;sid:84758653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.227.184.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895552/; classtype:trojan-activity;sid:84758652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.56.204.114"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895551/; classtype:trojan-activity;sid:84758651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.59.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895550/; classtype:trojan-activity;sid:84758650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.66.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895549/; classtype:trojan-activity;sid:84758649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.246.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895548/; classtype:trojan-activity;sid:84758648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.56.204.114"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895547/; classtype:trojan-activity;sid:84758647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.143.58"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895546/; classtype:trojan-activity;sid:84758646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.36.63"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895545/; classtype:trojan-activity;sid:84758645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.195.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895544/; classtype:trojan-activity;sid:84758644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.210.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895543/; classtype:trojan-activity;sid:84758643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.195.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895542/; classtype:trojan-activity;sid:84758642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.202.209.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895541/; classtype:trojan-activity;sid:84758641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.198.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895540/; classtype:trojan-activity;sid:84758640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.76.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895539/; classtype:trojan-activity;sid:84758639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.202.209.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895538/; classtype:trojan-activity;sid:84758638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0x/cls"; depth:7; endswith; nocase; http.host; content:"166.88.134.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895535/; classtype:trojan-activity;sid:84758635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0x/js"; depth:6; endswith; nocase; http.host; content:"166.88.134.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895536/; classtype:trojan-activity;sid:84758636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0x/ls"; depth:6; endswith; nocase; http.host; content:"166.88.134.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895537/; classtype:trojan-activity;sid:84758637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.82.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895534/; classtype:trojan-activity;sid:84758634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.82.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895533/; classtype:trojan-activity;sid:84758633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.127.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895532/; classtype:trojan-activity;sid:84758632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.21.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895531/; classtype:trojan-activity;sid:84758631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"120.53.120.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895530/; classtype:trojan-activity;sid:84758630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.200.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895529/; classtype:trojan-activity;sid:84758629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.199.254.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895528/; classtype:trojan-activity;sid:84758628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.199.254.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895521/; classtype:trojan-activity;sid:84758621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.83.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895522/; classtype:trojan-activity;sid:84758622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.112.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895523/; classtype:trojan-activity;sid:84758623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.232.123"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895524/; classtype:trojan-activity;sid:84758624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.175.111"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895525/; classtype:trojan-activity;sid:84758625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895526/; classtype:trojan-activity;sid:84758626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"8.134.218.77"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895527/; classtype:trojan-activity;sid:84758627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.236.44.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895499/; classtype:trojan-activity;sid:84758599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.58.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895500/; classtype:trojan-activity;sid:84758600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.93.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895501/; classtype:trojan-activity;sid:84758601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.80.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895502/; classtype:trojan-activity;sid:84758602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"144.48.123.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895503/; classtype:trojan-activity;sid:84758603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.88.248.179"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895504/; classtype:trojan-activity;sid:84758604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"144.48.123.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895505/; classtype:trojan-activity;sid:84758605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.112.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895506/; classtype:trojan-activity;sid:84758606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.215.140"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895507/; classtype:trojan-activity;sid:84758607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.76.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895508/; classtype:trojan-activity;sid:84758608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.235.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895509/; classtype:trojan-activity;sid:84758609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.205.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895510/; classtype:trojan-activity;sid:84758610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.161.116.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895511/; classtype:trojan-activity;sid:84758611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.181.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895512/; classtype:trojan-activity;sid:84758612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.59.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895513/; classtype:trojan-activity;sid:84758613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.195.28.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895514/; classtype:trojan-activity;sid:84758614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads.sh"; depth:12; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895515/; classtype:trojan-activity;sid:84758615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"81.225.195.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895516/; classtype:trojan-activity;sid:84758616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.11.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895517/; classtype:trojan-activity;sid:84758617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.213.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895518/; classtype:trojan-activity;sid:84758618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.201.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895519/; classtype:trojan-activity;sid:84758619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.25.71"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895520/; classtype:trojan-activity;sid:84758620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.52.62"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895494/; classtype:trojan-activity;sid:84758594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.101.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895495/; classtype:trojan-activity;sid:84758595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.170.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895496/; classtype:trojan-activity;sid:84758596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.226.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895497/; classtype:trojan-activity;sid:84758597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.245.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895498/; classtype:trojan-activity;sid:84758598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.134.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895493/; classtype:trojan-activity;sid:84758593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.71.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895485/; classtype:trojan-activity;sid:84758585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.233.151.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895486/; classtype:trojan-activity;sid:84758586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.81.110.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895487/; classtype:trojan-activity;sid:84758587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.157.169.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895488/; classtype:trojan-activity;sid:84758588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.181.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895489/; classtype:trojan-activity;sid:84758589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.100.32.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895490/; classtype:trojan-activity;sid:84758590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.195.28.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895491/; classtype:trojan-activity;sid:84758591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.202.181"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895492/; classtype:trojan-activity;sid:84758592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.30.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895462/; classtype:trojan-activity;sid:84758562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.49.184"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895463/; classtype:trojan-activity;sid:84758563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.205.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895464/; classtype:trojan-activity;sid:84758564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.155.68"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895465/; classtype:trojan-activity;sid:84758565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.151.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895466/; classtype:trojan-activity;sid:84758566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.84.130"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895467/; classtype:trojan-activity;sid:84758567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.233.151.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895468/; classtype:trojan-activity;sid:84758568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.197.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895469/; classtype:trojan-activity;sid:84758569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.2.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895470/; classtype:trojan-activity;sid:84758570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.102.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895471/; classtype:trojan-activity;sid:84758571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.73.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895472/; classtype:trojan-activity;sid:84758572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.181.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895473/; classtype:trojan-activity;sid:84758573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.94.222.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895474/; classtype:trojan-activity;sid:84758574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.52.227.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895475/; classtype:trojan-activity;sid:84758575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"204.116.34.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895476/; classtype:trojan-activity;sid:84758576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.246.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895477/; classtype:trojan-activity;sid:84758577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.154.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895478/; classtype:trojan-activity;sid:84758578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.170.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895479/; classtype:trojan-activity;sid:84758579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.237.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895480/; classtype:trojan-activity;sid:84758580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.197.69"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895481/; classtype:trojan-activity;sid:84758581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.220.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895482/; classtype:trojan-activity;sid:84758582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.151.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895483/; classtype:trojan-activity;sid:84758583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.38.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895484/; classtype:trojan-activity;sid:84758584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.117.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895457/; classtype:trojan-activity;sid:84758557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"190.109.227.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895458/; classtype:trojan-activity;sid:84758558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.2.242"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895459/; classtype:trojan-activity;sid:84758559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.194.144"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895460/; classtype:trojan-activity;sid:84758560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.82.112"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895461/; classtype:trojan-activity;sid:84758561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.94.222.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895456/; classtype:trojan-activity;sid:84758556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.192.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895455/; classtype:trojan-activity;sid:84758555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.170.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895454/; classtype:trojan-activity;sid:84758554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.227.109.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895439/; classtype:trojan-activity;sid:84758539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.54.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895440/; classtype:trojan-activity;sid:84758540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.94.58.116"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895441/; classtype:trojan-activity;sid:84758541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.151.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895442/; classtype:trojan-activity;sid:84758542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.58.142.224"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895443/; classtype:trojan-activity;sid:84758543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.41.102.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895444/; classtype:trojan-activity;sid:84758544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.170.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895445/; classtype:trojan-activity;sid:84758545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.221.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895446/; classtype:trojan-activity;sid:84758546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.59.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895447/; classtype:trojan-activity;sid:84758547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.215.140"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895448/; classtype:trojan-activity;sid:84758548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.20.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895449/; classtype:trojan-activity;sid:84758549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.192.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895450/; classtype:trojan-activity;sid:84758550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.221.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895451/; classtype:trojan-activity;sid:84758551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.108.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895452/; classtype:trojan-activity;sid:84758552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.38.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895453/; classtype:trojan-activity;sid:84758553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.50.210"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895427/; classtype:trojan-activity;sid:84758527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.225.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895428/; classtype:trojan-activity;sid:84758528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.150.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895429/; classtype:trojan-activity;sid:84758529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.168.178"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895430/; classtype:trojan-activity;sid:84758530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.84.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895431/; classtype:trojan-activity;sid:84758531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.118.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895432/; classtype:trojan-activity;sid:84758532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.190.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895433/; classtype:trojan-activity;sid:84758533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.118.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895434/; classtype:trojan-activity;sid:84758534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"202.163.107.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895435/; classtype:trojan-activity;sid:84758535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.76.51"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895436/; classtype:trojan-activity;sid:84758536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.11.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895437/; classtype:trojan-activity;sid:84758537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.134.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895438/; classtype:trojan-activity;sid:84758538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.246.106"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895423/; classtype:trojan-activity;sid:84758523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"87.227.173.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895424/; classtype:trojan-activity;sid:84758524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.239.251.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895425/; classtype:trojan-activity;sid:84758525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.245.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895426/; classtype:trojan-activity;sid:84758526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.252.140.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895422/; classtype:trojan-activity;sid:84758522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.210.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895413/; classtype:trojan-activity;sid:84758513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.180.122.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895414/; classtype:trojan-activity;sid:84758514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.92.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895415/; classtype:trojan-activity;sid:84758515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.84.130"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895416/; classtype:trojan-activity;sid:84758516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.33.170"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895417/; classtype:trojan-activity;sid:84758517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.218.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895418/; classtype:trojan-activity;sid:84758518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.76.51"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895419/; classtype:trojan-activity;sid:84758519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.18.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895420/; classtype:trojan-activity;sid:84758520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.148.132"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895421/; classtype:trojan-activity;sid:84758521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.237.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895391/; classtype:trojan-activity;sid:84758491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.242.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895392/; classtype:trojan-activity;sid:84758492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.62.210"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895393/; classtype:trojan-activity;sid:84758493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.87.161.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895394/; classtype:trojan-activity;sid:84758494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"1.61.151.115"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895395/; classtype:trojan-activity;sid:84758495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.58.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895396/; classtype:trojan-activity;sid:84758496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.52.227.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895397/; classtype:trojan-activity;sid:84758497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.177.157"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895398/; classtype:trojan-activity;sid:84758498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.96.38"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895399/; classtype:trojan-activity;sid:84758499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.123.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895400/; classtype:trojan-activity;sid:84758500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.213.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895401/; classtype:trojan-activity;sid:84758501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"38.56.21.66"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895402/; classtype:trojan-activity;sid:84758502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.252.199.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895403/; classtype:trojan-activity;sid:84758503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.146.185.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895404/; classtype:trojan-activity;sid:84758504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.202.77.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895405/; classtype:trojan-activity;sid:84758505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.37.212.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895406/; classtype:trojan-activity;sid:84758506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.227.109.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895407/; classtype:trojan-activity;sid:84758507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.84.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895408/; classtype:trojan-activity;sid:84758508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"87.227.173.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895409/; classtype:trojan-activity;sid:84758509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.77.116"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895410/; classtype:trojan-activity;sid:84758510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.73.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895411/; classtype:trojan-activity;sid:84758511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.33.170"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895412/; classtype:trojan-activity;sid:84758512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.182.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895389/; classtype:trojan-activity;sid:84758489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.194.144"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895390/; classtype:trojan-activity;sid:84758490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.193.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895388/; classtype:trojan-activity;sid:84758488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.86.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895387/; classtype:trojan-activity;sid:84758487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.81.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895386/; classtype:trojan-activity;sid:84758486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.208.179.252"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895385/; classtype:trojan-activity;sid:84758485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.47.41"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895384/; classtype:trojan-activity;sid:84758484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_03d11bb69b329ea4.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895383/; classtype:trojan-activity;sid:84758483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.i468"; depth:26; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895382/; classtype:trojan-activity;sid:84758482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.86.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895381/; classtype:trojan-activity;sid:84758481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.81.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895380/; classtype:trojan-activity;sid:84758480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.127.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895379/; classtype:trojan-activity;sid:84758479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myh"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895377/; classtype:trojan-activity;sid:84758477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9yz5"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895378/; classtype:trojan-activity;sid:84758478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dq0"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895374/; classtype:trojan-activity;sid:84758474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eyml"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895375/; classtype:trojan-activity;sid:84758475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tcii"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895376/; classtype:trojan-activity;sid:84758476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895373/; classtype:trojan-activity;sid:84758473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.123.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895372/; classtype:trojan-activity;sid:84758472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.216.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895371/; classtype:trojan-activity;sid:84758471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.86.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895370/; classtype:trojan-activity;sid:84758470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.179.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895369/; classtype:trojan-activity;sid:84758469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.197.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895368/; classtype:trojan-activity;sid:84758468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.229.216.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895367/; classtype:trojan-activity;sid:84758467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.214.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895366/; classtype:trojan-activity;sid:84758466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.1.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895365/; classtype:trojan-activity;sid:84758465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895364/; classtype:trojan-activity;sid:84758464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dmz8"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895354/; classtype:trojan-activity;sid:84758454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chq"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895355/; classtype:trojan-activity;sid:84758455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reo"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895356/; classtype:trojan-activity;sid:84758456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3hy"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895357/; classtype:trojan-activity;sid:84758457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m96"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895358/; classtype:trojan-activity;sid:84758458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uzj"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895359/; classtype:trojan-activity;sid:84758459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hjaw"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895360/; classtype:trojan-activity;sid:84758460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/828z"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895361/; classtype:trojan-activity;sid:84758461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4ao"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895362/; classtype:trojan-activity;sid:84758462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nkg"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895363/; classtype:trojan-activity;sid:84758463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.179.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895353/; classtype:trojan-activity;sid:84758453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.1.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895352/; classtype:trojan-activity;sid:84758452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.226.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895351/; classtype:trojan-activity;sid:84758451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/|3f|download=1"; depth:15; endswith; nocase; http.host; content:"svo-poiskrat.vercel.app"; depth:23; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895350/; classtype:trojan-activity;sid:84758450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_27c28b4831967d60.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895349/; classtype:trojan-activity;sid:84758449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.67.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895348/; classtype:trojan-activity;sid:84758448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.67.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895347/; classtype:trojan-activity;sid:84758447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.150.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895346/; classtype:trojan-activity;sid:84758446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.248.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895345/; classtype:trojan-activity;sid:84758445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.36.63"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895344/; classtype:trojan-activity;sid:84758444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a0497afdd457f5f8.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895343/; classtype:trojan-activity;sid:84758443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"113.221.58.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895342/; classtype:trojan-activity;sid:84758442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_60d2bd674d037b28.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895340/; classtype:trojan-activity;sid:84758440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_383a5ee68e302d41.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895341/; classtype:trojan-activity;sid:84758441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/femboy.sh"; depth:10; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895339/; classtype:trojan-activity;sid:84758439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895338/; classtype:trojan-activity;sid:84758438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_58065cc2507519e8.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895335/; classtype:trojan-activity;sid:84758435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"94.154.43.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895336/; classtype:trojan-activity;sid:84758436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_f8b3df0bb4538dce.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895337/; classtype:trojan-activity;sid:84758437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86"; depth:8; endswith; nocase; http.host; content:"94.154.43.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895331/; classtype:trojan-activity;sid:84758431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4ee2cb2e27bf5cf6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895332/; classtype:trojan-activity;sid:84758432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4cb61535391ee2ca.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895333/; classtype:trojan-activity;sid:84758433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a180d7b365a22950.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895334/; classtype:trojan-activity;sid:84758434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.248.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895330/; classtype:trojan-activity;sid:84758430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895329/; classtype:trojan-activity;sid:84758429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.20.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895328/; classtype:trojan-activity;sid:84758428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.220.11.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895327/; classtype:trojan-activity;sid:84758427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.180.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895326/; classtype:trojan-activity;sid:84758426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.86.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895325/; classtype:trojan-activity;sid:84758425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.180.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895324/; classtype:trojan-activity;sid:84758424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.104.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895323/; classtype:trojan-activity;sid:84758423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.23.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895322/; classtype:trojan-activity;sid:84758422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"186.149.204.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895321/; classtype:trojan-activity;sid:84758421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.53.243.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895320/; classtype:trojan-activity;sid:84758420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.134.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895319/; classtype:trojan-activity;sid:84758419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"186.149.204.12"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895318/; classtype:trojan-activity;sid:84758418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.64.97"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895317/; classtype:trojan-activity;sid:84758417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.armv7l"; depth:11; endswith; nocase; http.host; content:"104.252.175.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895316/; classtype:trojan-activity;sid:84758416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.53.243.200"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895315/; classtype:trojan-activity;sid:84758415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.154.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895314/; classtype:trojan-activity;sid:84758414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.99.167.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895313/; classtype:trojan-activity;sid:84758413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.37.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895312/; classtype:trojan-activity;sid:84758412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.81.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895310/; classtype:trojan-activity;sid:84758410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.182.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895311/; classtype:trojan-activity;sid:84758411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.235.137.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895308/; classtype:trojan-activity;sid:84758408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.167.68.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895309/; classtype:trojan-activity;sid:84758409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.235.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895307/; classtype:trojan-activity;sid:84758407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"wantsellonline.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895306/; classtype:trojan-activity;sid:84758406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.99.167.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895305/; classtype:trojan-activity;sid:84758405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.181.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895304/; classtype:trojan-activity;sid:84758404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.235.137.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895303/; classtype:trojan-activity;sid:84758403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.134.245.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895302/; classtype:trojan-activity;sid:84758402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.252.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895301/; classtype:trojan-activity;sid:84758401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.252.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895300/; classtype:trojan-activity;sid:84758400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.234.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895299/; classtype:trojan-activity;sid:84758399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.226.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895298/; classtype:trojan-activity;sid:84758398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.244.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895297/; classtype:trojan-activity;sid:84758397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.251.225.244"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895296/; classtype:trojan-activity;sid:84758396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.32.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895295/; classtype:trojan-activity;sid:84758395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.32.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895294/; classtype:trojan-activity;sid:84758394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.32.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895293/; classtype:trojan-activity;sid:84758393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.158.139"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895292/; classtype:trojan-activity;sid:84758392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.134.175.33"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895291/; classtype:trojan-activity;sid:84758391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pancake/bin.mipsel"; depth:19; endswith; nocase; http.host; content:"31.56.144.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895290/; classtype:trojan-activity;sid:84758390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.193.122.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895289/; classtype:trojan-activity;sid:84758389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.155.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895288/; classtype:trojan-activity;sid:84758388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.208.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895287/; classtype:trojan-activity;sid:84758387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.93.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895286/; classtype:trojan-activity;sid:84758386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.237.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895285/; classtype:trojan-activity;sid:84758385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.78.68.30"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895284/; classtype:trojan-activity;sid:84758384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.232.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895283/; classtype:trojan-activity;sid:84758383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.193.122.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895282/; classtype:trojan-activity;sid:84758382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.96.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895281/; classtype:trojan-activity;sid:84758381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.155.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895280/; classtype:trojan-activity;sid:84758380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.86.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895279/; classtype:trojan-activity;sid:84758379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.209.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895278/; classtype:trojan-activity;sid:84758378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.78.68.30"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895277/; classtype:trojan-activity;sid:84758377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.237.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895276/; classtype:trojan-activity;sid:84758376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.225.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895275/; classtype:trojan-activity;sid:84758375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"171.213.177.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895274/; classtype:trojan-activity;sid:84758374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.110.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895273/; classtype:trojan-activity;sid:84758373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.209.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895272/; classtype:trojan-activity;sid:84758372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a88c88317d5c7d6a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895271/; classtype:trojan-activity;sid:84758371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.29.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895270/; classtype:trojan-activity;sid:84758370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.73.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895269/; classtype:trojan-activity;sid:84758369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.12.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895268/; classtype:trojan-activity;sid:84758368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.110.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895267/; classtype:trojan-activity;sid:84758367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.7.132"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895266/; classtype:trojan-activity;sid:84758366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.155.230"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895265/; classtype:trojan-activity;sid:84758365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.12.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895264/; classtype:trojan-activity;sid:84758364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_1489820be780f8d5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895263/; classtype:trojan-activity;sid:84758363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.187.224.206"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895262/; classtype:trojan-activity;sid:84758362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.127.73.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895261/; classtype:trojan-activity;sid:84758361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_72f092cefee51b63.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895260/; classtype:trojan-activity;sid:84758360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.29.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895259/; classtype:trojan-activity;sid:84758359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.7.132"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895258/; classtype:trojan-activity;sid:84758358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.149.136"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895257/; classtype:trojan-activity;sid:84758357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.221.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895256/; classtype:trojan-activity;sid:84758356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.221.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895255/; classtype:trojan-activity;sid:84758355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.57.116.136"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895254/; classtype:trojan-activity;sid:84758354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.202.232.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895253/; classtype:trojan-activity;sid:84758353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.30.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895252/; classtype:trojan-activity;sid:84758352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.177.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895251/; classtype:trojan-activity;sid:84758351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.243.23"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895250/; classtype:trojan-activity;sid:84758350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.26.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895248/; classtype:trojan-activity;sid:84758348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.79.136"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895249/; classtype:trojan-activity;sid:84758349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_fb.sh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895247/; classtype:trojan-activity;sid:84758347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_dv.sh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895243/; classtype:trojan-activity;sid:84758343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_av.sh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895244/; classtype:trojan-activity;sid:84758344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_tbk.sh"; depth:13; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895245/; classtype:trojan-activity;sid:84758345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_tp.sh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895246/; classtype:trojan-activity;sid:84758346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_hi.sh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895242/; classtype:trojan-activity;sid:84758342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_ct.sh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895240/; classtype:trojan-activity;sid:84758340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_hk.sh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895241/; classtype:trojan-activity;sid:84758341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi_zh.sh"; depth:12; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895239/; classtype:trojan-activity;sid:84758339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.26.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895238/; classtype:trojan-activity;sid:84758338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.124.103"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895237/; classtype:trojan-activity;sid:84758337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.spc"; depth:25; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895226/; classtype:trojan-activity;sid:84758326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/debug"; depth:21; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895227/; classtype:trojan-activity;sid:84758327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.x86"; depth:25; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895228/; classtype:trojan-activity;sid:84758328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.sh"; depth:5; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895229/; classtype:trojan-activity;sid:84758329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.arc"; depth:25; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895230/; classtype:trojan-activity;sid:84758330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.arm7"; depth:26; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895231/; classtype:trojan-activity;sid:84758331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.arm"; depth:25; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895232/; classtype:trojan-activity;sid:84758332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.m68k"; depth:26; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895233/; classtype:trojan-activity;sid:84758333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.mips"; depth:26; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895234/; classtype:trojan-activity;sid:84758334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.i686"; depth:26; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895235/; classtype:trojan-activity;sid:84758335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.x86_64"; depth:28; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895236/; classtype:trojan-activity;sid:84758336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.sh4"; depth:25; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895221/; classtype:trojan-activity;sid:84758321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.arm5"; depth:26; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895222/; classtype:trojan-activity;sid:84758322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.arm6"; depth:26; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895223/; classtype:trojan-activity;sid:84758323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.mpsl"; depth:26; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895224/; classtype:trojan-activity;sid:84758324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/00101010101001/morte.ppc"; depth:25; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895225/; classtype:trojan-activity;sid:84758325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.237.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895220/; classtype:trojan-activity;sid:84758320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.148.218.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895219/; classtype:trojan-activity;sid:84758319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.148.218.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895218/; classtype:trojan-activity;sid:84758318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.124.103"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895217/; classtype:trojan-activity;sid:84758317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.52.156.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895216/; classtype:trojan-activity;sid:84758316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.105.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895215/; classtype:trojan-activity;sid:84758315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.180.160"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895214/; classtype:trojan-activity;sid:84758314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"154.250.102.0"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895213/; classtype:trojan-activity;sid:84758313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_71e9122fb7adb41f.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895212/; classtype:trojan-activity;sid:84758312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.149.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895211/; classtype:trojan-activity;sid:84758311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.180.160"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895210/; classtype:trojan-activity;sid:84758310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.105.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895209/; classtype:trojan-activity;sid:84758309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_8b0de4fcc07257ed.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895208/; classtype:trojan-activity;sid:84758308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7782139129/neitqa0.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895207/; classtype:trojan-activity;sid:84758307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.232.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895206/; classtype:trojan-activity;sid:84758306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"93.157.253.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895205/; classtype:trojan-activity;sid:84758305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.84.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895204/; classtype:trojan-activity;sid:84758304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3f6d7b23812e3a8e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895203/; classtype:trojan-activity;sid:84758303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.128.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895202/; classtype:trojan-activity;sid:84758302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig_x64"; depth:10; endswith; nocase; http.host; content:"94.154.43.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895201/; classtype:trojan-activity;sid:84758301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmr_miner_x64"; depth:14; endswith; nocase; http.host; content:"94.154.43.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895199/; classtype:trojan-activity;sid:84758299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmr_miner_arm64"; depth:16; endswith; nocase; http.host; content:"94.154.43.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895200/; classtype:trojan-activity;sid:84758300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.108.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895198/; classtype:trojan-activity;sid:84758298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.201.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895197/; classtype:trojan-activity;sid:84758297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.226.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895196/; classtype:trojan-activity;sid:84758296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.226.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895195/; classtype:trojan-activity;sid:84758295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.84.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895194/; classtype:trojan-activity;sid:84758294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.238.174"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895193/; classtype:trojan-activity;sid:84758293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.156.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895192/; classtype:trojan-activity;sid:84758292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.250.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895191/; classtype:trojan-activity;sid:84758291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"45.88.186.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895190/; classtype:trojan-activity;sid:84758290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"45.88.186.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895189/; classtype:trojan-activity;sid:84758289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_666aae9f729836c3.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895188/; classtype:trojan-activity;sid:84758288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5abf1a9afc412207.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895187/; classtype:trojan-activity;sid:84758287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.112.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895186/; classtype:trojan-activity;sid:84758286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.138.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895185/; classtype:trojan-activity;sid:84758285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.123.98.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895184/; classtype:trojan-activity;sid:84758284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.155.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895183/; classtype:trojan-activity;sid:84758283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.55.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895182/; classtype:trojan-activity;sid:84758282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.210.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895181/; classtype:trojan-activity;sid:84758281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.2.103"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895180/; classtype:trojan-activity;sid:84758280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.26.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895179/; classtype:trojan-activity;sid:84758279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.123.98.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895178/; classtype:trojan-activity;sid:84758278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_4a2298dc2ab315c6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895177/; classtype:trojan-activity;sid:84758277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.138.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895176/; classtype:trojan-activity;sid:84758276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.235.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895175/; classtype:trojan-activity;sid:84758275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.26.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895174/; classtype:trojan-activity;sid:84758274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.135.159.59"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895173/; classtype:trojan-activity;sid:84758273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.245.0.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895172/; classtype:trojan-activity;sid:84758272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.155.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895171/; classtype:trojan-activity;sid:84758271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.12.203"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895170/; classtype:trojan-activity;sid:84758270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.139.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895169/; classtype:trojan-activity;sid:84758269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.148.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895167/; classtype:trojan-activity;sid:84758267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.31.228.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895168/; classtype:trojan-activity;sid:84758268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.205.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895166/; classtype:trojan-activity;sid:84758266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.0.103.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895165/; classtype:trojan-activity;sid:84758265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.0.103.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895164/; classtype:trojan-activity;sid:84758264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.25.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895163/; classtype:trojan-activity;sid:84758263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.25.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895162/; classtype:trojan-activity;sid:84758262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.76.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895161/; classtype:trojan-activity;sid:84758261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.239.251.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895160/; classtype:trojan-activity;sid:84758260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.252.199.194"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895159/; classtype:trojan-activity;sid:84758259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.129.159"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895158/; classtype:trojan-activity;sid:84758258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.250.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895155/; classtype:trojan-activity;sid:84758255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.161.116.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895156/; classtype:trojan-activity;sid:84758256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.188.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895157/; classtype:trojan-activity;sid:84758257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.95.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895133/; classtype:trojan-activity;sid:84758233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.231.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895134/; classtype:trojan-activity;sid:84758234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.202.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895135/; classtype:trojan-activity;sid:84758235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.156.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895136/; classtype:trojan-activity;sid:84758236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.102.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895137/; classtype:trojan-activity;sid:84758237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.204.192.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895138/; classtype:trojan-activity;sid:84758238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.74.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895139/; classtype:trojan-activity;sid:84758239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.99.197.248"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895140/; classtype:trojan-activity;sid:84758240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.38.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895141/; classtype:trojan-activity;sid:84758241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.129.131.244"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895142/; classtype:trojan-activity;sid:84758242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.246.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895143/; classtype:trojan-activity;sid:84758243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.146.185.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895144/; classtype:trojan-activity;sid:84758244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.10.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895145/; classtype:trojan-activity;sid:84758245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895146/; classtype:trojan-activity;sid:84758246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.9.88"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895147/; classtype:trojan-activity;sid:84758247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.189.186.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895148/; classtype:trojan-activity;sid:84758248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/amd64"; depth:8; endswith; nocase; http.host; content:"151.241.154.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895149/; classtype:trojan-activity;sid:84758249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/linux"; depth:8; endswith; nocase; http.host; content:"151.241.154.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895150/; classtype:trojan-activity;sid:84758250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.142.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895151/; classtype:trojan-activity;sid:84758251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/kswpad"; depth:9; endswith; nocase; http.host; content:"151.241.154.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895152/; classtype:trojan-activity;sid:84758252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.95.23.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895153/; classtype:trojan-activity;sid:84758253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.230.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895154/; classtype:trojan-activity;sid:84758254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"118.178.144.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895123/; classtype:trojan-activity;sid:84758223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.135.114"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895124/; classtype:trojan-activity;sid:84758224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.239.99.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895125/; classtype:trojan-activity;sid:84758225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.72.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895126/; classtype:trojan-activity;sid:84758226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.118.72.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895127/; classtype:trojan-activity;sid:84758227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.122.205"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895128/; classtype:trojan-activity;sid:84758228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.0.146"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895129/; classtype:trojan-activity;sid:84758229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.202.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895130/; classtype:trojan-activity;sid:84758230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.52.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895131/; classtype:trojan-activity;sid:84758231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"185.248.14.255"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895132/; classtype:trojan-activity;sid:84758232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.227.225.67"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895122/; classtype:trojan-activity;sid:84758222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/kal64"; depth:8; endswith; nocase; http.host; content:"151.241.154.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895121/; classtype:trojan-activity;sid:84758221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.211.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895117/; classtype:trojan-activity;sid:84758217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.42.71.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895118/; classtype:trojan-activity;sid:84758218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.95.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895119/; classtype:trojan-activity;sid:84758219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.12.203"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895120/; classtype:trojan-activity;sid:84758220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.31.188.203"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895099/; classtype:trojan-activity;sid:84758199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.146.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895100/; classtype:trojan-activity;sid:84758200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.120.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895101/; classtype:trojan-activity;sid:84758201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"88.84.222.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895102/; classtype:trojan-activity;sid:84758202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.102.34"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895103/; classtype:trojan-activity;sid:84758203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"202.107.5.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895104/; classtype:trojan-activity;sid:84758204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.67.242"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895105/; classtype:trojan-activity;sid:84758205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.88.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895106/; classtype:trojan-activity;sid:84758206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"223.151.76.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895107/; classtype:trojan-activity;sid:84758207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.69.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895108/; classtype:trojan-activity;sid:84758208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.164.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895109/; classtype:trojan-activity;sid:84758209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.125.139"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895110/; classtype:trojan-activity;sid:84758210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.22.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895111/; classtype:trojan-activity;sid:84758211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"38.56.21.66"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895112/; classtype:trojan-activity;sid:84758212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.111.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895113/; classtype:trojan-activity;sid:84758213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.93.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895114/; classtype:trojan-activity;sid:84758214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.238.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895115/; classtype:trojan-activity;sid:84758215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.104.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895116/; classtype:trojan-activity;sid:84758216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.114.247"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895092/; classtype:trojan-activity;sid:84758192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.53.10.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895093/; classtype:trojan-activity;sid:84758193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.100.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895094/; classtype:trojan-activity;sid:84758194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.115.235.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895095/; classtype:trojan-activity;sid:84758195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.244.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895096/; classtype:trojan-activity;sid:84758196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.54.83.67"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895097/; classtype:trojan-activity;sid:84758197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.14.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895098/; classtype:trojan-activity;sid:84758198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.26.58"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895091/; classtype:trojan-activity;sid:84758191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.53.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895090/; classtype:trojan-activity;sid:84758190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.76.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895089/; classtype:trojan-activity;sid:84758189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.53.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895088/; classtype:trojan-activity;sid:84758188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.236.44.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895087/; classtype:trojan-activity;sid:84758187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.126.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895086/; classtype:trojan-activity;sid:84758186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.196.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895085/; classtype:trojan-activity;sid:84758185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.126.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895084/; classtype:trojan-activity;sid:84758184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.19.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895083/; classtype:trojan-activity;sid:84758183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.242.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895082/; classtype:trojan-activity;sid:84758182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.196.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895081/; classtype:trojan-activity;sid:84758181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.142.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895080/; classtype:trojan-activity;sid:84758180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.172.186"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895079/; classtype:trojan-activity;sid:84758179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.98.79"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895078/; classtype:trojan-activity;sid:84758178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.239.99.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895077/; classtype:trojan-activity;sid:84758177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.70.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895076/; classtype:trojan-activity;sid:84758176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.231.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895075/; classtype:trojan-activity;sid:84758175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.204.192.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895070/; classtype:trojan-activity;sid:84758170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.246.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895071/; classtype:trojan-activity;sid:84758171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.9.88"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895072/; classtype:trojan-activity;sid:84758172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.251.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895073/; classtype:trojan-activity;sid:84758173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.53.10.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895074/; classtype:trojan-activity;sid:84758174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.134.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895065/; classtype:trojan-activity;sid:84758165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.156.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895066/; classtype:trojan-activity;sid:84758166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.211.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895067/; classtype:trojan-activity;sid:84758167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.176.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895068/; classtype:trojan-activity;sid:84758168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.163.107.242"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895069/; classtype:trojan-activity;sid:84758169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.235.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895064/; classtype:trojan-activity;sid:84758164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.39.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895061/; classtype:trojan-activity;sid:84758161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.93.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895062/; classtype:trojan-activity;sid:84758162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.238.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895063/; classtype:trojan-activity;sid:84758163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.104.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895040/; classtype:trojan-activity;sid:84758140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.176.248.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895041/; classtype:trojan-activity;sid:84758141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.118.72.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895042/; classtype:trojan-activity;sid:84758142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.72.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895043/; classtype:trojan-activity;sid:84758143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.183.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895044/; classtype:trojan-activity;sid:84758144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.101.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895045/; classtype:trojan-activity;sid:84758145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.81.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895046/; classtype:trojan-activity;sid:84758146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.238.129.159"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895047/; classtype:trojan-activity;sid:84758147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.174.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895048/; classtype:trojan-activity;sid:84758148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.151.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895049/; classtype:trojan-activity;sid:84758149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.69.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895050/; classtype:trojan-activity;sid:84758150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.101.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895051/; classtype:trojan-activity;sid:84758151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.95.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895052/; classtype:trojan-activity;sid:84758152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.189.186.105"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895053/; classtype:trojan-activity;sid:84758153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.88.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895054/; classtype:trojan-activity;sid:84758154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.235.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895055/; classtype:trojan-activity;sid:84758155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.122.205"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895056/; classtype:trojan-activity;sid:84758156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.52.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895057/; classtype:trojan-activity;sid:84758157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.14.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895058/; classtype:trojan-activity;sid:84758158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.228.18"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895059/; classtype:trojan-activity;sid:84758159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.231.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895060/; classtype:trojan-activity;sid:84758160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.54.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895029/; classtype:trojan-activity;sid:84758129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.42.71.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895030/; classtype:trojan-activity;sid:84758130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.152.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895031/; classtype:trojan-activity;sid:84758131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.202.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895032/; classtype:trojan-activity;sid:84758132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.100.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895033/; classtype:trojan-activity;sid:84758133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.244.31"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895034/; classtype:trojan-activity;sid:84758134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.228.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895035/; classtype:trojan-activity;sid:84758135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.152.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895036/; classtype:trojan-activity;sid:84758136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.250.52"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895037/; classtype:trojan-activity;sid:84758137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.125.23.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895038/; classtype:trojan-activity;sid:84758138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.120.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895039/; classtype:trojan-activity;sid:84758139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.166.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895027/; classtype:trojan-activity;sid:84758127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.248.14.255"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895028/; classtype:trojan-activity;sid:84758128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.10.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895026/; classtype:trojan-activity;sid:84758126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.208.179.252"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895025/; classtype:trojan-activity;sid:84758125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.185.88"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895013/; classtype:trojan-activity;sid:84758113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.107.5.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895014/; classtype:trojan-activity;sid:84758114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.102.34"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895015/; classtype:trojan-activity;sid:84758115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.0.146"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895016/; classtype:trojan-activity;sid:84758116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.104.239"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895017/; classtype:trojan-activity;sid:84758117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.111.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895018/; classtype:trojan-activity;sid:84758118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.95.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895019/; classtype:trojan-activity;sid:84758119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.112.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895020/; classtype:trojan-activity;sid:84758120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.18.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895021/; classtype:trojan-activity;sid:84758121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.131.244"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895022/; classtype:trojan-activity;sid:84758122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.232.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895023/; classtype:trojan-activity;sid:84758123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.231.142.133"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895024/; classtype:trojan-activity;sid:84758124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.3.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895006/; classtype:trojan-activity;sid:84758106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.120.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895007/; classtype:trojan-activity;sid:84758107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.93.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895008/; classtype:trojan-activity;sid:84758108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.228.109.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895009/; classtype:trojan-activity;sid:84758109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.42.243.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895010/; classtype:trojan-activity;sid:84758110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.54.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895011/; classtype:trojan-activity;sid:84758111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.151.76.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895012/; classtype:trojan-activity;sid:84758112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.226.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895005/; classtype:trojan-activity;sid:84758105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.241.210.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895004/; classtype:trojan-activity;sid:84758104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.88.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895003/; classtype:trojan-activity;sid:84758103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milan.x86"; depth:10; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895001/; classtype:trojan-activity;sid:84758101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milan.armv7l"; depth:13; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895002/; classtype:trojan-activity;sid:84758102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milan.mipsel"; depth:13; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894997/; classtype:trojan-activity;sid:84758097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milan.armv6l"; depth:13; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894998/; classtype:trojan-activity;sid:84758098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milan.armv5l"; depth:13; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894999/; classtype:trojan-activity;sid:84758099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milan.aarch64"; depth:14; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3895000/; classtype:trojan-activity;sid:84758100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.142.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894996/; classtype:trojan-activity;sid:84758096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.24.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894995/; classtype:trojan-activity;sid:84758095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.241.210.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894994/; classtype:trojan-activity;sid:84758094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.88.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894993/; classtype:trojan-activity;sid:84758093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.42.91.193"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894992/; classtype:trojan-activity;sid:84758092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.83.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894991/; classtype:trojan-activity;sid:84758091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.194.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894990/; classtype:trojan-activity;sid:84758090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.83.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894989/; classtype:trojan-activity;sid:84758089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.42.91.193"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894988/; classtype:trojan-activity;sid:84758088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.4.67.131"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894987/; classtype:trojan-activity;sid:84758087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.194.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894986/; classtype:trojan-activity;sid:84758086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.231.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894985/; classtype:trojan-activity;sid:84758085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"160.30.142.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894984/; classtype:trojan-activity;sid:84758084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.123.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894983/; classtype:trojan-activity;sid:84758083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.135.114"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894982/; classtype:trojan-activity;sid:84758082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"108.170.136.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894981/; classtype:trojan-activity;sid:84758081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.123.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894980/; classtype:trojan-activity;sid:84758080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"160.30.142.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894979/; classtype:trojan-activity;sid:84758079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.172.49.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894978/; classtype:trojan-activity;sid:84758078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.14.66"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894977/; classtype:trojan-activity;sid:84758077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader.sh"; depth:10; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894976/; classtype:trojan-activity;sid:84758076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.riscv32"; depth:21; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894975/; classtype:trojan-activity;sid:84758075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"162.249.125.141"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894961/; classtype:trojan-activity;sid:84758061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.sh4"; depth:17; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894962/; classtype:trojan-activity;sid:84758062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.powerpc"; depth:21; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894963/; classtype:trojan-activity;sid:84758063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.csky"; depth:18; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894964/; classtype:trojan-activity;sid:84758064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.armv7l"; depth:20; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894965/; classtype:trojan-activity;sid:84758065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.i586"; depth:18; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894966/; classtype:trojan-activity;sid:84758066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.i486"; depth:18; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894967/; classtype:trojan-activity;sid:84758067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.riscv64"; depth:21; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894968/; classtype:trojan-activity;sid:84758068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.mips"; depth:18; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894969/; classtype:trojan-activity;sid:84758069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.aarch64"; depth:21; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894970/; classtype:trojan-activity;sid:84758070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.x86_64"; depth:20; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894971/; classtype:trojan-activity;sid:84758071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.i686"; depth:18; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894972/; classtype:trojan-activity;sid:84758072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.armv5l"; depth:20; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894973/; classtype:trojan-activity;sid:84758073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.armv6l"; depth:20; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894974/; classtype:trojan-activity;sid:84758074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.m68k"; depth:18; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894959/; classtype:trojan-activity;sid:84758059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.powerpc-440fp"; depth:27; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894960/; classtype:trojan-activity;sid:84758060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.arc"; depth:17; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894956/; classtype:trojan-activity;sid:84758056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.mipsel"; depth:20; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894957/; classtype:trojan-activity;sid:84758057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.armv4l"; depth:20; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894958/; classtype:trojan-activity;sid:84758058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/65a935"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894954/; classtype:trojan-activity;sid:84758054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f4dcdb"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894955/; classtype:trojan-activity;sid:84758055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/230da6"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894944/; classtype:trojan-activity;sid:84758044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5c3fa5"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894945/; classtype:trojan-activity;sid:84758045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/543bc8"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894946/; classtype:trojan-activity;sid:84758046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cc86cd"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894947/; classtype:trojan-activity;sid:84758047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/79d49a"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894948/; classtype:trojan-activity;sid:84758048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70184d"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894949/; classtype:trojan-activity;sid:84758049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/479377"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894950/; classtype:trojan-activity;sid:84758050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3c21f1"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894951/; classtype:trojan-activity;sid:84758051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d0cde1"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894952/; classtype:trojan-activity;sid:84758052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5b6509"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894953/; classtype:trojan-activity;sid:84758053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.147.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894943/; classtype:trojan-activity;sid:84758043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.185.64.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894942/; classtype:trojan-activity;sid:84758042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wgt.bin"; depth:8; endswith; nocase; http.host; content:"mobilab.by"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894941/; classtype:trojan-activity;sid:84758041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig_x64"; depth:10; endswith; nocase; http.host; content:"94.154.43.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894940/; classtype:trojan-activity;sid:84758040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmr_miner_x64"; depth:14; endswith; nocase; http.host; content:"94.154.43.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894939/; classtype:trojan-activity;sid:84758039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_9334a93c0b994d73.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894935/; classtype:trojan-activity;sid:84758035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_fbb6760870c8b3a9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894936/; classtype:trojan-activity;sid:84758036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_141186422b9db92a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894937/; classtype:trojan-activity;sid:84758037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iot"; depth:4; endswith; nocase; http.host; content:"fastdex.myddns.me"; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894938/; classtype:trojan-activity;sid:84758038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milan.armv7l"; depth:13; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894934/; classtype:trojan-activity;sid:84758034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.22.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894933/; classtype:trojan-activity;sid:84758033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.185.64.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894932/; classtype:trojan-activity;sid:84758032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.19.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894931/; classtype:trojan-activity;sid:84758031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.243.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894930/; classtype:trojan-activity;sid:84758030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.25.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894929/; classtype:trojan-activity;sid:84758029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.243.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894928/; classtype:trojan-activity;sid:84758028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.19.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894927/; classtype:trojan-activity;sid:84758027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.248.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894926/; classtype:trojan-activity;sid:84758026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.5.87.64"; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894925/; classtype:trojan-activity;sid:84758025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.120.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894924/; classtype:trojan-activity;sid:84758024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.240.8.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894923/; classtype:trojan-activity;sid:84758023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.243.251"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894922/; classtype:trojan-activity;sid:84758022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.53.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894921/; classtype:trojan-activity;sid:84758021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.122.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894920/; classtype:trojan-activity;sid:84758020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"171.244.44.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894919/; classtype:trojan-activity;sid:84758019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.2.246"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894918/; classtype:trojan-activity;sid:84758018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.192.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894917/; classtype:trojan-activity;sid:84758017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.230.101.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894916/; classtype:trojan-activity;sid:84758016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.2.246"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894915/; classtype:trojan-activity;sid:84758015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.188.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894914/; classtype:trojan-activity;sid:84758014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.164.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894913/; classtype:trojan-activity;sid:84758013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.82.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894912/; classtype:trojan-activity;sid:84758012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.27.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894911/; classtype:trojan-activity;sid:84758011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.49.204"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894910/; classtype:trojan-activity;sid:84758010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.82.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894909/; classtype:trojan-activity;sid:84758009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.76.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894908/; classtype:trojan-activity;sid:84758008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.86.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894907/; classtype:trojan-activity;sid:84758007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.37.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894906/; classtype:trojan-activity;sid:84758006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.164.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894905/; classtype:trojan-activity;sid:84758005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.86.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894904/; classtype:trojan-activity;sid:84758004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.245.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894903/; classtype:trojan-activity;sid:84758003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.245.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894902/; classtype:trojan-activity;sid:84758002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.166.78.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894901/; classtype:trojan-activity;sid:84758001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.47.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894900/; classtype:trojan-activity;sid:84758000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.220.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894899/; classtype:trojan-activity;sid:84757999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.164.213"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894898/; classtype:trojan-activity;sid:84757998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.187.32.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894897/; classtype:trojan-activity;sid:84757997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.166.78.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894896/; classtype:trojan-activity;sid:84757996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.128.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894895/; classtype:trojan-activity;sid:84757995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.96.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894894/; classtype:trojan-activity;sid:84757994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmr_miner_arm64"; depth:16; endswith; nocase; http.host; content:"94.154.43.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894893/; classtype:trojan-activity;sid:84757993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.54.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894892/; classtype:trojan-activity;sid:84757992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.172.49.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894891/; classtype:trojan-activity;sid:84757991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"85.15.80.74"; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894890/; classtype:trojan-activity;sid:84757990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.116.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894889/; classtype:trojan-activity;sid:84757989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.120.96.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894888/; classtype:trojan-activity;sid:84757988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.208.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894887/; classtype:trojan-activity;sid:84757987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.154.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894886/; classtype:trojan-activity;sid:84757986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.250.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894885/; classtype:trojan-activity;sid:84757985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/mkm65cf6qnqeovw9.exe"; depth:54; endswith; nocase; http.host; content:"192.162.199.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894884/; classtype:trojan-activity;sid:84757984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/6eq5gvofrvnmci54.exe"; depth:54; endswith; nocase; http.host; content:"192.162.199.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894883/; classtype:trojan-activity;sid:84757983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/9z7bgnrgpgs8czv7.exe"; depth:54; endswith; nocase; http.host; content:"192.162.199.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894881/; classtype:trojan-activity;sid:84757981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/gm9anpouznkx8zhj.exe"; depth:54; endswith; nocase; http.host; content:"192.162.199.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894882/; classtype:trojan-activity;sid:84757982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.232.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894880/; classtype:trojan-activity;sid:84757980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.156.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894879/; classtype:trojan-activity;sid:84757979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.232.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894878/; classtype:trojan-activity;sid:84757978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.20.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894877/; classtype:trojan-activity;sid:84757977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.129.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894876/; classtype:trojan-activity;sid:84757976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.168.178"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894875/; classtype:trojan-activity;sid:84757975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.20.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894874/; classtype:trojan-activity;sid:84757974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.152.244"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894873/; classtype:trojan-activity;sid:84757973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.22.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894872/; classtype:trojan-activity;sid:84757972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.129.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894871/; classtype:trojan-activity;sid:84757971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.60.222.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894870/; classtype:trojan-activity;sid:84757970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.59.4.167"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894868/; classtype:trojan-activity;sid:84757968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.59.4.167"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894869/; classtype:trojan-activity;sid:84757969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.232.75.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894867/; classtype:trojan-activity;sid:84757967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.101.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894866/; classtype:trojan-activity;sid:84757966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.93.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894863/; classtype:trojan-activity;sid:84757963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.135.159.59"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894864/; classtype:trojan-activity;sid:84757964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.234.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894865/; classtype:trojan-activity;sid:84757965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.205.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894860/; classtype:trojan-activity;sid:84757960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.146.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894861/; classtype:trojan-activity;sid:84757961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.93.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894862/; classtype:trojan-activity;sid:84757962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.101.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894859/; classtype:trojan-activity;sid:84757959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.71.40"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894858/; classtype:trojan-activity;sid:84757958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.205.153"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894857/; classtype:trojan-activity;sid:84757957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.27.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894856/; classtype:trojan-activity;sid:84757956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.24.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894855/; classtype:trojan-activity;sid:84757955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.167.175.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894854/; classtype:trojan-activity;sid:84757954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.101.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894853/; classtype:trojan-activity;sid:84757953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.235.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894852/; classtype:trojan-activity;sid:84757952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.241.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894851/; classtype:trojan-activity;sid:84757951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"193.25.217.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894850/; classtype:trojan-activity;sid:84757950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.76.96"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894849/; classtype:trojan-activity;sid:84757949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.255.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894848/; classtype:trojan-activity;sid:84757948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.151.237"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894847/; classtype:trojan-activity;sid:84757947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"1.61.151.115"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894846/; classtype:trojan-activity;sid:84757946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.129.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894845/; classtype:trojan-activity;sid:84757945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.7.222.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894844/; classtype:trojan-activity;sid:84757944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"185.39.181.103"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894843/; classtype:trojan-activity;sid:84757943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.191.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894842/; classtype:trojan-activity;sid:84757942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.129.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894841/; classtype:trojan-activity;sid:84757941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.147.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894840/; classtype:trojan-activity;sid:84757940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.206.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894839/; classtype:trojan-activity;sid:84757939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.0.61.79"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894838/; classtype:trojan-activity;sid:84757938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.246.106"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894837/; classtype:trojan-activity;sid:84757937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.77.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894836/; classtype:trojan-activity;sid:84757936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.0.61.79"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894835/; classtype:trojan-activity;sid:84757935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milan.sh"; depth:9; endswith; nocase; http.host; content:"45.196.97.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894834/; classtype:trojan-activity;sid:84757934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0fabad"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894832/; classtype:trojan-activity;sid:84757932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da7a04"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894833/; classtype:trojan-activity;sid:84757933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fc713a"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894822/; classtype:trojan-activity;sid:84757922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b22ab5"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894823/; classtype:trojan-activity;sid:84757923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/96f5c0"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894824/; classtype:trojan-activity;sid:84757924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/11c2a0"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894825/; classtype:trojan-activity;sid:84757925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0efa59"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894826/; classtype:trojan-activity;sid:84757926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/354edc"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894827/; classtype:trojan-activity;sid:84757927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23e522"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894828/; classtype:trojan-activity;sid:84757928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dd1d24"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894829/; classtype:trojan-activity;sid:84757929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5fd134"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894830/; classtype:trojan-activity;sid:84757930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20edef"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894831/; classtype:trojan-activity;sid:84757931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.246.126.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894821/; classtype:trojan-activity;sid:84757921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_78de74be0064d015.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894820/; classtype:trojan-activity;sid:84757920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7559850987/2ultuyw.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894819/; classtype:trojan-activity;sid:84757919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"88.246.126.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894818/; classtype:trojan-activity;sid:84757918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.167.160.35"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894817/; classtype:trojan-activity;sid:84757917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.148.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894816/; classtype:trojan-activity;sid:84757916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"1.70.76.156"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894815/; classtype:trojan-activity;sid:84757915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.40.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894814/; classtype:trojan-activity;sid:84757914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.75.21.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894813/; classtype:trojan-activity;sid:84757913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"1.70.76.156"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894812/; classtype:trojan-activity;sid:84757912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.40.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894811/; classtype:trojan-activity;sid:84757911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"178.75.21.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894810/; classtype:trojan-activity;sid:84757910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.193.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894809/; classtype:trojan-activity;sid:84757909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.34.56.255"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894808/; classtype:trojan-activity;sid:84757908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_9e0cffe620fa84bb.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894807/; classtype:trojan-activity;sid:84757907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qvmei/server"; depth:13; endswith; nocase; http.host; content:"temp.sh"; depth:7; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894806/; classtype:trojan-activity;sid:84757906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894804/; classtype:trojan-activity;sid:84757904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data/ip2asn-v4.tsv.gz"; depth:22; endswith; nocase; http.host; content:"iptoasn.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894805/; classtype:trojan-activity;sid:84757905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cats.sh"; depth:8; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894802/; classtype:trojan-activity;sid:84757902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/agent"; depth:15; endswith; nocase; http.host; content:"138.201.207.253"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894803/; classtype:trojan-activity;sid:84757903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.ppc"; depth:21; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894787/; classtype:trojan-activity;sid:84757887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.x86"; depth:21; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894788/; classtype:trojan-activity;sid:84757888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.mips"; depth:22; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894789/; classtype:trojan-activity;sid:84757889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arm"; depth:21; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894790/; classtype:trojan-activity;sid:84757890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arm6"; depth:22; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894791/; classtype:trojan-activity;sid:84757891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.i686"; depth:22; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894792/; classtype:trojan-activity;sid:84757892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.sh4"; depth:21; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894793/; classtype:trojan-activity;sid:84757893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.m68k"; depth:22; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894794/; classtype:trojan-activity;sid:84757894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arm7"; depth:22; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894795/; classtype:trojan-activity;sid:84757895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.mpsl"; depth:22; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894796/; classtype:trojan-activity;sid:84757896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arm5"; depth:22; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894797/; classtype:trojan-activity;sid:84757897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.spc"; depth:21; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894798/; classtype:trojan-activity;sid:84757898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.arc"; depth:21; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894799/; classtype:trojan-activity;sid:84757899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"45.130.151.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894800/; classtype:trojan-activity;sid:84757900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bachekuni/ohshit.x86_64"; depth:24; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894801/; classtype:trojan-activity;sid:84757901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cumshotnews"; depth:12; endswith; nocase; http.host; content:"166.0.192.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894785/; classtype:trojan-activity;sid:84757885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.sh"; depth:11; endswith; nocase; http.host; content:"187.77.145.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894786/; classtype:trojan-activity;sid:84757886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luba"; depth:5; endswith; nocase; http.host; content:"213.139.77.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894783/; classtype:trojan-activity;sid:84757883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.35.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894784/; classtype:trojan-activity;sid:84757884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.armv5l"; depth:20; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894780/; classtype:trojan-activity;sid:84757880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_6f3988250b2377ba.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894781/; classtype:trojan-activity;sid:84757881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"45.130.151.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894782/; classtype:trojan-activity;sid:84757882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.16.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894779/; classtype:trojan-activity;sid:84757879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.60.150"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894778/; classtype:trojan-activity;sid:84757878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.60.222.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894777/; classtype:trojan-activity;sid:84757877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/mkm65cf6qnqeovw9.exe"; depth:54; endswith; nocase; http.host; content:"193.233.75.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894776/; classtype:trojan-activity;sid:84757876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/gm9anpouznkx8zhj.exe"; depth:54; endswith; nocase; http.host; content:"193.233.75.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894775/; classtype:trojan-activity;sid:84757875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/9z7bgnrgpgs8czv7.exe"; depth:54; endswith; nocase; http.host; content:"193.233.75.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894774/; classtype:trojan-activity;sid:84757874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.171.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894773/; classtype:trojan-activity;sid:84757873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.68.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894772/; classtype:trojan-activity;sid:84757872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.26.110.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894771/; classtype:trojan-activity;sid:84757871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.234.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894770/; classtype:trojan-activity;sid:84757870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.117.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894769/; classtype:trojan-activity;sid:84757869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.234.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894768/; classtype:trojan-activity;sid:84757868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.116.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894767/; classtype:trojan-activity;sid:84757867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.229.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894766/; classtype:trojan-activity;sid:84757866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.mips"; depth:10; endswith; nocase; http.host; content:"171.244.44.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894765/; classtype:trojan-activity;sid:84757865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerv.x86_64"; depth:12; endswith; nocase; http.host; content:"171.244.44.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894764/; classtype:trojan-activity;sid:84757864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894763/; classtype:trojan-activity;sid:84757863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.201.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894762/; classtype:trojan-activity;sid:84757862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.7.53"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894761/; classtype:trojan-activity;sid:84757861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.13.233.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894760/; classtype:trojan-activity;sid:84757860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.150.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894759/; classtype:trojan-activity;sid:84757859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/digitalmccontract.com/30f92c8a298f5a70/termo%20de%20adesao-wfm0cf.zip"; depth:76; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894757/; classtype:trojan-activity;sid:84757857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/bro-pdffiller.lat/be5bed68b0a963bc/doc-qgn64o.zip"; depth:56; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894758/; classtype:trojan-activity;sid:84757858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/docusingdoc.tjspbr.com/1972e8755045de2c/docusign_pdf_-mzgg29.zip"; depth:71; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894756/; classtype:trojan-activity;sid:84757856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/std/|3f|sid=1785503832204-r5i9sqxt"; depth:35; endswith; nocase; http.host; content:"158.94.211.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894755/; classtype:trojan-activity;sid:84757855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/nf.boletos-notas.com/fcd598f9c282fd5b/nf-e_-e4wnzd.zip"; depth:61; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894754/; classtype:trojan-activity;sid:84757854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/mkt.alfatransportes.site/285d907ecc568318/chrome-0wxida.zip"; depth:66; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894752/; classtype:trojan-activity;sid:84757852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/buffet.boletos-notas.com/20841165b838087d/chrome_-n42p0v.iso"; depth:67; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894753/; classtype:trojan-activity;sid:84757853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/alfatransportes.site/0f594d8295f4f082/nfe_-bj1cx6.zip"; depth:60; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894747/; classtype:trojan-activity;sid:84757847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/nfe.boletos-notas.com/fcd598f9c282fd5b/nota_-szesaw.zip"; depth:62; endswith; nocase; http.host; content:"nfe.boletos-notas.com"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894748/; classtype:trojan-activity;sid:84757848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/783fdf63b7bcbb83/doc-b3qw6k.zip"; depth:58; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894749/; classtype:trojan-activity;sid:84757849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/documento.tjspbr.com/8fc430f0d9000733/notafiscal_-uhm3nt.zip"; depth:67; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894750/; classtype:trojan-activity;sid:84757850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/dn-pdflite.lat/de6ae97040d70645/doc-c48ttx.zip"; depth:53; endswith; nocase; http.host; content:"nf.boletos-notas.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894751/; classtype:trojan-activity;sid:84757851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.124.60"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894746/; classtype:trojan-activity;sid:84757846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.97.254.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894745/; classtype:trojan-activity;sid:84757845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/atualizaonavegador.com/0b19dac40e97b831/extension-fix-gyiudm.hta"; depth:71; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894735/; classtype:trojan-activity;sid:84757835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/xml.nfe-online.com/16d6a7a796a8b2e8/xml.-swoj4z.zip"; depth:58; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894736/; classtype:trojan-activity;sid:84757836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/nfe.boletos-notas.com/ee8bd98f70f5e846/nota_-zpvcot.zip"; depth:62; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894737/; classtype:trojan-activity;sid:84757837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdfcomprovanteacesso.online/ecc7e62d33f88e6e/file-8xov8w.zip"; depth:67; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894738/; classtype:trojan-activity;sid:84757838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/uol2.begdistribuidora.com.br/6cf6c4ab30ce1f08/nfe_-wpszyn.zip"; depth:68; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894739/; classtype:trojan-activity;sid:84757839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/doc.alfanotas.com/0dd3dee85fb33b58/nota_fiscal--g316ct.zip"; depth:65; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894740/; classtype:trojan-activity;sid:84757840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/xml.emissaofiscal.com/7c19a64ac982b7e9/nfe_xml-d8pe8e.zip"; depth:64; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894741/; classtype:trojan-activity;sid:84757841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/cvtpremiumprp.com/829c421526d79d23/file-fjbtst.zip"; depth:57; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894742/; classtype:trojan-activity;sid:84757842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/t-adobe.lat/1b34a16ec9de882b/doc-s8l35m.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894743/; classtype:trojan-activity;sid:84757843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/atualizacaosis.terramailbr.com/38436f1a5301b43a/file-0mcgy1.zip"; depth:70; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894744/; classtype:trojan-activity;sid:84757844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/milofalo.lat/3f0254db66a06970/notafiscal-u1rfjn.zip"; depth:58; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894729/; classtype:trojan-activity;sid:84757829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/0e48f6349bcd0bd7/doc-fka245.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894730/; classtype:trojan-activity;sid:84757830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/atualizaonavegador.com/0ff05b9a9880d55b/extension-fix-zn7hus.hta"; depth:71; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894731/; classtype:trojan-activity;sid:84757831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/documentos.alfatransportes.site/a077ad0026c10365/n_fiscal_-0mb558.zip"; depth:76; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894732/; classtype:trojan-activity;sid:84757832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/zf-adobe.lat/1e693801ee2cd267/doc-vooazd.zip"; depth:51; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894733/; classtype:trojan-activity;sid:84757833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/acessoprincipalconvite.com/34b6dc6109e4f634/contrato_acordo2026-c95axa.lnk"; depth:81; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894734/; classtype:trojan-activity;sid:84757834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/a.ste-pdffiller.lat/2ee833cf831a2e12/doc-sjdpwm.zip"; depth:58; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894727/; classtype:trojan-activity;sid:84757827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/xml.transalfa.online/209b9276134b25f4/xml_-4b5tlp.zip"; depth:60; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894728/; classtype:trojan-activity;sid:84757828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.53.243.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894726/; classtype:trojan-activity;sid:84757826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/03f8cfabbe9bdcee/doc-2qtlic.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894715/; classtype:trojan-activity;sid:84757815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/de7f1cdfd0a2600b/doc-0iiw0g.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894716/; classtype:trojan-activity;sid:84757816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/8260386830a6a375/doc-95ts7y.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894717/; classtype:trojan-activity;sid:84757817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/075cc4ba877f273b/doc-j0kts7.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894718/; classtype:trojan-activity;sid:84757818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/ae078b037cdd460a/doc-pr2g4x.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894719/; classtype:trojan-activity;sid:84757819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/0137adcb70b1f19d/doc-ykcqql.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894720/; classtype:trojan-activity;sid:84757820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/d5a6675f5b6a995a/doc-sag02b.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894721/; classtype:trojan-activity;sid:84757821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/5ef78cfaa472d28c/doc-vrtf20.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894722/; classtype:trojan-activity;sid:84757822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/e3453b1426b49014/doc-qekv4f.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894723/; classtype:trojan-activity;sid:84757823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/0ffddb1aa8cb5122/doc-ktf5mf.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894724/; classtype:trojan-activity;sid:84757824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/8b4479ece29243ce/doc-nrtf90.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894725/; classtype:trojan-activity;sid:84757825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/9ab4581b6699ebb7/doc-6f7fhb.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894695/; classtype:trojan-activity;sid:84757795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/0845c6ecff44e57d/doc-v6m9ai.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894696/; classtype:trojan-activity;sid:84757796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/c98dc8de7235020b/doc-v7dquy.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894697/; classtype:trojan-activity;sid:84757797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/84120ac8fbcadc0f/doc-yoy4fo.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894698/; classtype:trojan-activity;sid:84757798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/1e006bfa894b13fd/doc-09seda.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894699/; classtype:trojan-activity;sid:84757799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/01779d1417c8fe15/doc-mvf1x2.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894700/; classtype:trojan-activity;sid:84757800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/00a0ce9fa9eb75fd/doc-vxw3j8.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894701/; classtype:trojan-activity;sid:84757801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/01c89df476c11c06/doc-2ikjop.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894702/; classtype:trojan-activity;sid:84757802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/772e79841035b558/doc-g096ux.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894703/; classtype:trojan-activity;sid:84757803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/0e38a8dd795cf2d9/doc-8ou4i6.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894704/; classtype:trojan-activity;sid:84757804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/3f3a2688275698d5/doc-3vhasz.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894705/; classtype:trojan-activity;sid:84757805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/9436fbe373137500/doc-4rsl2x.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894706/; classtype:trojan-activity;sid:84757806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/36fb6b4420a2cd2f/doc-3rdw4b.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894707/; classtype:trojan-activity;sid:84757807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/3061ada4cb0c4572/doc-a4690o.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894708/; classtype:trojan-activity;sid:84757808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/ba73a102368f4f71/doc-g6pb4z.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894709/; classtype:trojan-activity;sid:84757809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/7aa9a1cf80049afd/doc-m9d8qn.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894710/; classtype:trojan-activity;sid:84757810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/96dd66acdb777562/doc-xi0kg9.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894711/; classtype:trojan-activity;sid:84757811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/fd1ecc3584e78a8d/doc-hfmruj.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894712/; classtype:trojan-activity;sid:84757812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/0f98ac7c4600e17b/doc-juezam.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894713/; classtype:trojan-activity;sid:84757813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/62c4ff2d34a5922b/doc-fhz12h.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894714/; classtype:trojan-activity;sid:84757814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.25.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894694/; classtype:trojan-activity;sid:84757794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/pdf-bro.lat/fcd598f9c282fd5b/doc-9m8org.zip"; depth:50; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894693/; classtype:trojan-activity;sid:84757793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/|3f|doc-pdracess398ik30"; depth:24; endswith; nocase; http.host; content:"pdf-bro.lat"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894692/; classtype:trojan-activity;sid:84757792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.254.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894691/; classtype:trojan-activity;sid:84757791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.53.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894690/; classtype:trojan-activity;sid:84757790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.49.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894689/; classtype:trojan-activity;sid:84757789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.53.243.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894688/; classtype:trojan-activity;sid:84757788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.49.205"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894687/; classtype:trojan-activity;sid:84757787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"175.10.48.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894686/; classtype:trojan-activity;sid:84757786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload/tadizabyazbi/97ba.sh"; depth:29; endswith; nocase; http.host; content:"94.154.43.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894682/; classtype:trojan-activity;sid:84757782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payloads/ciabins.sh"; depth:20; endswith; nocase; http.host; content:"104.129.11.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894684/; classtype:trojan-activity;sid:84757784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kworker_u8"; depth:11; endswith; nocase; http.host; content:"103.185.249.13"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894685/; classtype:trojan-activity;sid:84757785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.145.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894681/; classtype:trojan-activity;sid:84757781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.101.181.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894678/; classtype:trojan-activity;sid:84757778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.53.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894679/; classtype:trojan-activity;sid:84757779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.166.79.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894680/; classtype:trojan-activity;sid:84757780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.187.186"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894677/; classtype:trojan-activity;sid:84757777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.25.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894668/; classtype:trojan-activity;sid:84757768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.105.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894669/; classtype:trojan-activity;sid:84757769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.3.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894670/; classtype:trojan-activity;sid:84757770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.114.247"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894671/; classtype:trojan-activity;sid:84757771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.140.108"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894672/; classtype:trojan-activity;sid:84757772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.74.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894673/; classtype:trojan-activity;sid:84757773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.234.98.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894674/; classtype:trojan-activity;sid:84757774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.208.135.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894675/; classtype:trojan-activity;sid:84757775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.239.94.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894676/; classtype:trojan-activity;sid:84757776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.13.233.182"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894667/; classtype:trojan-activity;sid:84757767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"174.34.242.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894662/; classtype:trojan-activity;sid:84757762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.152.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894663/; classtype:trojan-activity;sid:84757763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.243.253.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894664/; classtype:trojan-activity;sid:84757764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.1.226.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894665/; classtype:trojan-activity;sid:84757765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"85.141.98.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894666/; classtype:trojan-activity;sid:84757766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.73.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894660/; classtype:trojan-activity;sid:84757760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.195.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894661/; classtype:trojan-activity;sid:84757761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.74.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894658/; classtype:trojan-activity;sid:84757758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.125.23.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894659/; classtype:trojan-activity;sid:84757759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"174.34.242.49"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894653/; classtype:trojan-activity;sid:84757753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.152.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894654/; classtype:trojan-activity;sid:84757754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.61.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894655/; classtype:trojan-activity;sid:84757755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.36.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894656/; classtype:trojan-activity;sid:84757756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.151.201.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894657/; classtype:trojan-activity;sid:84757757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.184.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894645/; classtype:trojan-activity;sid:84757745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.30.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894646/; classtype:trojan-activity;sid:84757746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.95.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894647/; classtype:trojan-activity;sid:84757747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.53.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894648/; classtype:trojan-activity;sid:84757748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.234.98.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894649/; classtype:trojan-activity;sid:84757749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.32.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894650/; classtype:trojan-activity;sid:84757750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.171.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894651/; classtype:trojan-activity;sid:84757751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.36.183"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894652/; classtype:trojan-activity;sid:84757752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.201.45"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894640/; classtype:trojan-activity;sid:84757740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.146.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894641/; classtype:trojan-activity;sid:84757741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.151.106.171"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894642/; classtype:trojan-activity;sid:84757742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.193.59"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894643/; classtype:trojan-activity;sid:84757743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.48.168"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894644/; classtype:trojan-activity;sid:84757744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.95.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894635/; classtype:trojan-activity;sid:84757735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.151.106.171"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894636/; classtype:trojan-activity;sid:84757736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.250.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894637/; classtype:trojan-activity;sid:84757737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.1.226.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894638/; classtype:trojan-activity;sid:84757738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.61.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894639/; classtype:trojan-activity;sid:84757739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894627/; classtype:trojan-activity;sid:84757727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.103.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894628/; classtype:trojan-activity;sid:84757728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.232.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894629/; classtype:trojan-activity;sid:84757729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.99.107"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894630/; classtype:trojan-activity;sid:84757730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.61.72"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894631/; classtype:trojan-activity;sid:84757731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.196.29.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894632/; classtype:trojan-activity;sid:84757732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.233.94.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894633/; classtype:trojan-activity;sid:84757733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.232.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894634/; classtype:trojan-activity;sid:84757734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.47.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894624/; classtype:trojan-activity;sid:84757724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.148.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894625/; classtype:trojan-activity;sid:84757725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.156.176.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894626/; classtype:trojan-activity;sid:84757726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.230.197.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894612/; classtype:trojan-activity;sid:84757712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.195.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894613/; classtype:trojan-activity;sid:84757713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.15.108"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894614/; classtype:trojan-activity;sid:84757714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.61.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894615/; classtype:trojan-activity;sid:84757715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.15.108"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894616/; classtype:trojan-activity;sid:84757716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.82.201.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894617/; classtype:trojan-activity;sid:84757717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.187.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894618/; classtype:trojan-activity;sid:84757718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.107.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894619/; classtype:trojan-activity;sid:84757719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.121.239"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894620/; classtype:trojan-activity;sid:84757720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894621/; classtype:trojan-activity;sid:84757721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.81.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894622/; classtype:trojan-activity;sid:84757722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.230.101.41"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894623/; classtype:trojan-activity;sid:84757723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.240.8.192"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894611/; classtype:trojan-activity;sid:84757711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.201.45"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894610/; classtype:trojan-activity;sid:84757710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.89.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894606/; classtype:trojan-activity;sid:84757706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.229.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894607/; classtype:trojan-activity;sid:84757707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.217.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894608/; classtype:trojan-activity;sid:84757708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.30.254"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894609/; classtype:trojan-activity;sid:84757709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.112.228"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894601/; classtype:trojan-activity;sid:84757701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.219.223.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894602/; classtype:trojan-activity;sid:84757702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.166.188.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894603/; classtype:trojan-activity;sid:84757703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.232.75.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894604/; classtype:trojan-activity;sid:84757704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.101.120"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894605/; classtype:trojan-activity;sid:84757705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.187.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894599/; classtype:trojan-activity;sid:84757699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894600/; classtype:trojan-activity;sid:84757700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.243.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894596/; classtype:trojan-activity;sid:84757696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.217.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894597/; classtype:trojan-activity;sid:84757697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.189.23"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894598/; classtype:trojan-activity;sid:84757698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"93.171.80.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894593/; classtype:trojan-activity;sid:84757693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.202.66.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894594/; classtype:trojan-activity;sid:84757694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.28.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894595/; classtype:trojan-activity;sid:84757695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.19.216.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894592/; classtype:trojan-activity;sid:84757692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.77.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894590/; classtype:trojan-activity;sid:84757690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.128.85"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894591/; classtype:trojan-activity;sid:84757691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.250.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894586/; classtype:trojan-activity;sid:84757686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.151.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894587/; classtype:trojan-activity;sid:84757687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"218.91.67.4"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894588/; classtype:trojan-activity;sid:84757688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.151.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894589/; classtype:trojan-activity;sid:84757689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.243.253.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894585/; classtype:trojan-activity;sid:84757685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.104.106"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894584/; classtype:trojan-activity;sid:84757684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.219.223.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894577/; classtype:trojan-activity;sid:84757677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.28.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894578/; classtype:trojan-activity;sid:84757678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.107.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894579/; classtype:trojan-activity;sid:84757679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.231.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894580/; classtype:trojan-activity;sid:84757680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.231.223"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894581/; classtype:trojan-activity;sid:84757681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.184.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894582/; classtype:trojan-activity;sid:84757682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.218.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894583/; classtype:trojan-activity;sid:84757683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.103.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894573/; classtype:trojan-activity;sid:84757673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894574/; classtype:trojan-activity;sid:84757674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.166.188.48"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894575/; classtype:trojan-activity;sid:84757675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.191.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894576/; classtype:trojan-activity;sid:84757676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.145.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894570/; classtype:trojan-activity;sid:84757670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.146.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894571/; classtype:trojan-activity;sid:84757671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.192.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894572/; classtype:trojan-activity;sid:84757672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.48.168"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894565/; classtype:trojan-activity;sid:84757665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.192.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894566/; classtype:trojan-activity;sid:84757666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.105.203"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894567/; classtype:trojan-activity;sid:84757667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.233.94.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894568/; classtype:trojan-activity;sid:84757668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.97.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894569/; classtype:trojan-activity;sid:84757669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.31.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894564/; classtype:trojan-activity;sid:84757664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.31.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894560/; classtype:trojan-activity;sid:84757660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.112.228"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894561/; classtype:trojan-activity;sid:84757661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.152.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894562/; classtype:trojan-activity;sid:84757662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.85.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894563/; classtype:trojan-activity;sid:84757663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.139.178.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894554/; classtype:trojan-activity;sid:84757654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.23.129.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894555/; classtype:trojan-activity;sid:84757655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.24.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894556/; classtype:trojan-activity;sid:84757656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.193.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894557/; classtype:trojan-activity;sid:84757657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.202.66.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894558/; classtype:trojan-activity;sid:84757658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.99.107"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894559/; classtype:trojan-activity;sid:84757659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.167.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894553/; classtype:trojan-activity;sid:84757653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.229.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894550/; classtype:trojan-activity;sid:84757650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.205.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894551/; classtype:trojan-activity;sid:84757651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.2.103"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894552/; classtype:trojan-activity;sid:84757652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.226.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894543/; classtype:trojan-activity;sid:84757643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.73.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894544/; classtype:trojan-activity;sid:84757644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.248.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894545/; classtype:trojan-activity;sid:84757645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.62.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894546/; classtype:trojan-activity;sid:84757646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.227.250"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894547/; classtype:trojan-activity;sid:84757647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.232.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894548/; classtype:trojan-activity;sid:84757648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.83.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894549/; classtype:trojan-activity;sid:84757649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.187.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894536/; classtype:trojan-activity;sid:84757636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.61.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894537/; classtype:trojan-activity;sid:84757637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.74.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894538/; classtype:trojan-activity;sid:84757638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.208.135.19"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894539/; classtype:trojan-activity;sid:84757639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.23.201.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894540/; classtype:trojan-activity;sid:84757640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.140.108"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894541/; classtype:trojan-activity;sid:84757641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.151.201.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894542/; classtype:trojan-activity;sid:84757642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.39.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894528/; classtype:trojan-activity;sid:84757628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"190.109.228.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894529/; classtype:trojan-activity;sid:84757629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.227.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894530/; classtype:trojan-activity;sid:84757630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.67.197"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894531/; classtype:trojan-activity;sid:84757631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.246.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894532/; classtype:trojan-activity;sid:84757632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.187.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894533/; classtype:trojan-activity;sid:84757633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.148.153.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894534/; classtype:trojan-activity;sid:84757634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.182.122.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894535/; classtype:trojan-activity;sid:84757635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.24.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894527/; classtype:trojan-activity;sid:84757627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.191.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894526/; classtype:trojan-activity;sid:84757626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.148.153.116"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894525/; classtype:trojan-activity;sid:84757625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.192.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894524/; classtype:trojan-activity;sid:84757624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.39.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894518/; classtype:trojan-activity;sid:84757618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.97.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894519/; classtype:trojan-activity;sid:84757619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.185.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894520/; classtype:trojan-activity;sid:84757620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.187.186"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894521/; classtype:trojan-activity;sid:84757621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.182.122.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894522/; classtype:trojan-activity;sid:84757622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.121.239"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894523/; classtype:trojan-activity;sid:84757623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.181.65"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894517/; classtype:trojan-activity;sid:84757617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.234.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894514/; classtype:trojan-activity;sid:84757614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.67.242"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894515/; classtype:trojan-activity;sid:84757615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.187.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894516/; classtype:trojan-activity;sid:84757616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.73.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894513/; classtype:trojan-activity;sid:84757613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.166.79.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894512/; classtype:trojan-activity;sid:84757612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.174.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894511/; classtype:trojan-activity;sid:84757611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.249.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894510/; classtype:trojan-activity;sid:84757610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.74.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894509/; classtype:trojan-activity;sid:84757609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.31.188.203"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894508/; classtype:trojan-activity;sid:84757608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.187.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894507/; classtype:trojan-activity;sid:84757607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.244.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894506/; classtype:trojan-activity;sid:84757606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.244.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894505/; classtype:trojan-activity;sid:84757605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.74.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894504/; classtype:trojan-activity;sid:84757604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.91.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894503/; classtype:trojan-activity;sid:84757603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.25.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894502/; classtype:trojan-activity;sid:84757602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.152.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894501/; classtype:trojan-activity;sid:84757601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.229.76"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894500/; classtype:trojan-activity;sid:84757600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.38.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894499/; classtype:trojan-activity;sid:84757599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.91.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894498/; classtype:trojan-activity;sid:84757598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.135.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894497/; classtype:trojan-activity;sid:84757597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.9.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894496/; classtype:trojan-activity;sid:84757596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader.exe"; depth:11; endswith; nocase; http.host; content:"192.159.99.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894495/; classtype:trojan-activity;sid:84757595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.72.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894494/; classtype:trojan-activity;sid:84757594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.229.76"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894493/; classtype:trojan-activity;sid:84757593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.152.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894492/; classtype:trojan-activity;sid:84757592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.160.208.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894491/; classtype:trojan-activity;sid:84757591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.135.228"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894490/; classtype:trojan-activity;sid:84757590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.61.72"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894489/; classtype:trojan-activity;sid:84757589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.252.127"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894488/; classtype:trojan-activity;sid:84757588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ptk.exe"; depth:8; endswith; nocase; http.host; content:"cosmeticapampa.com.ar"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894487/; classtype:trojan-activity;sid:84757587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.160.208.110"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894486/; classtype:trojan-activity;sid:84757586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"177.39.122.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894485/; classtype:trojan-activity;sid:84757585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894484/; classtype:trojan-activity;sid:84757584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.115.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894483/; classtype:trojan-activity;sid:84757583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.115.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894482/; classtype:trojan-activity;sid:84757582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.57.20.156"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894481/; classtype:trojan-activity;sid:84757581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.198.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894480/; classtype:trojan-activity;sid:84757580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.189.83"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894479/; classtype:trojan-activity;sid:84757579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4hr"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894478/; classtype:trojan-activity;sid:84757578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.16.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894477/; classtype:trojan-activity;sid:84757577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/czk"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894473/; classtype:trojan-activity;sid:84757573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v9g"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894474/; classtype:trojan-activity;sid:84757574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aaae"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894475/; classtype:trojan-activity;sid:84757575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmo"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894476/; classtype:trojan-activity;sid:84757576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.x86_64"; depth:12; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894472/; classtype:trojan-activity;sid:84757572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notepad.b64"; depth:12; endswith; nocase; http.host; content:"v-k.com.ua"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894471/; classtype:trojan-activity;sid:84757571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/verifyc.ps1"; depth:12; endswith; nocase; http.host; content:"v-k.com.ua"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894470/; classtype:trojan-activity;sid:84757570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.101.202"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894469/; classtype:trojan-activity;sid:84757569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.5.162"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894468/; classtype:trojan-activity;sid:84757568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/80/img_191526.png"; depth:18; endswith; nocase; http.host; content:"192.255.195.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894466/; classtype:trojan-activity;sid:84757566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msi_pros.png"; depth:13; endswith; nocase; http.host; content:"cloudimagehostingupdatesrealted.yzz.me"; depth:38; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894467/; classtype:trojan-activity;sid:84757567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/202607/27/h3vojwakkxjzfvt89apn/image.png"; depth:41; endswith; nocase; http.host; content:"plain-apac-prod-public.komododecks.com"; depth:38; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894465/; classtype:trojan-activity;sid:84757565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/msi_pro.png"; depth:16; endswith; nocase; http.host; content:"204.44.69.222"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894464/; classtype:trojan-activity;sid:84757564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vcapcha.ps1"; depth:12; endswith; nocase; http.host; content:"v-k.com.ua"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894463/; classtype:trojan-activity;sid:84757563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/get_verify|3f|i=20630"; depth:22; endswith; nocase; http.host; content:"casinodas.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894462/; classtype:trojan-activity;sid:84757562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"deviceauth-code.us.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894461/; classtype:trojan-activity;sid:84757561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.53.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894460/; classtype:trojan-activity;sid:84757560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.73.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894459/; classtype:trojan-activity;sid:84757559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.101.202"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894458/; classtype:trojan-activity;sid:84757558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.10.5.162"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894457/; classtype:trojan-activity;sid:84757557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.32.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894456/; classtype:trojan-activity;sid:84757556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.83.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894455/; classtype:trojan-activity;sid:84757555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.15.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894454/; classtype:trojan-activity;sid:84757554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.188.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894453/; classtype:trojan-activity;sid:84757553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.32.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894452/; classtype:trojan-activity;sid:84757552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/all.sh"; depth:7; endswith; nocase; http.host; content:"156.226.174.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894451/; classtype:trojan-activity;sid:84757551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nova.sh"; depth:8; endswith; nocase; http.host; content:"hehe.dstat.tech"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894450/; classtype:trojan-activity;sid:84757550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.159.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894449/; classtype:trojan-activity;sid:84757549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.188.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894448/; classtype:trojan-activity;sid:84757548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.198.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894447/; classtype:trojan-activity;sid:84757547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.180.159.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894446/; classtype:trojan-activity;sid:84757546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"90.228.239.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894445/; classtype:trojan-activity;sid:84757545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.15.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894444/; classtype:trojan-activity;sid:84757544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.8.31"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894443/; classtype:trojan-activity;sid:84757543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.158.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894442/; classtype:trojan-activity;sid:84757542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"90.228.239.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894441/; classtype:trojan-activity;sid:84757541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.236.100.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894440/; classtype:trojan-activity;sid:84757540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.200.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894439/; classtype:trojan-activity;sid:84757539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.81.22.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894437/; classtype:trojan-activity;sid:84757537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.15.134"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894438/; classtype:trojan-activity;sid:84757538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.200.244"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894436/; classtype:trojan-activity;sid:84757536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.8.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894435/; classtype:trojan-activity;sid:84757535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.14.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894434/; classtype:trojan-activity;sid:84757534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.236.100.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894433/; classtype:trojan-activity;sid:84757533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.8.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894432/; classtype:trojan-activity;sid:84757532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.72.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894431/; classtype:trojan-activity;sid:84757531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.133.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894430/; classtype:trojan-activity;sid:84757530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.87.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894429/; classtype:trojan-activity;sid:84757529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.1.140"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894428/; classtype:trojan-activity;sid:84757528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.133.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894427/; classtype:trojan-activity;sid:84757527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.191.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894426/; classtype:trojan-activity;sid:84757526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.229.56"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894425/; classtype:trojan-activity;sid:84757525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.159.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894424/; classtype:trojan-activity;sid:84757524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.87.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894423/; classtype:trojan-activity;sid:84757523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.64.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894422/; classtype:trojan-activity;sid:84757522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.79.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894421/; classtype:trojan-activity;sid:84757521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.126.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894420/; classtype:trojan-activity;sid:84757520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.7.7"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894419/; classtype:trojan-activity;sid:84757519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.30.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894418/; classtype:trojan-activity;sid:84757518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.228.159.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894417/; classtype:trojan-activity;sid:84757517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.79.35"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894416/; classtype:trojan-activity;sid:84757516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.152.179"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894415/; classtype:trojan-activity;sid:84757515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.125.139"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894414/; classtype:trojan-activity;sid:84757514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.194.19.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894413/; classtype:trojan-activity;sid:84757513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.210.165.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894412/; classtype:trojan-activity;sid:84757512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.64.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894411/; classtype:trojan-activity;sid:84757511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.30.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894410/; classtype:trojan-activity;sid:84757510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.149.25"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894409/; classtype:trojan-activity;sid:84757509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.152.179"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894408/; classtype:trojan-activity;sid:84757508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.157.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894407/; classtype:trojan-activity;sid:84757507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.79.8.107"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894406/; classtype:trojan-activity;sid:84757506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.234.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894405/; classtype:trojan-activity;sid:84757505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.213.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894404/; classtype:trojan-activity;sid:84757504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.79.8.107"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894403/; classtype:trojan-activity;sid:84757503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.126.249"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894402/; classtype:trojan-activity;sid:84757502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"193.163.187.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894401/; classtype:trojan-activity;sid:84757501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.167.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894400/; classtype:trojan-activity;sid:84757500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.73.178.223"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894399/; classtype:trojan-activity;sid:84757499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.42.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894398/; classtype:trojan-activity;sid:84757498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.80.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894397/; classtype:trojan-activity;sid:84757497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.16.174"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894396/; classtype:trojan-activity;sid:84757496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.236.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894395/; classtype:trojan-activity;sid:84757495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.80.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894394/; classtype:trojan-activity;sid:84757494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.60.210.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894393/; classtype:trojan-activity;sid:84757493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.236.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894392/; classtype:trojan-activity;sid:84757492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.202.91.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894391/; classtype:trojan-activity;sid:84757491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.7.137.238"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894390/; classtype:trojan-activity;sid:84757490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.18.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894389/; classtype:trojan-activity;sid:84757489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.7.137.238"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894388/; classtype:trojan-activity;sid:84757488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.189.83"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894387/; classtype:trojan-activity;sid:84757487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.229.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894385/; classtype:trojan-activity;sid:84757485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.18.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894386/; classtype:trojan-activity;sid:84757486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.18.10.89"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894384/; classtype:trojan-activity;sid:84757484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.55.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894383/; classtype:trojan-activity;sid:84757483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.229.33"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894382/; classtype:trojan-activity;sid:84757482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.89.186"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894381/; classtype:trojan-activity;sid:84757481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.55.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894380/; classtype:trojan-activity;sid:84757480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.119.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894379/; classtype:trojan-activity;sid:84757479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.118.247.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894378/; classtype:trojan-activity;sid:84757478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.89.186"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894377/; classtype:trojan-activity;sid:84757477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.92.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894376/; classtype:trojan-activity;sid:84757476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.94.251"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894375/; classtype:trojan-activity;sid:84757475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.94.251"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894374/; classtype:trojan-activity;sid:84757474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.57.144"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894373/; classtype:trojan-activity;sid:84757473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.199.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894372/; classtype:trojan-activity;sid:84757472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.167.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894371/; classtype:trojan-activity;sid:84757471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.202.90.163"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894370/; classtype:trojan-activity;sid:84757470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.53.132.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894368/; classtype:trojan-activity;sid:84757468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.238.171.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894369/; classtype:trojan-activity;sid:84757469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbc"; depth:4; endswith; nocase; http.host; content:"104.252.175.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894367/; classtype:trojan-activity;sid:84757467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_aa7f06411e2b4e88.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894366/; classtype:trojan-activity;sid:84757466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.172.186.151"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894365/; classtype:trojan-activity;sid:84757465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.199.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894364/; classtype:trojan-activity;sid:84757464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.155.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894363/; classtype:trojan-activity;sid:84757463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ccjt"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894358/; classtype:trojan-activity;sid:84757458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fr9v"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894359/; classtype:trojan-activity;sid:84757459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tagc"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894360/; classtype:trojan-activity;sid:84757460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cxip"; depth:5; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894361/; classtype:trojan-activity;sid:84757461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kia"; depth:4; endswith; nocase; http.host; content:"129.121.114.124"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894362/; classtype:trojan-activity;sid:84757462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.252.127"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894357/; classtype:trojan-activity;sid:84757457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.143.99"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894356/; classtype:trojan-activity;sid:84757456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.45.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894355/; classtype:trojan-activity;sid:84757455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.155.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894354/; classtype:trojan-activity;sid:84757454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.18.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894353/; classtype:trojan-activity;sid:84757453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.1.224.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894352/; classtype:trojan-activity;sid:84757452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/load123.bin"; depth:12; endswith; nocase; http.host; content:"panel.b2brouter-secure.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894351/; classtype:trojan-activity;sid:84757451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doc-fac.bin"; depth:12; endswith; nocase; http.host; content:"panel.b2brouter-secure.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894350/; classtype:trojan-activity;sid:84757450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhatta.exe"; depth:11; endswith; nocase; http.host; content:"uploadloop.com"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894349/; classtype:trojan-activity;sid:84757449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.8.154"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894348/; classtype:trojan-activity;sid:84757448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.199.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894347/; classtype:trojan-activity;sid:84757447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_851477f5539ff9f4.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894346/; classtype:trojan-activity;sid:84757446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.63.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894345/; classtype:trojan-activity;sid:84757445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.172.218.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894344/; classtype:trojan-activity;sid:84757444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.1.224.23"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894343/; classtype:trojan-activity;sid:84757443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.70.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894342/; classtype:trojan-activity;sid:84757442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.61.44"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894341/; classtype:trojan-activity;sid:84757441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.63.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894340/; classtype:trojan-activity;sid:84757440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.36.48"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894339/; classtype:trojan-activity;sid:84757439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7997280925/yxhtfdg.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894338/; classtype:trojan-activity;sid:84757438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.109.219.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894337/; classtype:trojan-activity;sid:84757437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.16.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894336/; classtype:trojan-activity;sid:84757436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.70.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894335/; classtype:trojan-activity;sid:84757435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.172.218.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894334/; classtype:trojan-activity;sid:84757434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.39.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894333/; classtype:trojan-activity;sid:84757433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.115.102.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894332/; classtype:trojan-activity;sid:84757432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.39.137"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894331/; classtype:trojan-activity;sid:84757431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.185.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894330/; classtype:trojan-activity;sid:84757430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"200.115.102.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894329/; classtype:trojan-activity;sid:84757429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.3.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894328/; classtype:trojan-activity;sid:84757428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.109.227.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894327/; classtype:trojan-activity;sid:84757427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.2.81"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894326/; classtype:trojan-activity;sid:84757426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.223.131.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894325/; classtype:trojan-activity;sid:84757425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.2.81"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894324/; classtype:trojan-activity;sid:84757424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_e123b357e127708d.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894323/; classtype:trojan-activity;sid:84757423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"172.245.12.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894322/; classtype:trojan-activity;sid:84757422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"198.37.105.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894321/; classtype:trojan-activity;sid:84757421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.144.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894320/; classtype:trojan-activity;sid:84757420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.223.131.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894319/; classtype:trojan-activity;sid:84757419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.202.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894318/; classtype:trojan-activity;sid:84757418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.11.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894317/; classtype:trojan-activity;sid:84757417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.151.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894316/; classtype:trojan-activity;sid:84757416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.106.146"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894315/; classtype:trojan-activity;sid:84757415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.45.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894314/; classtype:trojan-activity;sid:84757414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.20.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894313/; classtype:trojan-activity;sid:84757413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7782139129/4u8cr3o.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894312/; classtype:trojan-activity;sid:84757412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"75.1.240.64"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894311/; classtype:trojan-activity;sid:84757411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.42.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894310/; classtype:trojan-activity;sid:84757410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.45.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894309/; classtype:trojan-activity;sid:84757409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"206.62.120.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894308/; classtype:trojan-activity;sid:84757408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"206.62.120.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894307/; classtype:trojan-activity;sid:84757407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.42.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894306/; classtype:trojan-activity;sid:84757406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.108.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894305/; classtype:trojan-activity;sid:84757405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.226.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894304/; classtype:trojan-activity;sid:84757404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.202.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894302/; classtype:trojan-activity;sid:84757402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.148.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894303/; classtype:trojan-activity;sid:84757403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.146.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894301/; classtype:trojan-activity;sid:84757401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.94.172"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894300/; classtype:trojan-activity;sid:84757400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"192.176.50.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894298/; classtype:trojan-activity;sid:84757398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894299/; classtype:trojan-activity;sid:84757399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.139.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894295/; classtype:trojan-activity;sid:84757395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.100.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894296/; classtype:trojan-activity;sid:84757396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.8.128.30"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894297/; classtype:trojan-activity;sid:84757397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"72.194.227.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894293/; classtype:trojan-activity;sid:84757393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.5.10.179"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894294/; classtype:trojan-activity;sid:84757394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.24.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894286/; classtype:trojan-activity;sid:84757386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.8.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894287/; classtype:trojan-activity;sid:84757387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.155.54"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894288/; classtype:trojan-activity;sid:84757388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.119.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894289/; classtype:trojan-activity;sid:84757389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.191.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894290/; classtype:trojan-activity;sid:84757390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.57.155"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894291/; classtype:trojan-activity;sid:84757391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.151.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894292/; classtype:trojan-activity;sid:84757392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"192.176.50.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894285/; classtype:trojan-activity;sid:84757385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.139.178.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894284/; classtype:trojan-activity;sid:84757384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.124.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894282/; classtype:trojan-activity;sid:84757382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.153.144.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894283/; classtype:trojan-activity;sid:84757383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.53.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894279/; classtype:trojan-activity;sid:84757379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.78.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894280/; classtype:trojan-activity;sid:84757380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.7.53"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894281/; classtype:trojan-activity;sid:84757381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.159.34.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894277/; classtype:trojan-activity;sid:84757377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.70.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894278/; classtype:trojan-activity;sid:84757378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.234.219.192"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894276/; classtype:trojan-activity;sid:84757376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.111.98.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894275/; classtype:trojan-activity;sid:84757375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.174.196"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894273/; classtype:trojan-activity;sid:84757373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.139.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894274/; classtype:trojan-activity;sid:84757374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.239.224.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894271/; classtype:trojan-activity;sid:84757371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.195.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894272/; classtype:trojan-activity;sid:84757372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.151.245"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894269/; classtype:trojan-activity;sid:84757369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.212.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894270/; classtype:trojan-activity;sid:84757370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.70.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894268/; classtype:trojan-activity;sid:84757368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.119.202"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894267/; classtype:trojan-activity;sid:84757367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.174.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894266/; classtype:trojan-activity;sid:84757366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.113.75.65"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894265/; classtype:trojan-activity;sid:84757365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.229.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894263/; classtype:trojan-activity;sid:84757363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.93.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894264/; classtype:trojan-activity;sid:84757364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.36.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894261/; classtype:trojan-activity;sid:84757361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.94.53"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894262/; classtype:trojan-activity;sid:84757362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.78.46.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894256/; classtype:trojan-activity;sid:84757356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.14.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894257/; classtype:trojan-activity;sid:84757357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.234.150.188"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894258/; classtype:trojan-activity;sid:84757358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.237.5.204"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894259/; classtype:trojan-activity;sid:84757359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.119.187.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894260/; classtype:trojan-activity;sid:84757360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins.sh"; depth:8; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894255/; classtype:trojan-activity;sid:84757355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.196.29.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894254/; classtype:trojan-activity;sid:84757354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.224.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894253/; classtype:trojan-activity;sid:84757353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.exe"; depth:8; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894252/; classtype:trojan-activity;sid:84757352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.191.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894251/; classtype:trojan-activity;sid:84757351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.197.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894249/; classtype:trojan-activity;sid:84757349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"223.151.74.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894250/; classtype:trojan-activity;sid:84757350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.100.14"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894247/; classtype:trojan-activity;sid:84757347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.83.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894248/; classtype:trojan-activity;sid:84757348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.147.155"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894246/; classtype:trojan-activity;sid:84757346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.36.197.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894245/; classtype:trojan-activity;sid:84757345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.174.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894244/; classtype:trojan-activity;sid:84757344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.239.148.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894243/; classtype:trojan-activity;sid:84757343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.237.5.204"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894242/; classtype:trojan-activity;sid:84757342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.41.186"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894241/; classtype:trojan-activity;sid:84757341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.89.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894240/; classtype:trojan-activity;sid:84757340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.71.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894236/; classtype:trojan-activity;sid:84757336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.119.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894237/; classtype:trojan-activity;sid:84757337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.78.46.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894238/; classtype:trojan-activity;sid:84757338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.159.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894239/; classtype:trojan-activity;sid:84757339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.209.122.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894234/; classtype:trojan-activity;sid:84757334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.94.172"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894235/; classtype:trojan-activity;sid:84757335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.234.219.192"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894233/; classtype:trojan-activity;sid:84757333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.165.172.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894231/; classtype:trojan-activity;sid:84757331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.165.172.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894232/; classtype:trojan-activity;sid:84757332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.124.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894230/; classtype:trojan-activity;sid:84757330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.109.81.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894229/; classtype:trojan-activity;sid:84757329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.193.59"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894228/; classtype:trojan-activity;sid:84757328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"218.91.67.4"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894225/; classtype:trojan-activity;sid:84757325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.14.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894226/; classtype:trojan-activity;sid:84757326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.109.228.199"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894227/; classtype:trojan-activity;sid:84757327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.71.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894223/; classtype:trojan-activity;sid:84757323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"138.252.69.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894224/; classtype:trojan-activity;sid:84757324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.153.144.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894222/; classtype:trojan-activity;sid:84757322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.224.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894221/; classtype:trojan-activity;sid:84757321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.24.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894218/; classtype:trojan-activity;sid:84757318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.5.10.179"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894219/; classtype:trojan-activity;sid:84757319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.214.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894220/; classtype:trojan-activity;sid:84757320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.237.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894217/; classtype:trojan-activity;sid:84757317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.209.122.135"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894216/; classtype:trojan-activity;sid:84757316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.170.224.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894213/; classtype:trojan-activity;sid:84757313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.186.218"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894214/; classtype:trojan-activity;sid:84757314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.161.160.164"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894215/; classtype:trojan-activity;sid:84757315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.197.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894212/; classtype:trojan-activity;sid:84757312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.119.187.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894211/; classtype:trojan-activity;sid:84757311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.159.190.99"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894210/; classtype:trojan-activity;sid:84757310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.37.212.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894209/; classtype:trojan-activity;sid:84757309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.159.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894208/; classtype:trojan-activity;sid:84757308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.93.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894206/; classtype:trojan-activity;sid:84757306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.229.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894207/; classtype:trojan-activity;sid:84757307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.38.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894205/; classtype:trojan-activity;sid:84757305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894204/; classtype:trojan-activity;sid:84757304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amd64"; depth:6; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894198/; classtype:trojan-activity;sid:84757298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894199/; classtype:trojan-activity;sid:84757299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsle"; depth:7; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894200/; classtype:trojan-activity;sid:84757300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/android_arm64"; depth:14; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894201/; classtype:trojan-activity;sid:84757301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm64"; depth:6; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894202/; classtype:trojan-activity;sid:84757302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894203/; classtype:trojan-activity;sid:84757303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894194/; classtype:trojan-activity;sid:84757294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i386"; depth:5; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894195/; classtype:trojan-activity;sid:84757295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894196/; classtype:trojan-activity;sid:84757296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"salmosnet.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894197/; classtype:trojan-activity;sid:84757297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_0607be65f0526ebe.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894193/; classtype:trojan-activity;sid:84757293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"125.45.57.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894192/; classtype:trojan-activity;sid:84757292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_7691c09246236975.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894191/; classtype:trojan-activity;sid:84757291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.100.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894190/; classtype:trojan-activity;sid:84757290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.216.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894189/; classtype:trojan-activity;sid:84757289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.36.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894188/; classtype:trojan-activity;sid:84757288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.33.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894187/; classtype:trojan-activity;sid:84757287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.14.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894186/; classtype:trojan-activity;sid:84757286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.216.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894185/; classtype:trojan-activity;sid:84757285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.253.89"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894184/; classtype:trojan-activity;sid:84757284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.33.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894183/; classtype:trojan-activity;sid:84757283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.240.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894182/; classtype:trojan-activity;sid:84757282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.87.15.172"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894181/; classtype:trojan-activity;sid:84757281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.11.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894180/; classtype:trojan-activity;sid:84757280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"106.41.44.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894179/; classtype:trojan-activity;sid:84757279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.22.251"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894178/; classtype:trojan-activity;sid:84757278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894177/; classtype:trojan-activity;sid:84757277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.64.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894176/; classtype:trojan-activity;sid:84757276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.240.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894175/; classtype:trojan-activity;sid:84757275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.181.65"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894174/; classtype:trojan-activity;sid:84757274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.184.241"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894173/; classtype:trojan-activity;sid:84757273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.103.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894172/; classtype:trojan-activity;sid:84757272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.64.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894170/; classtype:trojan-activity;sid:84757270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.11.85"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894171/; classtype:trojan-activity;sid:84757271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.220.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894169/; classtype:trojan-activity;sid:84757269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_5b2a99625685db40.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894167/; classtype:trojan-activity;sid:84757267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a9d864181ab71029.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894168/; classtype:trojan-activity;sid:84757268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.48.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894166/; classtype:trojan-activity;sid:84757266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.48.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894165/; classtype:trojan-activity;sid:84757265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.131.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894164/; classtype:trojan-activity;sid:84757264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.85.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894163/; classtype:trojan-activity;sid:84757263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.230.197.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894162/; classtype:trojan-activity;sid:84757262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.90.59"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894161/; classtype:trojan-activity;sid:84757261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.220.15"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894160/; classtype:trojan-activity;sid:84757260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.71.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894159/; classtype:trojan-activity;sid:84757259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.250.233"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894158/; classtype:trojan-activity;sid:84757258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.202.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894157/; classtype:trojan-activity;sid:84757257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.131.1"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894156/; classtype:trojan-activity;sid:84757256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.90.59"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894155/; classtype:trojan-activity;sid:84757255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.81.22.56"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894154/; classtype:trojan-activity;sid:84757254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"94.154.32.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894153/; classtype:trojan-activity;sid:84757253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"94.154.32.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894152/; classtype:trojan-activity;sid:84757252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/installer.exe"; depth:14; endswith; nocase; http.host; content:"158.94.211.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894151/; classtype:trojan-activity;sid:84757251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"2.58.56.111"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894149/; classtype:trojan-activity;sid:84757249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"2.58.56.111"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894150/; classtype:trojan-activity;sid:84757250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.29.195"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894148/; classtype:trojan-activity;sid:84757248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"203.159.90.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894147/; classtype:trojan-activity;sid:84757247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"203.159.90.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894146/; classtype:trojan-activity;sid:84757246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"45.154.98.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894144/; classtype:trojan-activity;sid:84757244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"45.154.98.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894145/; classtype:trojan-activity;sid:84757245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.153.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894143/; classtype:trojan-activity;sid:84757243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.60.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894142/; classtype:trojan-activity;sid:84757242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.6.71"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894141/; classtype:trojan-activity;sid:84757241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.60.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894140/; classtype:trojan-activity;sid:84757240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.42.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894139/; classtype:trojan-activity;sid:84757239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.153.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894138/; classtype:trojan-activity;sid:84757238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.6.71"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894137/; classtype:trojan-activity;sid:84757237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/boots%d0%b5%d1%85%d0%b5cn64.zip"; depth:40; endswith; nocase; http.host; content:"roblox-xeno.info"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894135/; classtype:trojan-activity;sid:84757235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.exe"; depth:6; endswith; nocase; http.host; content:"v2202606372363474129.happysrv.de"; depth:32; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894134/; classtype:trojan-activity;sid:84757234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.exe"; depth:6; endswith; nocase; http.host; content:"94.16.122.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894133/; classtype:trojan-activity;sid:84757233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"176.65.132.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894132/; classtype:trojan-activity;sid:84757232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.123.178.196"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894131/; classtype:trojan-activity;sid:84757231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.220.11.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894130/; classtype:trojan-activity;sid:84757230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.238.131"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894129/; classtype:trojan-activity;sid:84757229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.68.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894128/; classtype:trojan-activity;sid:84757228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.4.12"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894127/; classtype:trojan-activity;sid:84757227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.123.178.196"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894126/; classtype:trojan-activity;sid:84757226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.68.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894125/; classtype:trojan-activity;sid:84757225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.69.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894124/; classtype:trojan-activity;sid:84757224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.157.210.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894123/; classtype:trojan-activity;sid:84757223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.199.52"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894122/; classtype:trojan-activity;sid:84757222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.4.12"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894121/; classtype:trojan-activity;sid:84757221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/995a0b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894105/; classtype:trojan-activity;sid:84757205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5d7d3b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894106/; classtype:trojan-activity;sid:84757206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/13f62b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894107/; classtype:trojan-activity;sid:84757207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/76705d"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894108/; classtype:trojan-activity;sid:84757208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/94115c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894109/; classtype:trojan-activity;sid:84757209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e9cc83"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894110/; classtype:trojan-activity;sid:84757210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/53bd7e"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894111/; classtype:trojan-activity;sid:84757211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/519e48"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894112/; classtype:trojan-activity;sid:84757212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1dc272"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894113/; classtype:trojan-activity;sid:84757213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/522f30"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894114/; classtype:trojan-activity;sid:84757214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/18e6dd"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894115/; classtype:trojan-activity;sid:84757215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cdb6cf"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894116/; classtype:trojan-activity;sid:84757216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d87017"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894117/; classtype:trojan-activity;sid:84757217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7e26a6"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894118/; classtype:trojan-activity;sid:84757218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fa3fc2"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894119/; classtype:trojan-activity;sid:84757219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7e73d7"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894120/; classtype:trojan-activity;sid:84757220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a0e5aa"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894097/; classtype:trojan-activity;sid:84757197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2dde2f"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894098/; classtype:trojan-activity;sid:84757198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/62a68f"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894099/; classtype:trojan-activity;sid:84757199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/597b65"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894100/; classtype:trojan-activity;sid:84757200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/06fe0b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894101/; classtype:trojan-activity;sid:84757201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5a9b45"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894102/; classtype:trojan-activity;sid:84757202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6dfc96"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894103/; classtype:trojan-activity;sid:84757203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6d7e02"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894104/; classtype:trojan-activity;sid:84757204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/updhfjsbfs.bat"; depth:15; endswith; nocase; http.host; content:"gmbh-hunt-dividend-arena.trycloudflare.com"; depth:42; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894096/; classtype:trojan-activity;sid:84757196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"164.163.25.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894095/; classtype:trojan-activity;sid:84757195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.69.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894094/; classtype:trojan-activity;sid:84757194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.137.153.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894093/; classtype:trojan-activity;sid:84757193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"164.163.25.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894092/; classtype:trojan-activity;sid:84757192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.234.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894091/; classtype:trojan-activity;sid:84757191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.234.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894090/; classtype:trojan-activity;sid:84757190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.60.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894089/; classtype:trojan-activity;sid:84757189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.60.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894088/; classtype:trojan-activity;sid:84757188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.100.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894087/; classtype:trojan-activity;sid:84757187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"110.136.44.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894086/; classtype:trojan-activity;sid:84757186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v0/b/new-era-14dfd/o/lincoln.ps1|3f|alt=media|7c|26|7c|token=0b1e9378-0fc3-468d-9a3e-e5c215ea5f49"; depth:98; endswith; nocase; http.host; content:"firebasestorage.googleapis.com"; depth:30; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894085/; classtype:trojan-activity;sid:84757185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.84.222.217"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894084/; classtype:trojan-activity;sid:84757184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real.bot"; depth:9; endswith; nocase; http.host; content:"91.92.40.8"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894083/; classtype:trojan-activity;sid:84757183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.8.154"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894082/; classtype:trojan-activity;sid:84757182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.151.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894081/; classtype:trojan-activity;sid:84757181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.151.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894080/; classtype:trojan-activity;sid:84757180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.80.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894079/; classtype:trojan-activity;sid:84757179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/|3f|get=1"; depth:10; endswith; nocase; http.host; content:"88.212.109.208.host.secureserver.net"; depth:36; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894078/; classtype:trojan-activity;sid:84757178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/$bin"; depth:13; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894074/; classtype:trojan-activity;sid:84757174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a8d74bd52287c2ac.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894075/; classtype:trojan-activity;sid:84757175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_c166f39d565559f4.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894076/; classtype:trojan-activity;sid:84757176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_966dd80e15fd05d1.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894077/; classtype:trojan-activity;sid:84757177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.180.108.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894073/; classtype:trojan-activity;sid:84757173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.70.179.92"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894072/; classtype:trojan-activity;sid:84757172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.11.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894071/; classtype:trojan-activity;sid:84757171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.11.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894070/; classtype:trojan-activity;sid:84757170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"193.163.187.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894069/; classtype:trojan-activity;sid:84757169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.26.212.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894068/; classtype:trojan-activity;sid:84757168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.155.54"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894067/; classtype:trojan-activity;sid:84757167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.71.201.170"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894066/; classtype:trojan-activity;sid:84757166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"72.255.30.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894065/; classtype:trojan-activity;sid:84757165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.102.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894064/; classtype:trojan-activity;sid:84757164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"72.255.30.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894063/; classtype:trojan-activity;sid:84757163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.26.212.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894062/; classtype:trojan-activity;sid:84757162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.241.209.93"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894061/; classtype:trojan-activity;sid:84757161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.7.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894060/; classtype:trojan-activity;sid:84757160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.102.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894059/; classtype:trojan-activity;sid:84757159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.8.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894058/; classtype:trojan-activity;sid:84757158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.70.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894057/; classtype:trojan-activity;sid:84757157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.241.209.93"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894056/; classtype:trojan-activity;sid:84757156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.70.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894055/; classtype:trojan-activity;sid:84757155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.11.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894054/; classtype:trojan-activity;sid:84757154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.spc"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894051/; classtype:trojan-activity;sid:84757151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mpsl"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894052/; classtype:trojan-activity;sid:84757152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.ppc"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894053/; classtype:trojan-activity;sid:84757153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.mips"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894048/; classtype:trojan-activity;sid:84757148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm6"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894049/; classtype:trojan-activity;sid:84757149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894050/; classtype:trojan-activity;sid:84757150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.m68k"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894047/; classtype:trojan-activity;sid:84757147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.sh4"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894046/; classtype:trojan-activity;sid:84757146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm7"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894045/; classtype:trojan-activity;sid:84757145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/xd.arm5"; depth:10; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894044/; classtype:trojan-activity;sid:84757144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sensi.sh"; depth:9; endswith; nocase; http.host; content:"95.155.151.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894043/; classtype:trojan-activity;sid:84757143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894042/; classtype:trojan-activity;sid:84757142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.240.149.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894041/; classtype:trojan-activity;sid:84757141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.207.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894040/; classtype:trojan-activity;sid:84757140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.207.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894039/; classtype:trojan-activity;sid:84757139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.18.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894038/; classtype:trojan-activity;sid:84757138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmaarriioisectanee/mmaarriioisectanee.mips"; depth:43; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894037/; classtype:trojan-activity;sid:84757137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.31.103.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894036/; classtype:trojan-activity;sid:84757136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.154.139"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894035/; classtype:trojan-activity;sid:84757135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.14.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894034/; classtype:trojan-activity;sid:84757134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.102.203"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894033/; classtype:trojan-activity;sid:84757133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.14.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894032/; classtype:trojan-activity;sid:84757132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.59.239.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894031/; classtype:trojan-activity;sid:84757131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.154.139"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894030/; classtype:trojan-activity;sid:84757130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.143.236"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894029/; classtype:trojan-activity;sid:84757129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3bc9ccd02805e1bd.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894028/; classtype:trojan-activity;sid:84757128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.16.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894027/; classtype:trojan-activity;sid:84757127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.229.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894026/; classtype:trojan-activity;sid:84757126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.23.127.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894025/; classtype:trojan-activity;sid:84757125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.72.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894024/; classtype:trojan-activity;sid:84757124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.240.254.56"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894023/; classtype:trojan-activity;sid:84757123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.72.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894022/; classtype:trojan-activity;sid:84757122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"24.95.54.96"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894021/; classtype:trojan-activity;sid:84757121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.23.127.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894020/; classtype:trojan-activity;sid:84757120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.140.180.134"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894019/; classtype:trojan-activity;sid:84757119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"24.95.54.96"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894018/; classtype:trojan-activity;sid:84757118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.180.134"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894017/; classtype:trojan-activity;sid:84757117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.105.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894016/; classtype:trojan-activity;sid:84757116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.247.88.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894015/; classtype:trojan-activity;sid:84757115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.227.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894014/; classtype:trojan-activity;sid:84757114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.229.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894013/; classtype:trojan-activity;sid:84757113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.238.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894012/; classtype:trojan-activity;sid:84757112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.232.227.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894011/; classtype:trojan-activity;sid:84757111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.214.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894010/; classtype:trojan-activity;sid:84757110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.229.130"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894009/; classtype:trojan-activity;sid:84757109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.214.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894008/; classtype:trojan-activity;sid:84757108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"77.247.88.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894007/; classtype:trojan-activity;sid:84757107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.20.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894006/; classtype:trojan-activity;sid:84757106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.0.112"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894005/; classtype:trojan-activity;sid:84757105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.65.9"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894004/; classtype:trojan-activity;sid:84757104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"123.172.77.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894003/; classtype:trojan-activity;sid:84757103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/package.msi"; depth:12; endswith; nocase; http.host; content:"pub-5eee967508114192a40c0ca052a3bb9d.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894002/; classtype:trojan-activity;sid:84757102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kxunkw4z-u2qv2kxd-qd76zt3x-kmcbgxy3/package.msi"; depth:48; endswith; nocase; http.host; content:"89.34.90.130"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894001/; classtype:trojan-activity;sid:84757101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/verify.ps1"; depth:11; endswith; nocase; http.host; content:"45.13.186.129"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3894000/; classtype:trojan-activity;sid:84757100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ya4"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893999/; classtype:trojan-activity;sid:84757099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.29.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893998/; classtype:trojan-activity;sid:84757098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/y1v"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893997/; classtype:trojan-activity;sid:84757097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.136.44.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893996/; classtype:trojan-activity;sid:84757096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_sh4"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893987/; classtype:trojan-activity;sid:84757087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm6"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893988/; classtype:trojan-activity;sid:84757088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_ppc"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893989/; classtype:trojan-activity;sid:84757089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86"; depth:8; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893990/; classtype:trojan-activity;sid:84757090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_i686"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893991/; classtype:trojan-activity;sid:84757091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_arm5"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893992/; classtype:trojan-activity;sid:84757092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_0729_0324/real_arm"; depth:26; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893993/; classtype:trojan-activity;sid:84757093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_0729_0324/real_mips"; depth:27; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893994/; classtype:trojan-activity;sid:84757094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.253.48.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893995/; classtype:trojan-activity;sid:84757095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.i686"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893985/; classtype:trojan-activity;sid:84757085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_arm6"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893986/; classtype:trojan-activity;sid:84757086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_arm7"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893977/; classtype:trojan-activity;sid:84757077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_0729_0324/real_mipsel"; depth:29; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893978/; classtype:trojan-activity;sid:84757078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.sh4"; depth:8; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893979/; classtype:trojan-activity;sid:84757079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ssh_brute"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893980/; classtype:trojan-activity;sid:84757080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_x86"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893981/; classtype:trojan-activity;sid:84757081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.m68k"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893982/; classtype:trojan-activity;sid:84757082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_m68k"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893983/; classtype:trojan-activity;sid:84757083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_0729_0324/real_x86_64"; depth:29; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893984/; classtype:trojan-activity;sid:84757084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm7"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893975/; classtype:trojan-activity;sid:84757075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.ppc"; depth:8; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893976/; classtype:trojan-activity;sid:84757076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_0729_0324/real_arm64"; depth:28; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893974/; classtype:trojan-activity;sid:84757074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm5"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893973/; classtype:trojan-activity;sid:84757073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_spc"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893971/; classtype:trojan-activity;sid:84757071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.spc"; depth:8; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893972/; classtype:trojan-activity;sid:84757072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"138.204.196.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893970/; classtype:trojan-activity;sid:84757070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hix"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893967/; classtype:trojan-activity;sid:84757067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryb"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893968/; classtype:trojan-activity;sid:84757068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hjeg"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893969/; classtype:trojan-activity;sid:84757069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.136.44.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893966/; classtype:trojan-activity;sid:84757066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.121.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893965/; classtype:trojan-activity;sid:84757065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.0.112"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893964/; classtype:trojan-activity;sid:84757064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"138.204.196.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893963/; classtype:trojan-activity;sid:84757063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.9.222"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893962/; classtype:trojan-activity;sid:84757062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.93.219"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893961/; classtype:trojan-activity;sid:84757061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.189.99"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893960/; classtype:trojan-activity;sid:84757060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.9.222"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893959/; classtype:trojan-activity;sid:84757059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.93.219"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893958/; classtype:trojan-activity;sid:84757058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.76.155"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893957/; classtype:trojan-activity;sid:84757057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.76.155"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893956/; classtype:trojan-activity;sid:84757056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.160.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893955/; classtype:trojan-activity;sid:84757055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.176.252.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893954/; classtype:trojan-activity;sid:84757054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.163.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893953/; classtype:trojan-activity;sid:84757053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.253.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893952/; classtype:trojan-activity;sid:84757052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.64.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893951/; classtype:trojan-activity;sid:84757051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//i486"; depth:6; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893946/; classtype:trojan-activity;sid:84757046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//powerpc"; depth:9; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893947/; classtype:trojan-activity;sid:84757047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//x86_64"; depth:8; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893948/; classtype:trojan-activity;sid:84757048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//i586"; depth:6; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893949/; classtype:trojan-activity;sid:84757049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//arm6"; depth:6; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893950/; classtype:trojan-activity;sid:84757050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.154.78.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893945/; classtype:trojan-activity;sid:84757045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.163.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893944/; classtype:trojan-activity;sid:84757044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.64.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893943/; classtype:trojan-activity;sid:84757043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.151.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893942/; classtype:trojan-activity;sid:84757042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.201.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893941/; classtype:trojan-activity;sid:84757041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malw5500.msi"; depth:13; endswith; nocase; http.host; content:"104.249.10.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893940/; classtype:trojan-activity;sid:84757040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.48.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893939/; classtype:trojan-activity;sid:84757039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rvtools4.8.1.msi"; depth:17; endswith; nocase; http.host; content:"vmwrvtools.com"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893938/; classtype:trojan-activity;sid:84757038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.9.165.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893937/; classtype:trojan-activity;sid:84757037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/449ce2"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893935/; classtype:trojan-activity;sid:84757035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f3bb28"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893936/; classtype:trojan-activity;sid:84757036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4317af"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893926/; classtype:trojan-activity;sid:84757026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4404fc"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893927/; classtype:trojan-activity;sid:84757027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dc20a8"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893928/; classtype:trojan-activity;sid:84757028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12c344"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893929/; classtype:trojan-activity;sid:84757029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/76f32c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893930/; classtype:trojan-activity;sid:84757030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4a720d"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893931/; classtype:trojan-activity;sid:84757031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/32f59e"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893932/; classtype:trojan-activity;sid:84757032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/655399"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893933/; classtype:trojan-activity;sid:84757033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/75745b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893934/; classtype:trojan-activity;sid:84757034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/38e096"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893922/; classtype:trojan-activity;sid:84757022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c0v"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893923/; classtype:trojan-activity;sid:84757023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iwh"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893924/; classtype:trojan-activity;sid:84757024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phtn"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893925/; classtype:trojan-activity;sid:84757025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bslw"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893920/; classtype:trojan-activity;sid:84757020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yhy"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893921/; classtype:trojan-activity;sid:84757021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lai"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893915/; classtype:trojan-activity;sid:84757015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ouwr"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893916/; classtype:trojan-activity;sid:84757016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gtrf"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893917/; classtype:trojan-activity;sid:84757017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hfpa"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893918/; classtype:trojan-activity;sid:84757018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fgx2"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893919/; classtype:trojan-activity;sid:84757019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.121.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893914/; classtype:trojan-activity;sid:84757014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.48.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893913/; classtype:trojan-activity;sid:84757013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.115.185.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893912/; classtype:trojan-activity;sid:84757012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.242.183.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893911/; classtype:trojan-activity;sid:84757011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.45.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893910/; classtype:trojan-activity;sid:84757010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.242.183.234"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893909/; classtype:trojan-activity;sid:84757009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.29.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893908/; classtype:trojan-activity;sid:84757008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.84.79"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893907/; classtype:trojan-activity;sid:84757007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.227.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893906/; classtype:trojan-activity;sid:84757006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.100.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893905/; classtype:trojan-activity;sid:84757005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.30.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893904/; classtype:trojan-activity;sid:84757004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.20.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893903/; classtype:trojan-activity;sid:84757003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.237.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893902/; classtype:trojan-activity;sid:84757002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.148.255"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893901/; classtype:trojan-activity;sid:84757001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.20.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893900/; classtype:trojan-activity;sid:84757000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.236.46.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893899/; classtype:trojan-activity;sid:84756999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.46.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893898/; classtype:trojan-activity;sid:84756998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.140.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893897/; classtype:trojan-activity;sid:84756997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.253.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893896/; classtype:trojan-activity;sid:84756996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.107.54"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893895/; classtype:trojan-activity;sid:84756995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"193.26.115.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893894/; classtype:trojan-activity;sid:84756994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"193.26.115.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893893/; classtype:trojan-activity;sid:84756993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893892/; classtype:trojan-activity;sid:84756992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.64.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893891/; classtype:trojan-activity;sid:84756991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.220.145.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893890/; classtype:trojan-activity;sid:84756990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.64.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893889/; classtype:trojan-activity;sid:84756989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.62.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893888/; classtype:trojan-activity;sid:84756988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.140.184"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893887/; classtype:trojan-activity;sid:84756987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.107.54"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893886/; classtype:trojan-activity;sid:84756986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"203.159.90.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893885/; classtype:trojan-activity;sid:84756985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"203.159.90.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893884/; classtype:trojan-activity;sid:84756984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"2.58.56.147"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893883/; classtype:trojan-activity;sid:84756983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"2.58.56.147"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893882/; classtype:trojan-activity;sid:84756982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"45.83.28.52"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893881/; classtype:trojan-activity;sid:84756981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"45.83.28.52"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893880/; classtype:trojan-activity;sid:84756980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.220.145.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893879/; classtype:trojan-activity;sid:84756979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"78.25.170.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893878/; classtype:trojan-activity;sid:84756978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.218.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893877/; classtype:trojan-activity;sid:84756977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.57.20.156"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893875/; classtype:trojan-activity;sid:84756975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.156.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893876/; classtype:trojan-activity;sid:84756976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.251.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893873/; classtype:trojan-activity;sid:84756973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.156.3"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893874/; classtype:trojan-activity;sid:84756974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.85.165"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893871/; classtype:trojan-activity;sid:84756971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.125.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893872/; classtype:trojan-activity;sid:84756972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.96.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893868/; classtype:trojan-activity;sid:84756968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.124.207"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893869/; classtype:trojan-activity;sid:84756969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.138.220"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893870/; classtype:trojan-activity;sid:84756970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.206.197.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893862/; classtype:trojan-activity;sid:84756962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.202.64.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893863/; classtype:trojan-activity;sid:84756963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.115.102.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893864/; classtype:trojan-activity;sid:84756964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.189.31.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893865/; classtype:trojan-activity;sid:84756965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.108.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893866/; classtype:trojan-activity;sid:84756966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.124.207"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893867/; classtype:trojan-activity;sid:84756967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.190.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893854/; classtype:trojan-activity;sid:84756954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.228.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893855/; classtype:trojan-activity;sid:84756955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.139.198.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893856/; classtype:trojan-activity;sid:84756956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.198.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893857/; classtype:trojan-activity;sid:84756957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.58.42.3"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893858/; classtype:trojan-activity;sid:84756958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.149.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893859/; classtype:trojan-activity;sid:84756959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"93.157.253.209"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893860/; classtype:trojan-activity;sid:84756960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.219.1.198"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893861/; classtype:trojan-activity;sid:84756961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.221.24"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893853/; classtype:trojan-activity;sid:84756953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.216.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893850/; classtype:trojan-activity;sid:84756950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.190.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893851/; classtype:trojan-activity;sid:84756951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.90.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893852/; classtype:trojan-activity;sid:84756952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.193.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893834/; classtype:trojan-activity;sid:84756934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.177.33.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893835/; classtype:trojan-activity;sid:84756935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.13.235.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893836/; classtype:trojan-activity;sid:84756936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.161.160.164"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893837/; classtype:trojan-activity;sid:84756937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.177.33.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893838/; classtype:trojan-activity;sid:84756938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"98.252.87.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893839/; classtype:trojan-activity;sid:84756939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893840/; classtype:trojan-activity;sid:84756940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.176.252.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893841/; classtype:trojan-activity;sid:84756941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.245.0.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893842/; classtype:trojan-activity;sid:84756942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.145.11"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893843/; classtype:trojan-activity;sid:84756943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.75.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893844/; classtype:trojan-activity;sid:84756944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install.sh"; depth:11; endswith; nocase; http.host; content:"filmchill.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893845/; classtype:trojan-activity;sid:84756945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.149.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893846/; classtype:trojan-activity;sid:84756946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.92.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893847/; classtype:trojan-activity;sid:84756947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.229.90.24"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893848/; classtype:trojan-activity;sid:84756948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.195.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893849/; classtype:trojan-activity;sid:84756949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.78.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893826/; classtype:trojan-activity;sid:84756926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.43.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893827/; classtype:trojan-activity;sid:84756927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.206.197.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893828/; classtype:trojan-activity;sid:84756928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.228.103.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893829/; classtype:trojan-activity;sid:84756929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.140.185.252"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893830/; classtype:trojan-activity;sid:84756930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.49.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893831/; classtype:trojan-activity;sid:84756931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"200.115.102.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893832/; classtype:trojan-activity;sid:84756932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.49.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893833/; classtype:trojan-activity;sid:84756933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893824/; classtype:trojan-activity;sid:84756924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"hackers.krd"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893825/; classtype:trojan-activity;sid:84756925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.239.191.177"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893823/; classtype:trojan-activity;sid:84756923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.243.208.30"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893822/; classtype:trojan-activity;sid:84756922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"120.77.79.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893821/; classtype:trojan-activity;sid:84756921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"39.97.246.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893820/; classtype:trojan-activity;sid:84756920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.14.26"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893819/; classtype:trojan-activity;sid:84756919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.118.245.179"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893818/; classtype:trojan-activity;sid:84756918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hexmostafa/sshcracker/releases/download/sshcrackerv1.0.0/sshcracker.exe"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893817/; classtype:trojan-activity;sid:84756917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chaitin/xray/releases/download/1.9.11/xray_linux_amd64.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893816/; classtype:trojan-activity;sid:84756916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fahrj/reverse-ssh/releases/download/v1.2.0/upx_reverse-sshx64"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893811/; classtype:trojan-activity;sid:84756911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/languages/plugins/ds5.txt"; depth:37; endswith; nocase; http.host; content:"www.dra.com.ve"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893812/; classtype:trojan-activity;sid:84756912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"108.168.10.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893813/; classtype:trojan-activity;sid:84756913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"14.189.246.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893814/; classtype:trojan-activity;sid:84756914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dom/show"; depth:9; endswith; nocase; http.host; content:"2.57.122.159"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893815/; classtype:trojan-activity;sid:84756915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.243.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893805/; classtype:trojan-activity;sid:84756905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.121.184.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893806/; classtype:trojan-activity;sid:84756906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mingkwind/sshcrack/releases/download/sshcrack/sshcrack_linux.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893807/; classtype:trojan-activity;sid:84756907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.26.0/xmrig-6.26.0-linux-static-x64.tar.gz"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893808/; classtype:trojan-activity;sid:84756908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/github-production-release-asset/88327406/ecfabc02-9e68-4cec-a6d1-a0e7773d900e|3f|sp=r|7c|26|7c|sv=2018-11-09|7c|26|7c|sr=b|7c|26|7c|spr=https|7c|26|7c|se=2026-05-07t10%3a13%3a53z|7c|26|7c|rscd=attachment%3b+filename%3dxmrig-6.26.0-linux-static-x64.tar.gz|7c|26|7c|rsct=application%2foctet-stream|7c|26|7c|skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0|7c|26|7c|sktid=398a6654-997b-47e9-b12b-9515b896b4de|7c|26|7c|skt=2026-05-07t09%3a13%3a04z|7c|26|7c|ske=2026-05-07t10%3a13%3a53z|7c|26|7c|sks=b|7c|26|7c|skv=2018-11-09|7c|26|7c|sig=tqkub8ur8ddawsq4epd8gk73jfcczauzxfvwcl1k7ks%3d|7c|26|7c|jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc3ode0ntu3miwibmjmijoxnzc4mtq1mjcylcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.aouyu6vhnh7_rqn7cd0bnhiaug92hu2skk6zwjr2qbg|7c|26|7c|response-content-disposition=attachment%3b%20filename%3dxmrig-6.26.0-linux-static-x64.tar.gz|7c|26|7c|response-content-type=application%2foctet-stream"; depth:1052; endswith; nocase; http.host; content:"release-assets.githubusercontent.com"; depth:36; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893809/; classtype:trojan-activity;sid:84756909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"106.14.58.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893810/; classtype:trojan-activity;sid:84756910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"106.41.44.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893804/; classtype:trojan-activity;sid:84756904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/admin/productimages/unkillbot_x86_64"; depth:37; endswith; nocase; http.host; content:"sistemasyusa.icu"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893799/; classtype:trojan-activity;sid:84756899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.15.204"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893800/; classtype:trojan-activity;sid:84756900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.22.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893801/; classtype:trojan-activity;sid:84756901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.238.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893802/; classtype:trojan-activity;sid:84756902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t/kal64"; depth:8; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893803/; classtype:trojan-activity;sid:84756903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.44.147.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893798/; classtype:trojan-activity;sid:84756898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"38.137.250.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893794/; classtype:trojan-activity;sid:84756894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7%20-o%20/tmp/arm7"; depth:22; endswith; nocase; http.host; content:"37.48.254.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893795/; classtype:trojan-activity;sid:84756895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.179.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893796/; classtype:trojan-activity;sid:84756896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/kswpad"; depth:9; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893797/; classtype:trojan-activity;sid:84756897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893791/; classtype:trojan-activity;sid:84756891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"185.244.84.159"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893792/; classtype:trojan-activity;sid:84756892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"210.8.142.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893793/; classtype:trojan-activity;sid:84756893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"77.247.88.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893790/; classtype:trojan-activity;sid:84756890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"82.86.65.140"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893784/; classtype:trojan-activity;sid:84756884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"159.203.181.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893785/; classtype:trojan-activity;sid:84756885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/dlr.ppc"; depth:16; endswith; nocase; http.host; content:"91.196.32.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893786/; classtype:trojan-activity;sid:84756886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.123.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893787/; classtype:trojan-activity;sid:84756887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.126.223.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893788/; classtype:trojan-activity;sid:84756888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.130.133.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893789/; classtype:trojan-activity;sid:84756889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.189.31.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893775/; classtype:trojan-activity;sid:84756875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.87.110.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893776/; classtype:trojan-activity;sid:84756876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"88.85.199.186"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893777/; classtype:trojan-activity;sid:84756877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.70.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893778/; classtype:trojan-activity;sid:84756878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.176.116.4"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893779/; classtype:trojan-activity;sid:84756879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.95.27.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893780/; classtype:trojan-activity;sid:84756880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.136.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893781/; classtype:trojan-activity;sid:84756881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.216.48.105"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893782/; classtype:trojan-activity;sid:84756882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.x/pax.txt"; depth:11; endswith; nocase; http.host; content:"177.22.88.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893783/; classtype:trojan-activity;sid:84756883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.211.136"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893773/; classtype:trojan-activity;sid:84756873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.126.223.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893774/; classtype:trojan-activity;sid:84756874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.237.63.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893771/; classtype:trojan-activity;sid:84756871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.162.49.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893772/; classtype:trojan-activity;sid:84756872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.py"; depth:7; endswith; nocase; http.host; content:"216.167.26.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893770/; classtype:trojan-activity;sid:84756870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.232.219.81"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893767/; classtype:trojan-activity;sid:84756867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.32.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893768/; classtype:trojan-activity;sid:84756868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mot"; depth:4; endswith; nocase; http.host; content:"venom.rotero.vc"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893769/; classtype:trojan-activity;sid:84756869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.185.91.180"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893765/; classtype:trojan-activity;sid:84756865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.24.219"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893766/; classtype:trojan-activity;sid:84756866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.215.23.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893755/; classtype:trojan-activity;sid:84756855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"204.116.34.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893756/; classtype:trojan-activity;sid:84756856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893757/; classtype:trojan-activity;sid:84756857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.228.134.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893758/; classtype:trojan-activity;sid:84756858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.234.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893759/; classtype:trojan-activity;sid:84756859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.74.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893760/; classtype:trojan-activity;sid:84756860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893761/; classtype:trojan-activity;sid:84756861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"220.180.99.71"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893762/; classtype:trojan-activity;sid:84756862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"31.25.28.110"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893763/; classtype:trojan-activity;sid:84756863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv6l"; depth:7; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893764/; classtype:trojan-activity;sid:84756864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.41.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893750/; classtype:trojan-activity;sid:84756850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"185.9.139.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893751/; classtype:trojan-activity;sid:84756851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_x86_64"; depth:12; endswith; nocase; http.host; content:"103.195.239.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893752/; classtype:trojan-activity;sid:84756852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arc"; depth:50; endswith; nocase; http.host; content:"31.77.227.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893753/; classtype:trojan-activity;sid:84756853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"187.45.95.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893754/; classtype:trojan-activity;sid:84756854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"126.76.103.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893746/; classtype:trojan-activity;sid:84756846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"120.77.237.174"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893747/; classtype:trojan-activity;sid:84756847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahdimgf2/botmirzapanel/main/install.sh"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893748/; classtype:trojan-activity;sid:84756848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.147.57"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893749/; classtype:trojan-activity;sid:84756849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.237.133.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893742/; classtype:trojan-activity;sid:84756842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.118.245.231"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893743/; classtype:trojan-activity;sid:84756843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"5.202.46.59"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893744/; classtype:trojan-activity;sid:84756844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.21.0/xmrig-6.21.0-linux-x64.tar.gz"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893739/; classtype:trojan-activity;sid:84756839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.241.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893740/; classtype:trojan-activity;sid:84756840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zed"; depth:4; endswith; nocase; http.host; content:"107.190.130.2"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893741/; classtype:trojan-activity;sid:84756841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5kbtigfn/raw"; depth:13; endswith; nocase; http.host; content:"pastefy.app"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893738/; classtype:trojan-activity;sid:84756838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.193.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893734/; classtype:trojan-activity;sid:84756834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.238.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893735/; classtype:trojan-activity;sid:84756835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.236.44.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893736/; classtype:trojan-activity;sid:84756836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/agent/loader|3f|k=n4d-2ff16c75b1d2"; depth:39; endswith; nocase; http.host; content:"cdnorigin.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893737/; classtype:trojan-activity;sid:84756837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"176.193.95.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893727/; classtype:trojan-activity;sid:84756827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.248.219"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893728/; classtype:trojan-activity;sid:84756828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.245.56.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893729/; classtype:trojan-activity;sid:84756829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/languages/plugins/ds5.txt)"; depth:38; endswith; nocase; http.host; content:"www.dra.com.ve"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893730/; classtype:trojan-activity;sid:84756830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mot"; depth:4; endswith; nocase; http.host; content:"77.90.185.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893731/; classtype:trojan-activity;sid:84756831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.77.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893732/; classtype:trojan-activity;sid:84756832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.23.129.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893733/; classtype:trojan-activity;sid:84756833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kryptex-miners-org/kryptex-miners/releases/download/lolminer-1-98a/lolminer_v1.98a_lin64.tar.gz"; depth:96; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893723/; classtype:trojan-activity;sid:84756823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.81.37.15"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893724/; classtype:trojan-activity;sid:84756824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.80.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893725/; classtype:trojan-activity;sid:84756825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syss"; depth:5; endswith; nocase; http.host; content:"120.222.159.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893726/; classtype:trojan-activity;sid:84756826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_mips"; depth:10; endswith; nocase; http.host; content:"103.195.239.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893720/; classtype:trojan-activity;sid:84756820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"180.76.137.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893721/; classtype:trojan-activity;sid:84756821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/kswpad"; depth:9; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893722/; classtype:trojan-activity;sid:84756822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl601"; depth:6; endswith; nocase; http.host; content:"31.170.22.205"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893718/; classtype:trojan-activity;sid:84756818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6zmh9qt2|3f|vjcn9t7=gr"; depth:23; endswith; nocase; http.host; content:"194.238.79.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893719/; classtype:trojan-activity;sid:84756819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.237.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893714/; classtype:trojan-activity;sid:84756814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.74.83.192"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893715/; classtype:trojan-activity;sid:84756815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.254.52"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893716/; classtype:trojan-activity;sid:84756816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv4l"; depth:7; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893717/; classtype:trojan-activity;sid:84756817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.83.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893711/; classtype:trojan-activity;sid:84756811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"72.194.227.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893712/; classtype:trojan-activity;sid:84756812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.55.49.152"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893713/; classtype:trojan-activity;sid:84756813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.225.114.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893710/; classtype:trojan-activity;sid:84756810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.228.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893703/; classtype:trojan-activity;sid:84756803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.110.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893704/; classtype:trojan-activity;sid:84756804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.237.98.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893705/; classtype:trojan-activity;sid:84756805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dropper.sh"; depth:11; endswith; nocase; http.host; content:"185.242.3.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893706/; classtype:trojan-activity;sid:84756806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7ft24yrx/raw)/"; depth:15; endswith; nocase; http.host; content:"pastefy.app"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893707/; classtype:trojan-activity;sid:84756807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.34.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893708/; classtype:trojan-activity;sid:84756808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl/blahajnet.x86_64"; depth:20; endswith; nocase; http.host; content:"51.75.118.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893709/; classtype:trojan-activity;sid:84756809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.121.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893700/; classtype:trojan-activity;sid:84756800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.15.204"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893701/; classtype:trojan-activity;sid:84756801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.7.240.14"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893702/; classtype:trojan-activity;sid:84756802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.198.193.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893699/; classtype:trojan-activity;sid:84756799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sparc"; depth:6; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893698/; classtype:trojan-activity;sid:84756798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/main_arm"; depth:9; endswith; nocase; http.host; content:"103.195.239.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893696/; classtype:trojan-activity;sid:84756796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.237.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893697/; classtype:trojan-activity;sid:84756797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"172.245.148.28"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893693/; classtype:trojan-activity;sid:84756793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.253.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893694/; classtype:trojan-activity;sid:84756794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.193.195.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893695/; classtype:trojan-activity;sid:84756795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/dlr.arm6"; depth:17; endswith; nocase; http.host; content:"91.196.32.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893691/; classtype:trojan-activity;sid:84756791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"hackerai.co"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893692/; classtype:trojan-activity;sid:84756792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.234.150.188"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893684/; classtype:trojan-activity;sid:84756784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.9.139.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893685/; classtype:trojan-activity;sid:84756785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.10.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893686/; classtype:trojan-activity;sid:84756786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/dlr.sh4"; depth:16; endswith; nocase; http.host; content:"91.196.32.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893687/; classtype:trojan-activity;sid:84756787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.56.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893688/; classtype:trojan-activity;sid:84756788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"98.252.87.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893689/; classtype:trojan-activity;sid:84756789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.107.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893690/; classtype:trojan-activity;sid:84756790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.25.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893681/; classtype:trojan-activity;sid:84756781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.87.110.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893682/; classtype:trojan-activity;sid:84756782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.32.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893683/; classtype:trojan-activity;sid:84756783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.113.113.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893669/; classtype:trojan-activity;sid:84756769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.82.201.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893670/; classtype:trojan-activity;sid:84756770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/amd64"; depth:8; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893671/; classtype:trojan-activity;sid:84756771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"110.37.76.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893672/; classtype:trojan-activity;sid:84756772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"183.11.226.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893673/; classtype:trojan-activity;sid:84756773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.92.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893674/; classtype:trojan-activity;sid:84756774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.28.66"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893675/; classtype:trojan-activity;sid:84756775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.231.233.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893676/; classtype:trojan-activity;sid:84756776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.58.223"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893677/; classtype:trojan-activity;sid:84756777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.174.91.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893678/; classtype:trojan-activity;sid:84756778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.146.153.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893679/; classtype:trojan-activity;sid:84756779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.85.108.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893668/; classtype:trojan-activity;sid:84756768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.252.159.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893664/; classtype:trojan-activity;sid:84756764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.34.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893665/; classtype:trojan-activity;sid:84756765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/des"; depth:4; endswith; nocase; http.host; content:"147.182.224.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893666/; classtype:trojan-activity;sid:84756766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.57.155"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893667/; classtype:trojan-activity;sid:84756767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"85.12.205.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893661/; classtype:trojan-activity;sid:84756761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mddos/mddos.arm5"; depth:17; endswith; nocase; http.host; content:"154.219.116.177"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893662/; classtype:trojan-activity;sid:84756762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.171.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893663/; classtype:trojan-activity;sid:84756763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqxpuo2j13ngf|3f|jafpednm=cags"; depth:31; endswith; nocase; http.host; content:"194.238.79.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893658/; classtype:trojan-activity;sid:84756758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.121.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893659/; classtype:trojan-activity;sid:84756759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.39.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893660/; classtype:trojan-activity;sid:84756760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.248.82.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893656/; classtype:trojan-activity;sid:84756756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"14.189.118.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893657/; classtype:trojan-activity;sid:84756757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"39.108.72.32"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893653/; classtype:trojan-activity;sid:84756753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ssh-it-deploy.sh"; depth:17; endswith; nocase; http.host; content:"nossl.segfault.net"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893654/; classtype:trojan-activity;sid:84756754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893655/; classtype:trojan-activity;sid:84756755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0rg1epq6|3f|ypeh4dqh=dkpx"; depth:26; endswith; nocase; http.host; content:"194.238.79.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893649/; classtype:trojan-activity;sid:84756749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p2.sh"; depth:6; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893650/; classtype:trojan-activity;sid:84756750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.252.159.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893651/; classtype:trojan-activity;sid:84756751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/linux"; depth:8; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893652/; classtype:trojan-activity;sid:84756752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.1.226.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893642/; classtype:trojan-activity;sid:84756742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.85.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893643/; classtype:trojan-activity;sid:84756743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893644/; classtype:trojan-activity;sid:84756744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/max"; depth:4; endswith; nocase; http.host; content:"147.182.224.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893645/; classtype:trojan-activity;sid:84756745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phpmyadmin/setup/lib/syscon"; depth:28; endswith; nocase; http.host; content:"106.54.223.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893646/; classtype:trojan-activity;sid:84756746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893647/; classtype:trojan-activity;sid:84756747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64.bin"; depth:16; endswith; nocase; http.host; content:"194.110.87.216"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893648/; classtype:trojan-activity;sid:84756748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.43.93.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893638/; classtype:trojan-activity;sid:84756738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/dlr.m68k"; depth:17; endswith; nocase; http.host; content:"91.196.32.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893639/; classtype:trojan-activity;sid:84756739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"14.189.118.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893640/; classtype:trojan-activity;sid:84756740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"59.110.9.189"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893641/; classtype:trojan-activity;sid:84756741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.86.29"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893631/; classtype:trojan-activity;sid:84756731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.118.245.179"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893632/; classtype:trojan-activity;sid:84756732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.56.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893633/; classtype:trojan-activity;sid:84756733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.43.93.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893634/; classtype:trojan-activity;sid:84756734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893635/; classtype:trojan-activity;sid:84756735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"1.222.167.7"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893636/; classtype:trojan-activity;sid:84756736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.72.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893637/; classtype:trojan-activity;sid:84756737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.123.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893624/; classtype:trojan-activity;sid:84756724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.21.26.73"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893625/; classtype:trojan-activity;sid:84756725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893626/; classtype:trojan-activity;sid:84756726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.103.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893627/; classtype:trojan-activity;sid:84756727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.158.55.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893628/; classtype:trojan-activity;sid:84756728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i486"; depth:5; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893629/; classtype:trojan-activity;sid:84756729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.146.92.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893630/; classtype:trojan-activity;sid:84756730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dots"; depth:5; endswith; nocase; http.host; content:"77.90.185.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893623/; classtype:trojan-activity;sid:84756723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.118.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893621/; classtype:trojan-activity;sid:84756721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893622/; classtype:trojan-activity;sid:84756722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.229.203.112"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893618/; classtype:trojan-activity;sid:84756718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.103.197.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893619/; classtype:trojan-activity;sid:84756719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"85.12.205.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893620/; classtype:trojan-activity;sid:84756720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aldmq0vwep8|3f|ifbkqo2=iwz"; depth:27; endswith; nocase; http.host; content:"194.238.79.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893616/; classtype:trojan-activity;sid:84756716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"204.116.34.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893617/; classtype:trojan-activity;sid:84756717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/install-agent.sh"; depth:26; endswith; nocase; http.host; content:"curlservice.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893613/; classtype:trojan-activity;sid:84756713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.84.79"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893614/; classtype:trojan-activity;sid:84756714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.170.224.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893611/; classtype:trojan-activity;sid:84756711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/dlr.arm5"; depth:17; endswith; nocase; http.host; content:"91.196.32.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893612/; classtype:trojan-activity;sid:84756712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.217.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893604/; classtype:trojan-activity;sid:84756704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4qynx|3f|ojtcyp4=ti16"; depth:22; endswith; nocase; http.host; content:"194.238.79.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893605/; classtype:trojan-activity;sid:84756705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.237.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893606/; classtype:trojan-activity;sid:84756706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.245.39.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893607/; classtype:trojan-activity;sid:84756707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bvo2dwphufc0|3f|7bnqag=leo14"; depth:29; endswith; nocase; http.host; content:"194.238.79.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893608/; classtype:trojan-activity;sid:84756708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader.sh"; depth:10; endswith; nocase; http.host; content:"151.242.30.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893609/; classtype:trojan-activity;sid:84756709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dot"; depth:4; endswith; nocase; http.host; content:"84.201.25.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893610/; classtype:trojan-activity;sid:84756710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.38.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893594/; classtype:trojan-activity;sid:84756694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"101.66.20.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893595/; classtype:trojan-activity;sid:84756695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.77.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893596/; classtype:trojan-activity;sid:84756696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t/amd64"; depth:8; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893597/; classtype:trojan-activity;sid:84756697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shitmloversishere.sh"; depth:21; endswith; nocase; http.host; content:"31.77.227.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893598/; classtype:trojan-activity;sid:84756698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jokowiajg623/do/refs/heads/main/passwd.sh"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893599/; classtype:trojan-activity;sid:84756699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.124.253.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893600/; classtype:trojan-activity;sid:84756700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"108.170.136.155"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893601/; classtype:trojan-activity;sid:84756701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t/kswpad"; depth:9; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893602/; classtype:trojan-activity;sid:84756702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.217.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893603/; classtype:trojan-activity;sid:84756703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kes.pl"; depth:7; endswith; nocase; http.host; content:"147.182.224.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893585/; classtype:trojan-activity;sid:84756685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"95.43.75.2"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893586/; classtype:trojan-activity;sid:84756686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.12.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893587/; classtype:trojan-activity;sid:84756687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.2.23"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893588/; classtype:trojan-activity;sid:84756688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.236.44.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893589/; classtype:trojan-activity;sid:84756689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chrono"; depth:7; endswith; nocase; http.host; content:"filmchill.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893590/; classtype:trojan-activity;sid:84756690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"106.15.6.205"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893591/; classtype:trojan-activity;sid:84756691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893592/; classtype:trojan-activity;sid:84756692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.36.197.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893593/; classtype:trojan-activity;sid:84756693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.168.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893582/; classtype:trojan-activity;sid:84756682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.232.60.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893583/; classtype:trojan-activity;sid:84756683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"79.165.88.118"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893584/; classtype:trojan-activity;sid:84756684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/agent/full|3f|arch=amd64"; depth:29; endswith; nocase; http.host; content:"209.99.186.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893577/; classtype:trojan-activity;sid:84756677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv5l"; depth:7; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893578/; classtype:trojan-activity;sid:84756678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.233.236.144"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893579/; classtype:trojan-activity;sid:84756679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.63.8.194"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893580/; classtype:trojan-activity;sid:84756680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.1.226.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893581/; classtype:trojan-activity;sid:84756681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.171.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893569/; classtype:trojan-activity;sid:84756669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"108.168.10.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893571/; classtype:trojan-activity;sid:84756671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/plugins/dvgfltm/onelife/loader.sh"; depth:45; endswith; nocase; http.host; content:"tpkpolus.ru"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893572/; classtype:trojan-activity;sid:84756672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.230.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893573/; classtype:trojan-activity;sid:84756673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.134.84.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893574/; classtype:trojan-activity;sid:84756674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.25.0/xmrig-6.25.0-linux-static-x64.tar.gz"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893575/; classtype:trojan-activity;sid:84756675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.85.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893576/; classtype:trojan-activity;sid:84756676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"101.133.172.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893562/; classtype:trojan-activity;sid:84756662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/setup.sh"; depth:9; endswith; nocase; http.host; content:"ssc.nexajs.com"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893563/; classtype:trojan-activity;sid:84756663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bss"; depth:4; endswith; nocase; http.host; content:"147.182.224.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893564/; classtype:trojan-activity;sid:84756664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.94.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893565/; classtype:trojan-activity;sid:84756665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.186.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893566/; classtype:trojan-activity;sid:84756666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.238.27.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893567/; classtype:trojan-activity;sid:84756667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"111.185.147.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893568/; classtype:trojan-activity;sid:84756668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.106.148"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893556/; classtype:trojan-activity;sid:84756656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.241.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893557/; classtype:trojan-activity;sid:84756657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"38.179.101.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893558/; classtype:trojan-activity;sid:84756658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.x/sys_users"; depth:13; endswith; nocase; http.host; content:"177.22.88.133"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893559/; classtype:trojan-activity;sid:84756659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.46.196.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893560/; classtype:trojan-activity;sid:84756660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"207.34.149.169"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893561/; classtype:trojan-activity;sid:84756661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.159.218.169"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893554/; classtype:trojan-activity;sid:84756654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.9.139.117"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893555/; classtype:trojan-activity;sid:84756655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/kal64"; depth:8; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893551/; classtype:trojan-activity;sid:84756651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"178.208.248.77"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893552/; classtype:trojan-activity;sid:84756652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.80.162"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893553/; classtype:trojan-activity;sid:84756653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.108.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893550/; classtype:trojan-activity;sid:84756650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.114.34.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893547/; classtype:trojan-activity;sid:84756647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/amd64"; depth:8; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893548/; classtype:trojan-activity;sid:84756648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.4.159"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893549/; classtype:trojan-activity;sid:84756649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i486"; depth:51; endswith; nocase; http.host; content:"31.77.227.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893543/; classtype:trojan-activity;sid:84756643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.231.233.62"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893544/; classtype:trojan-activity;sid:84756644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.245.39.127"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893545/; classtype:trojan-activity;sid:84756645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.85.199.186"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893546/; classtype:trojan-activity;sid:84756646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.7.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893536/; classtype:trojan-activity;sid:84756636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.238.96.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893537/; classtype:trojan-activity;sid:84756637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.187.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893538/; classtype:trojan-activity;sid:84756638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/beacon|3f|k=n4d-2ff16c75b1d2|7c|26|7c|h=ipcam"; depth:50; endswith; nocase; http.host; content:"209.99.186.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893539/; classtype:trojan-activity;sid:84756639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.233.236.144"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893540/; classtype:trojan-activity;sid:84756640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"60.205.248.70"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893541/; classtype:trojan-activity;sid:84756641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.233.224.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893542/; classtype:trojan-activity;sid:84756642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/agent/loader|3f|k=n4d-2ff16c75b1d2"; depth:39; endswith; nocase; http.host; content:"209.99.186.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893528/; classtype:trojan-activity;sid:84756628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.237.133.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893529/; classtype:trojan-activity;sid:84756629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"188.121.201.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893530/; classtype:trojan-activity;sid:84756630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"89.189.181.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893531/; classtype:trojan-activity;sid:84756631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.228.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893532/; classtype:trojan-activity;sid:84756632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.208.248.77"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893533/; classtype:trojan-activity;sid:84756633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.188.73.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893534/; classtype:trojan-activity;sid:84756634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r00ts3c/ddos-rootsec/raw/refs/heads/master/ddos%20scripts/amp%20methods/dnp%20amplification/d.c"; depth:96; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893535/; classtype:trojan-activity;sid:84756635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893524/; classtype:trojan-activity;sid:84756624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amd"; depth:4; endswith; nocase; http.host; content:"120.222.159.43"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893525/; classtype:trojan-activity;sid:84756625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/dlr.mips"; depth:17; endswith; nocase; http.host; content:"91.196.32.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893526/; classtype:trojan-activity;sid:84756626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"118.190.161.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893527/; classtype:trojan-activity;sid:84756627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.243.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893521/; classtype:trojan-activity;sid:84756621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.247.87.36"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893522/; classtype:trojan-activity;sid:84756622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.38.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893523/; classtype:trojan-activity;sid:84756623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/linux"; depth:8; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893519/; classtype:trojan-activity;sid:84756619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.136.156"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893520/; classtype:trojan-activity;sid:84756620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.38.19.88"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893514/; classtype:trojan-activity;sid:84756614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.162.49.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893515/; classtype:trojan-activity;sid:84756615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.38.208.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893516/; classtype:trojan-activity;sid:84756616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/21oatf109angbyhs_5e13zp2tv1nrhfnvj0gg1xu8cninympqsqqwvibdhtgzbv502qkprty_f7v0q1ydiezapki058yotyuvqlppv9imhcjinamwk9tx8k4_hybidy1vxzluyzsvrait9t28ci2sqpym_8wape4cldt3kohikpzbng/efqgjl6i8zrh9vw/x86"; depth:196; endswith; nocase; http.host; content:"download1532.mediafire.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893517/; classtype:trojan-activity;sid:84756617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.208.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893518/; classtype:trojan-activity;sid:84756618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.252.159.101"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893512/; classtype:trojan-activity;sid:84756612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"89.189.181.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893513/; classtype:trojan-activity;sid:84756613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.46.149.240"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893510/; classtype:trojan-activity;sid:84756610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"171.213.200.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893511/; classtype:trojan-activity;sid:84756611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.95.27.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893500/; classtype:trojan-activity;sid:84756600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/release/dlr.mpsl"; depth:17; endswith; nocase; http.host; content:"91.196.32.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893501/; classtype:trojan-activity;sid:84756601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"187.45.95.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893502/; classtype:trojan-activity;sid:84756602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.238.96.14"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893503/; classtype:trojan-activity;sid:84756603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.38.16.176"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893504/; classtype:trojan-activity;sid:84756604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/powerpc"; depth:8; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893505/; classtype:trojan-activity;sid:84756605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.155.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893506/; classtype:trojan-activity;sid:84756606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.211.136"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893507/; classtype:trojan-activity;sid:84756607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"83.168.69.141"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893508/; classtype:trojan-activity;sid:84756608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/femboysec-intelligence-team/sdsjkasndjaskdnaskjdnaskjdnaskjdnaskjdnakjdnasjdnasjnasdkjdnaskd/femboyse.c"; depth:104; endswith; nocase; http.host; content:"femboy.center"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893509/; classtype:trojan-activity;sid:84756609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.168.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893498/; classtype:trojan-activity;sid:84756598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.215.97"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893499/; classtype:trojan-activity;sid:84756599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5kbtigfn/raw)/"; depth:15; endswith; nocase; http.host; content:"pastefy.app"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893493/; classtype:trojan-activity;sid:84756593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"171.213.200.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893494/; classtype:trojan-activity;sid:84756594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"47.212.193.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893495/; classtype:trojan-activity;sid:84756595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.236.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893496/; classtype:trojan-activity;sid:84756596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"178.238.27.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893497/; classtype:trojan-activity;sid:84756597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.115.37.164"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893490/; classtype:trojan-activity;sid:84756590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.25.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893491/; classtype:trojan-activity;sid:84756591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.27.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893492/; classtype:trojan-activity;sid:84756592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.21.0/xmrig-6.21.0-linux-static-x64.tar.gz"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893486/; classtype:trojan-activity;sid:84756586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cp"; depth:3; endswith; nocase; http.host; content:"82.197.93.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893487/; classtype:trojan-activity;sid:84756587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.202.20.139"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893488/; classtype:trojan-activity;sid:84756588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"60.170.253.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893489/; classtype:trojan-activity;sid:84756589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.254.52"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893482/; classtype:trojan-activity;sid:84756582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.118.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893483/; classtype:trojan-activity;sid:84756583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7ft24yrx/raw)"; depth:14; endswith; nocase; http.host; content:"pastefy.app"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893484/; classtype:trojan-activity;sid:84756584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.156.155.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893485/; classtype:trojan-activity;sid:84756585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"163.142.94.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893478/; classtype:trojan-activity;sid:84756578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"126.76.103.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893479/; classtype:trojan-activity;sid:84756579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zehir.sh"; depth:9; endswith; nocase; http.host; content:"91.196.32.55"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893480/; classtype:trojan-activity;sid:84756580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.249.223"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893481/; classtype:trojan-activity;sid:84756581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.245.39.127"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893467/; classtype:trojan-activity;sid:84756567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"122.193.195.215"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893468/; classtype:trojan-activity;sid:84756568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.188.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893469/; classtype:trojan-activity;sid:84756569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.155.232"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893470/; classtype:trojan-activity;sid:84756570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/kal64"; depth:8; endswith; nocase; http.host; content:"195.177.94.72"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893471/; classtype:trojan-activity;sid:84756571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.105.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893472/; classtype:trojan-activity;sid:84756572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.245.56.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893473/; classtype:trojan-activity;sid:84756573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.129.128.50"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893474/; classtype:trojan-activity;sid:84756574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i686"; depth:51; endswith; nocase; http.host; content:"31.77.227.104"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893475/; classtype:trojan-activity;sid:84756575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.32.177"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893476/; classtype:trojan-activity;sid:84756576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"176.193.95.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893477/; classtype:trojan-activity;sid:84756577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.187.137"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893459/; classtype:trojan-activity;sid:84756559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.124.253.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893460/; classtype:trojan-activity;sid:84756560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.143.172.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893461/; classtype:trojan-activity;sid:84756561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"47.212.193.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893462/; classtype:trojan-activity;sid:84756562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.46.196.157"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893463/; classtype:trojan-activity;sid:84756563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7ft24yrx/raw"; depth:13; endswith; nocase; http.host; content:"pastefy.app"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893464/; classtype:trojan-activity;sid:84756564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.186.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893465/; classtype:trojan-activity;sid:84756565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phpmyadmin/setup/lib/888.sh"; depth:28; endswith; nocase; http.host; content:"106.54.223.106"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893466/; classtype:trojan-activity;sid:84756566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.198.118.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893454/; classtype:trojan-activity;sid:84756554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.252.159.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893455/; classtype:trojan-activity;sid:84756555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.12.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893456/; classtype:trojan-activity;sid:84756556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.70.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893457/; classtype:trojan-activity;sid:84756557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.59.239.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893458/; classtype:trojan-activity;sid:84756558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.25.170.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893453/; classtype:trojan-activity;sid:84756553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/favico.ico"; depth:11; endswith; nocase; http.host; content:"197.255.229.88"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893452/; classtype:trojan-activity;sid:84756552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/plugins/dvgfltm/onelife/loader.sh"; depth:45; endswith; nocase; http.host; content:"tpkpolus.ru"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893451/; classtype:trojan-activity;sid:84756551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pikujyhtcxz/loader.sh"; depth:22; endswith; nocase; http.host; content:"164.215.103.113"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893449/; classtype:trojan-activity;sid:84756549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"2.187.38.183"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893450/; classtype:trojan-activity;sid:84756550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.25.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893448/; classtype:trojan-activity;sid:84756548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/25730http2flooder.zip"; depth:22; endswith; nocase; http.host; content:"dl.proxiespool.wiki"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893447/; classtype:trojan-activity;sid:84756547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"116.162.55.77"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893446/; classtype:trojan-activity;sid:84756546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.zip"; depth:6; endswith; nocase; http.host; content:"dl.proxiespool.wiki"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893445/; classtype:trojan-activity;sid:84756545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkbrk/slowloris/master/slowloris.py"; depth:36; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893444/; classtype:trojan-activity;sid:84756544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/install_panel.sh"; depth:25; endswith; nocase; http.host; content:"download.bt.cn"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893440/; classtype:trojan-activity;sid:84756540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0.zip"; depth:6; endswith; nocase; http.host; content:"dl.proxiespool.wiki"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893441/; classtype:trojan-activity;sid:84756541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/setup.sh"; depth:9; endswith; nocase; http.host; content:"free.tiurl.top"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893442/; classtype:trojan-activity;sid:84756542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.76.79.220"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893443/; classtype:trojan-activity;sid:84756543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackerschoice/gsocket/releases/download/v1.4.43/gs-netcat_linux-x86_64"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893438/; classtype:trojan-activity;sid:84756538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.24.0/xmrig-6.24.0-linux-static-x64.tar.gz"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893439/; classtype:trojan-activity;sid:84756539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"79.0.5.138"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893437/; classtype:trojan-activity;sid:84756537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/red"; depth:4; endswith; nocase; http.host; content:"147.182.224.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893431/; classtype:trojan-activity;sid:84756531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/|3f|q=|7c|7b|7c|random.randint(1,1000000)|7c|7d|7c||7c|26|7c|rnd=|7c|7b|7c|random.random()|7c|7d|7c|"; depth:101; endswith; nocase; http.host; content:"91.199.45.108"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893432/; classtype:trojan-activity;sid:84756532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apt"; depth:4; endswith; nocase; http.host; content:"11-4xt.pages.dev"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893435/; classtype:trojan-activity;sid:84756535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.194.103.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893430/; classtype:trojan-activity;sid:84756530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.4.159"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893429/; classtype:trojan-activity;sid:84756529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b/bd570760274eb2b44d484b0a6ec56d82"; depth:35; endswith; nocase; http.host; content:"bs-deliver-e817.61d8f0e6ac62c139abd08ba5.workers.dev"; depth:52; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893428/; classtype:trojan-activity;sid:84756528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/inner/691cbe2e-d6bb-484d-8259-5c101c3909c0"; depth:45; endswith; nocase; http.host; content:"bs-deliver-e817.61d8f0e6ac62c139abd08ba5.workers.dev"; depth:52; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893427/; classtype:trojan-activity;sid:84756527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.58.83.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893426/; classtype:trojan-activity;sid:84756526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.39.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893425/; classtype:trojan-activity;sid:84756525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.233.255.77"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893424/; classtype:trojan-activity;sid:84756524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.58.83.206"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893423/; classtype:trojan-activity;sid:84756523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.39.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893422/; classtype:trojan-activity;sid:84756522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.189.180.123"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893421/; classtype:trojan-activity;sid:84756521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"115.51.43.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893420/; classtype:trojan-activity;sid:84756520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hamerderta/lzxhcjhsdajfslfgdsgh/releases/download/malware/xeno.v1.3.55.exe"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893419/; classtype:trojan-activity;sid:84756519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psl.zip"; depth:8; endswith; nocase; http.host; content:"kemaxglobalshippings.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893418/; classtype:trojan-activity;sid:84756518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.55.49.152"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893417/; classtype:trojan-activity;sid:84756517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.152.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893416/; classtype:trojan-activity;sid:84756516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.152.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893415/; classtype:trojan-activity;sid:84756515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.220.172"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893414/; classtype:trojan-activity;sid:84756514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/bin.exe"; depth:17; endswith; nocase; http.host; content:"ufavalkplus.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893413/; classtype:trojan-activity;sid:84756513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.84.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893412/; classtype:trojan-activity;sid:84756512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm7"; depth:51; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893408/; classtype:trojan-activity;sid:84756508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893409/; classtype:trojan-activity;sid:84756509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893410/; classtype:trojan-activity;sid:84756510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893411/; classtype:trojan-activity;sid:84756511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/public_files/vjify5p.txt"; depth:25; endswith; nocase; http.host; content:"192.162.199.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893407/; classtype:trojan-activity;sid:84756507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update.sh"; depth:10; endswith; nocase; http.host; content:"cnc.strikec2.wtf"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893406/; classtype:trojan-activity;sid:84756506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.ppc"; depth:50; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893400/; classtype:trojan-activity;sid:84756500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm6"; depth:51; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893401/; classtype:trojan-activity;sid:84756501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm5"; depth:51; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893402/; classtype:trojan-activity;sid:84756502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86"; depth:50; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893403/; classtype:trojan-activity;sid:84756503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm"; depth:50; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893404/; classtype:trojan-activity;sid:84756504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86_64"; depth:53; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893405/; classtype:trojan-activity;sid:84756505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.spc"; depth:50; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893395/; classtype:trojan-activity;sid:84756495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.m68k"; depth:51; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893396/; classtype:trojan-activity;sid:84756496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.sh4"; depth:50; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893397/; classtype:trojan-activity;sid:84756497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mpsl"; depth:51; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893398/; classtype:trojan-activity;sid:84756498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mips"; depth:51; endswith; nocase; http.host; content:"nigg.tashirpizza.su"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893399/; classtype:trojan-activity;sid:84756499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.85.99.9"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893394/; classtype:trojan-activity;sid:84756494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.143.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893393/; classtype:trojan-activity;sid:84756493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.159.34.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893392/; classtype:trojan-activity;sid:84756492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.15.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893391/; classtype:trojan-activity;sid:84756491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.128.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893390/; classtype:trojan-activity;sid:84756490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.ppc"; depth:50; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893389/; classtype:trojan-activity;sid:84756489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm6"; depth:51; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893379/; classtype:trojan-activity;sid:84756479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86"; depth:50; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893380/; classtype:trojan-activity;sid:84756480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.m68k"; depth:51; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893381/; classtype:trojan-activity;sid:84756481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm5"; depth:51; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893382/; classtype:trojan-activity;sid:84756482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm"; depth:50; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893383/; classtype:trojan-activity;sid:84756483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mpsl"; depth:51; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893384/; classtype:trojan-activity;sid:84756484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.spc"; depth:50; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893385/; classtype:trojan-activity;sid:84756485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm7"; depth:51; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893386/; classtype:trojan-activity;sid:84756486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86_64"; depth:53; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893387/; classtype:trojan-activity;sid:84756487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893388/; classtype:trojan-activity;sid:84756488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mips"; depth:51; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893375/; classtype:trojan-activity;sid:84756475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.sh4"; depth:50; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893376/; classtype:trojan-activity;sid:84756476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893377/; classtype:trojan-activity;sid:84756477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893378/; classtype:trojan-activity;sid:84756478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.143.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893374/; classtype:trojan-activity;sid:84756474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.38.225"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893373/; classtype:trojan-activity;sid:84756473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.187.182"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893372/; classtype:trojan-activity;sid:84756472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.128.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893371/; classtype:trojan-activity;sid:84756471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.103.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893370/; classtype:trojan-activity;sid:84756470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.exe"; depth:6; endswith; nocase; http.host; content:"hindustanagency.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893369/; classtype:trojan-activity;sid:84756469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.115.185.8"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893368/; classtype:trojan-activity;sid:84756468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.64.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893367/; classtype:trojan-activity;sid:84756467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.237.59"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893366/; classtype:trojan-activity;sid:84756466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"36.89.62.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893365/; classtype:trojan-activity;sid:84756465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.101.207"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893364/; classtype:trojan-activity;sid:84756464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.131.38.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893363/; classtype:trojan-activity;sid:84756463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.193.224"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893362/; classtype:trojan-activity;sid:84756462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.148.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893361/; classtype:trojan-activity;sid:84756461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.131.38.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893360/; classtype:trojan-activity;sid:84756460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.42.71.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893358/; classtype:trojan-activity;sid:84756458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.215.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893359/; classtype:trojan-activity;sid:84756459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.215.97"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893357/; classtype:trojan-activity;sid:84756457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_43d8213197042487.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893356/; classtype:trojan-activity;sid:84756456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.63.89"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893355/; classtype:trojan-activity;sid:84756455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7782139129/qsxep8i.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893354/; classtype:trojan-activity;sid:84756454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.233.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893353/; classtype:trojan-activity;sid:84756453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.63.89"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893352/; classtype:trojan-activity;sid:84756452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.187.182"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893351/; classtype:trojan-activity;sid:84756451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893350/; classtype:trojan-activity;sid:84756450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.51.222"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893349/; classtype:trojan-activity;sid:84756449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893346/; classtype:trojan-activity;sid:84756446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893347/; classtype:trojan-activity;sid:84756447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893348/; classtype:trojan-activity;sid:84756448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/463bc8"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893338/; classtype:trojan-activity;sid:84756438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893339/; classtype:trojan-activity;sid:84756439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893340/; classtype:trojan-activity;sid:84756440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893341/; classtype:trojan-activity;sid:84756441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893342/; classtype:trojan-activity;sid:84756442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893343/; classtype:trojan-activity;sid:84756443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893344/; classtype:trojan-activity;sid:84756444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893345/; classtype:trojan-activity;sid:84756445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45b5ab"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893337/; classtype:trojan-activity;sid:84756437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/193fbf"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893330/; classtype:trojan-activity;sid:84756430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4e7801"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893331/; classtype:trojan-activity;sid:84756431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eb6627"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893332/; classtype:trojan-activity;sid:84756432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2b88f1"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893333/; classtype:trojan-activity;sid:84756433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ae1b25"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893334/; classtype:trojan-activity;sid:84756434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/716d57"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893335/; classtype:trojan-activity;sid:84756435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/93e25d"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893336/; classtype:trojan-activity;sid:84756436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893327/; classtype:trojan-activity;sid:84756427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893328/; classtype:trojan-activity;sid:84756428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893329/; classtype:trojan-activity;sid:84756429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893325/; classtype:trojan-activity;sid:84756425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893326/; classtype:trojan-activity;sid:84756426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893323/; classtype:trojan-activity;sid:84756423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"frostyislebe.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893324/; classtype:trojan-activity;sid:84756424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.72.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893322/; classtype:trojan-activity;sid:84756422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.118.244.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893318/; classtype:trojan-activity;sid:84756418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893319/; classtype:trojan-activity;sid:84756419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893320/; classtype:trojan-activity;sid:84756420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893321/; classtype:trojan-activity;sid:84756421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/56708e"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893317/; classtype:trojan-activity;sid:84756417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8f0b0c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893315/; classtype:trojan-activity;sid:84756415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e04648"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893316/; classtype:trojan-activity;sid:84756416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893314/; classtype:trojan-activity;sid:84756414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893308/; classtype:trojan-activity;sid:84756408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893309/; classtype:trojan-activity;sid:84756409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893310/; classtype:trojan-activity;sid:84756410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893311/; classtype:trojan-activity;sid:84756411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893312/; classtype:trojan-activity;sid:84756412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"nobleshadebu.pro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893313/; classtype:trojan-activity;sid:84756413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tues/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"orienttaxtile.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893307/; classtype:trojan-activity;sid:84756407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.118.244.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893306/; classtype:trojan-activity;sid:84756406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.204.65"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893305/; classtype:trojan-activity;sid:84756405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.176.211.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893304/; classtype:trojan-activity;sid:84756404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"216.126.86.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893303/; classtype:trojan-activity;sid:84756403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.149.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893302/; classtype:trojan-activity;sid:84756402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"216.126.86.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893301/; classtype:trojan-activity;sid:84756401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.18.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893300/; classtype:trojan-activity;sid:84756400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.204.65"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893299/; classtype:trojan-activity;sid:84756399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.237.63.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893298/; classtype:trojan-activity;sid:84756398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.149.201"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893297/; classtype:trojan-activity;sid:84756397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.48.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893296/; classtype:trojan-activity;sid:84756396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ycl"; depth:4; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893295/; classtype:trojan-activity;sid:84756395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/service"; depth:8; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893294/; classtype:trojan-activity;sid:84756394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update"; depth:7; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893293/; classtype:trojan-activity;sid:84756393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.76.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893291/; classtype:trojan-activity;sid:84756391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.237.59"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893292/; classtype:trojan-activity;sid:84756392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/my-files/5.msi|3f|x-amz-algorithm=aws4-hmac-sha256|7c|26|7c|x-amz-credential=6483d30e4e635518dc3375a0d3ab56a6/20260727/auto/s3/aws4_request|7c|26|7c|x-amz-date=20260727t191829z|7c|26|7c|x-amz-expires=604800|7c|26|7c|x-amz-signedheaders=host|7c|26|7c|x-amz-signature=a9992d87e82deb0062b4299448b1050236e325aeaef616a16debb9690a8ca832"; depth:331; endswith; nocase; http.host; content:"1d2ef215ce65986951fe48e70c16d6d4.r2.cloudflarestorage.com"; depth:57; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893290/; classtype:trojan-activity;sid:84756390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/weds/crypted.ps1"; depth:17; endswith; nocase; http.host; content:"orienttaxtile.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893289/; classtype:trojan-activity;sid:84756389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fjp/zvjspngr.bat"; depth:17; endswith; nocase; http.host; content:"nfeletronica.sevendocumentos.vip"; depth:32; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893288/; classtype:trojan-activity;sid:84756388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_372e453e8176fe84.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893285/; classtype:trojan-activity;sid:84756385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_56a54f3ee74d7c37.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893286/; classtype:trojan-activity;sid:84756386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_9da84e402c095df5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893287/; classtype:trojan-activity;sid:84756387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.229.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893284/; classtype:trojan-activity;sid:84756384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.76.246"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893283/; classtype:trojan-activity;sid:84756383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.110.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893282/; classtype:trojan-activity;sid:84756382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.109.219.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893281/; classtype:trojan-activity;sid:84756381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.243.95.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893280/; classtype:trojan-activity;sid:84756380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.114.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893279/; classtype:trojan-activity;sid:84756379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.56.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893278/; classtype:trojan-activity;sid:84756378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.243.95.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893277/; classtype:trojan-activity;sid:84756377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.38.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893276/; classtype:trojan-activity;sid:84756376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.236.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893275/; classtype:trojan-activity;sid:84756375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.56.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893274/; classtype:trojan-activity;sid:84756374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ad7fd402048f3819.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893273/; classtype:trojan-activity;sid:84756373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.237.104"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893272/; classtype:trojan-activity;sid:84756372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.38.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893271/; classtype:trojan-activity;sid:84756371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.163.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893270/; classtype:trojan-activity;sid:84756370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.76.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893269/; classtype:trojan-activity;sid:84756369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.25.201"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893268/; classtype:trojan-activity;sid:84756368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.253.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893267/; classtype:trojan-activity;sid:84756367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.229.163.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893266/; classtype:trojan-activity;sid:84756366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"157.66.146.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893265/; classtype:trojan-activity;sid:84756365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.132.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893264/; classtype:trojan-activity;sid:84756364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"157.66.146.183"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893263/; classtype:trojan-activity;sid:84756363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.97.251.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893262/; classtype:trojan-activity;sid:84756362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.11.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893261/; classtype:trojan-activity;sid:84756361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.14.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893260/; classtype:trojan-activity;sid:84756360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"220.202.64.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893259/; classtype:trojan-activity;sid:84756359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/16.exe"; depth:7; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893258/; classtype:trojan-activity;sid:84756358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.166.39.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893257/; classtype:trojan-activity;sid:84756357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.15.19"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893256/; classtype:trojan-activity;sid:84756356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.231.228.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893255/; classtype:trojan-activity;sid:84756355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.14.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893254/; classtype:trojan-activity;sid:84756354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.157.252"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893253/; classtype:trojan-activity;sid:84756353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.58.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893252/; classtype:trojan-activity;sid:84756352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.122.196.88"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893251/; classtype:trojan-activity;sid:84756351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"2.177.76.111"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893250/; classtype:trojan-activity;sid:84756350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893249/; classtype:trojan-activity;sid:84756349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.154.78.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893248/; classtype:trojan-activity;sid:84756348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.231.228.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893247/; classtype:trojan-activity;sid:84756347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.58.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893246/; classtype:trojan-activity;sid:84756346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.74.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893245/; classtype:trojan-activity;sid:84756345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.157.252"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893244/; classtype:trojan-activity;sid:84756344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.86.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893243/; classtype:trojan-activity;sid:84756343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.17.95"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893242/; classtype:trojan-activity;sid:84756342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.59.89.146"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893241/; classtype:trojan-activity;sid:84756341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.28.66"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893240/; classtype:trojan-activity;sid:84756340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.46.234.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893239/; classtype:trojan-activity;sid:84756339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.99.227"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893238/; classtype:trojan-activity;sid:84756338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.34.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893237/; classtype:trojan-activity;sid:84756337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.7.114"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893236/; classtype:trojan-activity;sid:84756336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.7.114"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893232/; classtype:trojan-activity;sid:84756332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.89.194"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893233/; classtype:trojan-activity;sid:84756333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.5.24"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893234/; classtype:trojan-activity;sid:84756334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.78.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893235/; classtype:trojan-activity;sid:84756335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.93.243.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893224/; classtype:trojan-activity;sid:84756324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.234.235.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893225/; classtype:trojan-activity;sid:84756325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.35.172"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893226/; classtype:trojan-activity;sid:84756326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.46.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893227/; classtype:trojan-activity;sid:84756327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.116.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893228/; classtype:trojan-activity;sid:84756328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.24.85.12"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893229/; classtype:trojan-activity;sid:84756329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.221.74.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893230/; classtype:trojan-activity;sid:84756330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.209.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893231/; classtype:trojan-activity;sid:84756331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"94.154.43.203"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893222/; classtype:trojan-activity;sid:84756322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/setting.xml"; depth:17; endswith; nocase; http.host; content:"94.154.43.203"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893223/; classtype:trojan-activity;sid:84756323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.212.124"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893221/; classtype:trojan-activity;sid:84756321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.120.41.220"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893220/; classtype:trojan-activity;sid:84756320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.231.145.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893216/; classtype:trojan-activity;sid:84756316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.122.238.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893217/; classtype:trojan-activity;sid:84756317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.52.241.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893218/; classtype:trojan-activity;sid:84756318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.241.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893219/; classtype:trojan-activity;sid:84756319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.124.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893214/; classtype:trojan-activity;sid:84756314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.231.145.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893215/; classtype:trojan-activity;sid:84756315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.52.153.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893213/; classtype:trojan-activity;sid:84756313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.80.170"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893212/; classtype:trojan-activity;sid:84756312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.15.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893211/; classtype:trojan-activity;sid:84756311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.72.30.243"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893210/; classtype:trojan-activity;sid:84756310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.72.30.243"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893209/; classtype:trojan-activity;sid:84756309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"116.248.82.191"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893208/; classtype:trojan-activity;sid:84756308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.32.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893206/; classtype:trojan-activity;sid:84756306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.15.1"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893207/; classtype:trojan-activity;sid:84756307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.99.227"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893199/; classtype:trojan-activity;sid:84756299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.32.249"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893200/; classtype:trojan-activity;sid:84756300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.10.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893201/; classtype:trojan-activity;sid:84756301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.175.252"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893202/; classtype:trojan-activity;sid:84756302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.10.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893203/; classtype:trojan-activity;sid:84756303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.209.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893204/; classtype:trojan-activity;sid:84756304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.228.202"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893205/; classtype:trojan-activity;sid:84756305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.30.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893195/; classtype:trojan-activity;sid:84756295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.220.59"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893196/; classtype:trojan-activity;sid:84756296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.125.24.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893197/; classtype:trojan-activity;sid:84756297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.24.85.12"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893198/; classtype:trojan-activity;sid:84756298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.34.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893194/; classtype:trojan-activity;sid:84756294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.70.229.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893193/; classtype:trojan-activity;sid:84756293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.80.170"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893192/; classtype:trojan-activity;sid:84756292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.133.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893191/; classtype:trojan-activity;sid:84756291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.103.121.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893190/; classtype:trojan-activity;sid:84756290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.70.229.45"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893189/; classtype:trojan-activity;sid:84756289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.168.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893188/; classtype:trojan-activity;sid:84756288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.166.48.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893187/; classtype:trojan-activity;sid:84756287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.216.101.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893186/; classtype:trojan-activity;sid:84756286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.168.117"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893185/; classtype:trojan-activity;sid:84756285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893184/; classtype:trojan-activity;sid:84756284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.40.245"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893183/; classtype:trojan-activity;sid:84756283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.85.108.218"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893182/; classtype:trojan-activity;sid:84756282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893181/; classtype:trojan-activity;sid:84756281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.7.227.87"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893180/; classtype:trojan-activity;sid:84756280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.138.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893179/; classtype:trojan-activity;sid:84756279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.166.48.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893178/; classtype:trojan-activity;sid:84756278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.216.101.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893177/; classtype:trojan-activity;sid:84756277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.120.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893176/; classtype:trojan-activity;sid:84756276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.152.9.9"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893175/; classtype:trojan-activity;sid:84756275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.37.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893174/; classtype:trojan-activity;sid:84756274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.7.227.87"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893173/; classtype:trojan-activity;sid:84756273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.75.251"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893172/; classtype:trojan-activity;sid:84756272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.136.124.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893171/; classtype:trojan-activity;sid:84756271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.138.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893170/; classtype:trojan-activity;sid:84756270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qme1"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893168/; classtype:trojan-activity;sid:84756268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5ff"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893169/; classtype:trojan-activity;sid:84756269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.176.211.198"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893167/; classtype:trojan-activity;sid:84756267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.43.37.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893166/; classtype:trojan-activity;sid:84756266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.120.233"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893165/; classtype:trojan-activity;sid:84756265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lft3"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893164/; classtype:trojan-activity;sid:84756264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lrtt"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893163/; classtype:trojan-activity;sid:84756263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lrhq"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893162/; classtype:trojan-activity;sid:84756262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"220.158.234.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893159/; classtype:trojan-activity;sid:84756259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893160/; classtype:trojan-activity;sid:84756260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/m68k"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893161/; classtype:trojan-activity;sid:84756261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.166.39.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893158/; classtype:trojan-activity;sid:84756258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.197.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893157/; classtype:trojan-activity;sid:84756257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.136.124.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893156/; classtype:trojan-activity;sid:84756256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.173.214.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893155/; classtype:trojan-activity;sid:84756255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.95.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893154/; classtype:trojan-activity;sid:84756254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.95.67"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893153/; classtype:trojan-activity;sid:84756253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.118.88.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893152/; classtype:trojan-activity;sid:84756252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.147.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893151/; classtype:trojan-activity;sid:84756251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.173.214.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893150/; classtype:trojan-activity;sid:84756250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.133.47"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893149/; classtype:trojan-activity;sid:84756249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.56.135.237"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893148/; classtype:trojan-activity;sid:84756248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.34.242.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893147/; classtype:trojan-activity;sid:84756247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.118.88.64"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893146/; classtype:trojan-activity;sid:84756246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"94.45.34.166"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893145/; classtype:trojan-activity;sid:84756245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/8646908407/ovrg7ds.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893144/; classtype:trojan-activity;sid:84756244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/7782139129/tbxaqzf.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893143/; classtype:trojan-activity;sid:84756243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.196.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893142/; classtype:trojan-activity;sid:84756242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.218.62.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893141/; classtype:trojan-activity;sid:84756241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.51.123.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893140/; classtype:trojan-activity;sid:84756240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.196.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893139/; classtype:trojan-activity;sid:84756239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.34.242.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893138/; classtype:trojan-activity;sid:84756238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.51.123.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893137/; classtype:trojan-activity;sid:84756237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.218.62.176"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893136/; classtype:trojan-activity;sid:84756236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.46.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893135/; classtype:trojan-activity;sid:84756235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.exe"; depth:6; endswith; nocase; http.host; content:"hindustanagency.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893134/; classtype:trojan-activity;sid:84756234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"120.46.15.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893133/; classtype:trojan-activity;sid:84756233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"34.88.165.144"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893132/; classtype:trojan-activity;sid:84756232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"159.112.183.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893116/; classtype:trojan-activity;sid:84756216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"113.45.17.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893117/; classtype:trojan-activity;sid:84756217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"116.205.168.247"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893118/; classtype:trojan-activity;sid:84756218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"1.95.51.146"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893119/; classtype:trojan-activity;sid:84756219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"114.132.77.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893120/; classtype:trojan-activity;sid:84756220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"113.45.17.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893121/; classtype:trojan-activity;sid:84756221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"1.94.221.183"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893122/; classtype:trojan-activity;sid:84756222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"1.94.221.183"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893123/; classtype:trojan-activity;sid:84756223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"120.46.12.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893124/; classtype:trojan-activity;sid:84756224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"1.92.136.152"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893125/; classtype:trojan-activity;sid:84756225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"123.249.20.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893126/; classtype:trojan-activity;sid:84756226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"1.92.136.152"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893127/; classtype:trojan-activity;sid:84756227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"120.46.12.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893128/; classtype:trojan-activity;sid:84756228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"1.94.221.183"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893129/; classtype:trojan-activity;sid:84756229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"113.45.17.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893130/; classtype:trojan-activity;sid:84756230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"82.156.56.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893131/; classtype:trojan-activity;sid:84756231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"34.88.165.144"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893110/; classtype:trojan-activity;sid:84756210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"116.205.168.247"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893111/; classtype:trojan-activity;sid:84756211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"120.46.15.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893112/; classtype:trojan-activity;sid:84756212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"116.205.168.247"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893113/; classtype:trojan-activity;sid:84756213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"1.95.51.146"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893114/; classtype:trojan-activity;sid:84756214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"114.132.77.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893115/; classtype:trojan-activity;sid:84756215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"123.249.20.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893109/; classtype:trojan-activity;sid:84756209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"1.92.101.221"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893104/; classtype:trojan-activity;sid:84756204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"139.159.233.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893105/; classtype:trojan-activity;sid:84756205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"82.156.56.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893106/; classtype:trojan-activity;sid:84756206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"1.92.101.221"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893107/; classtype:trojan-activity;sid:84756207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"82.156.56.214"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893108/; classtype:trojan-activity;sid:84756208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"159.112.183.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893102/; classtype:trojan-activity;sid:84756202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"159.112.183.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893103/; classtype:trojan-activity;sid:84756203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"120.46.15.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893101/; classtype:trojan-activity;sid:84756201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"123.249.20.250"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893100/; classtype:trojan-activity;sid:84756200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"114.132.77.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893096/; classtype:trojan-activity;sid:84756196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"139.159.233.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893097/; classtype:trojan-activity;sid:84756197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"120.46.12.14"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893098/; classtype:trojan-activity;sid:84756198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"1.95.51.146"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893099/; classtype:trojan-activity;sid:84756199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"1.92.101.221"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893093/; classtype:trojan-activity;sid:84756193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"1.92.136.152"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893094/; classtype:trojan-activity;sid:84756194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"139.159.233.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893095/; classtype:trojan-activity;sid:84756195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"34.88.165.144"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893092/; classtype:trojan-activity;sid:84756192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.236.101.64"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893090/; classtype:trojan-activity;sid:84756190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.247.255.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893091/; classtype:trojan-activity;sid:84756191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update.cmd"; depth:11; endswith; nocase; http.host; content:"157.245.34.109"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893089/; classtype:trojan-activity;sid:84756189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.186.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893088/; classtype:trojan-activity;sid:84756188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.188.57"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893087/; classtype:trojan-activity;sid:84756187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.44.137.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893086/; classtype:trojan-activity;sid:84756186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdyusagyisdfdygufs"; depth:19; endswith; nocase; http.host; content:"144.31.148.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893085/; classtype:trojan-activity;sid:84756185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.188.57"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893084/; classtype:trojan-activity;sid:84756184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.34.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893083/; classtype:trojan-activity;sid:84756183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.44.137.12"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893082/; classtype:trojan-activity;sid:84756182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.208.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893081/; classtype:trojan-activity;sid:84756181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_old/real_mips"; depth:21; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893079/; classtype:trojan-activity;sid:84756179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_old/real_arm64"; depth:22; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893080/; classtype:trojan-activity;sid:84756180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_old/real_x86_64"; depth:23; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893076/; classtype:trojan-activity;sid:84756176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_old/real_mipsel"; depth:23; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893077/; classtype:trojan-activity;sid:84756177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/backup_old/real_arm"; depth:20; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893078/; classtype:trojan-activity;sid:84756178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.43.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893075/; classtype:trojan-activity;sid:84756175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.187.137"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893074/; classtype:trojan-activity;sid:84756174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.91.116.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893073/; classtype:trojan-activity;sid:84756173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.54.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893072/; classtype:trojan-activity;sid:84756172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.91.116.175"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893071/; classtype:trojan-activity;sid:84756171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teamm.ps1"; depth:10; endswith; nocase; http.host; content:"malaysianpastrybakery.org"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893070/; classtype:trojan-activity;sid:84756170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ttt.png"; depth:8; endswith; nocase; http.host; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893067/; classtype:trojan-activity;sid:84756167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hgziy"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893068/; classtype:trojan-activity;sid:84756168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/admin/niceimg_122852.png"; depth:25; endswith; nocase; http.host; content:"sunix-technology.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893069/; classtype:trojan-activity;sid:84756169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/admin/newmsi_pro.png"; depth:21; endswith; nocase; http.host; content:"sunix-technology.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893066/; classtype:trojan-activity;sid:84756166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.205.208.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893065/; classtype:trojan-activity;sid:84756165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.54.124"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893064/; classtype:trojan-activity;sid:84756164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893063/; classtype:trojan-activity;sid:84756163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893061/; classtype:trojan-activity;sid:84756161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893062/; classtype:trojan-activity;sid:84756162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893060/; classtype:trojan-activity;sid:84756160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893059/; classtype:trojan-activity;sid:84756159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893053/; classtype:trojan-activity;sid:84756153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893054/; classtype:trojan-activity;sid:84756154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893055/; classtype:trojan-activity;sid:84756155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893056/; classtype:trojan-activity;sid:84756156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893057/; classtype:trojan-activity;sid:84756157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893058/; classtype:trojan-activity;sid:84756158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893050/; classtype:trojan-activity;sid:84756150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893051/; classtype:trojan-activity;sid:84756151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"94.154.43.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893052/; classtype:trojan-activity;sid:84756152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/mz.x86_64"; depth:13; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893049/; classtype:trojan-activity;sid:84756149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyj2zekmt0tftabkg9fnrt8w"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893048/; classtype:trojan-activity;sid:84756148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyj3fwrgv7gtxph4vq7071tj"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893046/; classtype:trojan-activity;sid:84756146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyhnyxvdre60bm6qdq95gjrv"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893047/; classtype:trojan-activity;sid:84756147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyhb8k9rvqqwajxvnrtqtjpb"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893045/; classtype:trojan-activity;sid:84756145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kycr02ej7dta93swy6h8paaw"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893044/; classtype:trojan-activity;sid:84756144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyhhjyfhh685h8txnxrqg20a"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893042/; classtype:trojan-activity;sid:84756142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyhvwwtv8z93y6g3a7qwkq1s"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893043/; classtype:trojan-activity;sid:84756143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyhn9kv0vhpqg19fk26f7wf1"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893040/; classtype:trojan-activity;sid:84756140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kycn26dzsm0saq83jkv6v9bs"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893041/; classtype:trojan-activity;sid:84756141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/developmentteamx/developmenxxx/main/chromeelevator.exe"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893039/; classtype:trojan-activity;sid:84756139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyhgvgcyvwkd5gg3s7g9wrss"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893037/; classtype:trojan-activity;sid:84756137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyfeyvhff8bw6rqgkmr0szpf"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893038/; classtype:trojan-activity;sid:84756138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01kyey32stbhhrjehqfqnn4mqs"; depth:27; endswith; nocase; http.host; content:"pstbn.dev"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893036/; classtype:trojan-activity;sid:84756136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv6l"; depth:12; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893034/; classtype:trojan-activity;sid:84756134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv7l"; depth:12; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893035/; classtype:trojan-activity;sid:84756135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893020/; classtype:trojan-activity;sid:84756120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv4l"; depth:12; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893021/; classtype:trojan-activity;sid:84756121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.sh4"; depth:9; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893022/; classtype:trojan-activity;sid:84756122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mipsrouter"; depth:16; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893023/; classtype:trojan-activity;sid:84756123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.aarch64"; depth:13; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893024/; classtype:trojan-activity;sid:84756124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.x86"; depth:9; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893025/; classtype:trojan-activity;sid:84756125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.sparc"; depth:11; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893026/; classtype:trojan-activity;sid:84756126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv5l"; depth:12; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893027/; classtype:trojan-activity;sid:84756127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.m68k"; depth:10; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893028/; classtype:trojan-activity;sid:84756128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.arc"; depth:9; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893029/; classtype:trojan-activity;sid:84756129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.i486"; depth:10; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893030/; classtype:trojan-activity;sid:84756130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.powerpc"; depth:13; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893031/; classtype:trojan-activity;sid:84756131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mips"; depth:10; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893032/; classtype:trojan-activity;sid:84756132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mipsel"; depth:12; endswith; nocase; http.host; content:"217.60.195.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893033/; classtype:trojan-activity;sid:84756133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mipsrouter"; depth:16; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893018/; classtype:trojan-activity;sid:84756118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"111.178.125.136"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893019/; classtype:trojan-activity;sid:84756119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893016/; classtype:trojan-activity;sid:84756116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.76.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893017/; classtype:trojan-activity;sid:84756117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arc"; depth:10; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893012/; classtype:trojan-activity;sid:84756112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i686"; depth:11; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893013/; classtype:trojan-activity;sid:84756113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893014/; classtype:trojan-activity;sid:84756114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893015/; classtype:trojan-activity;sid:84756115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893003/; classtype:trojan-activity;sid:84756103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893004/; classtype:trojan-activity;sid:84756104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893005/; classtype:trojan-activity;sid:84756105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893006/; classtype:trojan-activity;sid:84756106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893007/; classtype:trojan-activity;sid:84756107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893008/; classtype:trojan-activity;sid:84756108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arc"; depth:10; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893009/; classtype:trojan-activity;sid:84756109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm7"; depth:11; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893010/; classtype:trojan-activity;sid:84756110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893011/; classtype:trojan-activity;sid:84756111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893002/; classtype:trojan-activity;sid:84756102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/o.xml"; depth:9; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892999/; classtype:trojan-activity;sid:84756099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893000/; classtype:trojan-activity;sid:84756100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893001/; classtype:trojan-activity;sid:84756101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm"; depth:10; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892997/; classtype:trojan-activity;sid:84756097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892998/; classtype:trojan-activity;sid:84756098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892995/; classtype:trojan-activity;sid:84756095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892996/; classtype:trojan-activity;sid:84756096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"31-56-209-153.cprapid.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892993/; classtype:trojan-activity;sid:84756093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm"; depth:10; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892994/; classtype:trojan-activity;sid:84756094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892991/; classtype:trojan-activity;sid:84756091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i686"; depth:11; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892992/; classtype:trojan-activity;sid:84756092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm"; depth:10; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892990/; classtype:trojan-activity;sid:84756090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i686"; depth:11; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892989/; classtype:trojan-activity;sid:84756089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arc"; depth:10; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892987/; classtype:trojan-activity;sid:84756087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892988/; classtype:trojan-activity;sid:84756088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892985/; classtype:trojan-activity;sid:84756085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892986/; classtype:trojan-activity;sid:84756086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.205.208.226"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892984/; classtype:trojan-activity;sid:84756084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6272"; depth:5; endswith; nocase; http.host; content:"fine-work-team.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892983/; classtype:trojan-activity;sid:84756083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.43.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892982/; classtype:trojan-activity;sid:84756082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.153.133.160"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892981/; classtype:trojan-activity;sid:84756081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892980/; classtype:trojan-activity;sid:84756080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/93/goodthingswithbestnetworkingskillcomingfromtheheartforme.js"; depth:63; endswith; nocase; http.host; content:"204.44.69.216"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892979/; classtype:trojan-activity;sid:84756079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/93/ecce/givenmethebestthignswithbetterplacescomingfromthebest.hta"; depth:66; endswith; nocase; http.host; content:"204.44.69.216"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892978/; classtype:trojan-activity;sid:84756078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/5851730241/zxnbt4g.exe"; depth:29; endswith; nocase; http.host; content:"62.60.226.140"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892977/; classtype:trojan-activity;sid:84756077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/14d"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892972/; classtype:trojan-activity;sid:84756072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qva"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892973/; classtype:trojan-activity;sid:84756073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emu"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892974/; classtype:trojan-activity;sid:84756074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djr"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892975/; classtype:trojan-activity;sid:84756075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ftop"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892976/; classtype:trojan-activity;sid:84756076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exec_binary"; depth:12; endswith; nocase; http.host; content:"94.154.43.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892971/; classtype:trojan-activity;sid:84756071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892970/; classtype:trojan-activity;sid:84756070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.21.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892968/; classtype:trojan-activity;sid:84756068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.237.98.82"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892969/; classtype:trojan-activity;sid:84756069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.21.172"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892967/; classtype:trojan-activity;sid:84756067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.242.84.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892966/; classtype:trojan-activity;sid:84756066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.73.125"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892965/; classtype:trojan-activity;sid:84756065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.242.84.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892964/; classtype:trojan-activity;sid:84756064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.122.39"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892963/; classtype:trojan-activity;sid:84756063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.70.192.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892962/; classtype:trojan-activity;sid:84756062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_669902b87da3f16e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892961/; classtype:trojan-activity;sid:84756061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.141.233.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892960/; classtype:trojan-activity;sid:84756060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.134.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892959/; classtype:trojan-activity;sid:84756059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.70.192.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892958/; classtype:trojan-activity;sid:84756058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"185.141.233.178"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892957/; classtype:trojan-activity;sid:84756057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.70.225.171"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892956/; classtype:trojan-activity;sid:84756056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.127.59"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892955/; classtype:trojan-activity;sid:84756055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.202.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892954/; classtype:trojan-activity;sid:84756054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.63.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892953/; classtype:trojan-activity;sid:84756053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.127.59"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892952/; classtype:trojan-activity;sid:84756052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.134.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892951/; classtype:trojan-activity;sid:84756051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.58.160.115"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892950/; classtype:trojan-activity;sid:84756050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"reservphotoinstaynow.shop"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892949/; classtype:trojan-activity;sid:84756049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.190.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892948/; classtype:trojan-activity;sid:84756048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1158-27.exe"; depth:12; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892946/; classtype:trojan-activity;sid:84756046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dun0uclxi/image/upload/v1785205268/img_191949_mvcfdt.jpg"; depth:57; endswith; nocase; http.host; content:"res.cloudinary.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892947/; classtype:trojan-activity;sid:84756047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.132.154"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892945/; classtype:trojan-activity;sid:84756045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.15.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892944/; classtype:trojan-activity;sid:84756044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.15.2"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892943/; classtype:trojan-activity;sid:84756043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.190.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892942/; classtype:trojan-activity;sid:84756042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.51.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892941/; classtype:trojan-activity;sid:84756041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.219.74.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892940/; classtype:trojan-activity;sid:84756040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.230.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892939/; classtype:trojan-activity;sid:84756039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.19.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892938/; classtype:trojan-activity;sid:84756038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.219.74.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892937/; classtype:trojan-activity;sid:84756037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.122.39"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892936/; classtype:trojan-activity;sid:84756036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.230.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892935/; classtype:trojan-activity;sid:84756035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.52.154.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892934/; classtype:trojan-activity;sid:84756034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.156.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892933/; classtype:trojan-activity;sid:84756033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.118.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892932/; classtype:trojan-activity;sid:84756032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.51.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892931/; classtype:trojan-activity;sid:84756031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.127.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892930/; classtype:trojan-activity;sid:84756030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.90.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892929/; classtype:trojan-activity;sid:84756029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.35.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892928/; classtype:trojan-activity;sid:84756028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"37.52.154.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892927/; classtype:trojan-activity;sid:84756027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.237.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892926/; classtype:trojan-activity;sid:84756026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.178.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892925/; classtype:trojan-activity;sid:84756025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.178.22"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892923/; classtype:trojan-activity;sid:84756023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.46.142"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892924/; classtype:trojan-activity;sid:84756024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.14.106.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892922/; classtype:trojan-activity;sid:84756022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/client.exe"; depth:11; endswith; nocase; http.host; content:"94.26.90.90"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892921/; classtype:trojan-activity;sid:84756021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kworker_u8"; depth:16; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892920/; classtype:trojan-activity;sid:84756020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/scsi_tmf_0"; depth:16; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892919/; classtype:trojan-activity;sid:84756019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/rcuop_0"; depth:13; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892918/; classtype:trojan-activity;sid:84756018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xfsaild_sda"; depth:17; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892917/; classtype:trojan-activity;sid:84756017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.4.139.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892915/; classtype:trojan-activity;sid:84756015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/zswap_shrinkd"; depth:19; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892916/; classtype:trojan-activity;sid:84756016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/edac_polld"; depth:16; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892914/; classtype:trojan-activity;sid:84756014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/cfg80211d"; depth:15; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892913/; classtype:trojan-activity;sid:84756013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ecryptfsd"; depth:15; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892912/; classtype:trojan-activity;sid:84756012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/jbd2_sda1d"; depth:16; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892911/; classtype:trojan-activity;sid:84756011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/devfreq_wq"; depth:16; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892909/; classtype:trojan-activity;sid:84756009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ksoftirqd0"; depth:16; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892910/; classtype:trojan-activity;sid:84756010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kblockd0"; depth:14; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892908/; classtype:trojan-activity;sid:84756008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/bioset0"; depth:13; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892907/; classtype:trojan-activity;sid:84756007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loader.sh"; depth:10; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892905/; classtype:trojan-activity;sid:84756005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kswapd0"; depth:13; endswith; nocase; http.host; content:"185.139.214.200"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892906/; classtype:trojan-activity;sid:84756006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.141.131.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892904/; classtype:trojan-activity;sid:84756004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.29.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892903/; classtype:trojan-activity;sid:84756003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.14.106.122"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892902/; classtype:trojan-activity;sid:84756002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.141.131.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892901/; classtype:trojan-activity;sid:84756001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.80.57.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892900/; classtype:trojan-activity;sid:84756000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.139.99"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892899/; classtype:trojan-activity;sid:84755999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.11.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892898/; classtype:trojan-activity;sid:84755998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.198.130.140"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892897/; classtype:trojan-activity;sid:84755997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.29.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892896/; classtype:trojan-activity;sid:84755996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"85.120.81.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892895/; classtype:trojan-activity;sid:84755995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.165.30.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892894/; classtype:trojan-activity;sid:84755994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c2lv"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892893/; classtype:trojan-activity;sid:84755993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akmh"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892889/; classtype:trojan-activity;sid:84755989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0f9"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892890/; classtype:trojan-activity;sid:84755990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xvg"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892891/; classtype:trojan-activity;sid:84755991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jst0"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892892/; classtype:trojan-activity;sid:84755992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fqaz"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892888/; classtype:trojan-activity;sid:84755988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yi8"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892884/; classtype:trojan-activity;sid:84755984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2rl1"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892885/; classtype:trojan-activity;sid:84755985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sa0"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892886/; classtype:trojan-activity;sid:84755986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s9w"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892887/; classtype:trojan-activity;sid:84755987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.165.30.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892883/; classtype:trojan-activity;sid:84755983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/client.exe"; depth:11; endswith; nocase; http.host; content:"91.199.133.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892882/; classtype:trojan-activity;sid:84755982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.84.215.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892881/; classtype:trojan-activity;sid:84755981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.84.215.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892880/; classtype:trojan-activity;sid:84755980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.248.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892879/; classtype:trojan-activity;sid:84755979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.193.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892878/; classtype:trojan-activity;sid:84755978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.113.248.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892877/; classtype:trojan-activity;sid:84755977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.142.220.59"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892876/; classtype:trojan-activity;sid:84755976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.193.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892875/; classtype:trojan-activity;sid:84755975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"193.187.101.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892874/; classtype:trojan-activity;sid:84755974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"182.112.30.222"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892873/; classtype:trojan-activity;sid:84755973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/odot/download.php"; depth:18; endswith; nocase; http.host; content:"cuttingedgefencing.ca"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892872/; classtype:trojan-activity;sid:84755972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.85.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892871/; classtype:trojan-activity;sid:84755971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.197.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892870/; classtype:trojan-activity;sid:84755970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"193.187.101.227"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892869/; classtype:trojan-activity;sid:84755969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.10.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892868/; classtype:trojan-activity;sid:84755968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"91.92.34.123"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892867/; classtype:trojan-activity;sid:84755967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"91.92.34.123"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892866/; classtype:trojan-activity;sid:84755966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.156.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892865/; classtype:trojan-activity;sid:84755965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/client.exe"; depth:11; endswith; nocase; http.host; content:"91.92.43.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892864/; classtype:trojan-activity;sid:84755964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.197.90"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892863/; classtype:trojan-activity;sid:84755963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.37.10.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892862/; classtype:trojan-activity;sid:84755962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.85.152"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892861/; classtype:trojan-activity;sid:84755961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rogerz7.exe"; depth:12; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892860/; classtype:trojan-activity;sid:84755960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.15.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892859/; classtype:trojan-activity;sid:84755959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.130.133.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892858/; classtype:trojan-activity;sid:84755958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.66.229.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892857/; classtype:trojan-activity;sid:84755957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.87.15.172"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892856/; classtype:trojan-activity;sid:84755956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.87.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892855/; classtype:trojan-activity;sid:84755955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"178.66.229.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892854/; classtype:trojan-activity;sid:84755954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.242.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892853/; classtype:trojan-activity;sid:84755953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.146.153.129"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892852/; classtype:trojan-activity;sid:84755952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_arm64"; depth:11; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892848/; classtype:trojan-activity;sid:84755948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rawbot_mipsel"; depth:14; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892849/; classtype:trojan-activity;sid:84755949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm"; depth:8; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892850/; classtype:trojan-activity;sid:84755950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.x86_64"; depth:11; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892851/; classtype:trojan-activity;sid:84755951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_discord"; depth:12; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892843/; classtype:trojan-activity;sid:84755943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test_mipsel_26"; depth:15; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892844/; classtype:trojan-activity;sid:84755944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_attack"; depth:11; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892845/; classtype:trojan-activity;sid:84755945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test_mips_26"; depth:13; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892846/; classtype:trojan-activity;sid:84755946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/condi_c2"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892847/; classtype:trojan-activity;sid:84755947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vivotek.py"; depth:11; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892842/; classtype:trojan-activity;sid:84755942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/router_exploit_v2"; depth:18; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892841/; classtype:trojan-activity;sid:84755941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_x86_64"; depth:12; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892837/; classtype:trojan-activity;sid:84755937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.x86_64"; depth:11; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892838/; classtype:trojan-activity;sid:84755938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm64"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892839/; classtype:trojan-activity;sid:84755939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/discord_mipsel"; depth:15; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892840/; classtype:trojan-activity;sid:84755940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mipsel"; depth:11; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892828/; classtype:trojan-activity;sid:84755928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_mipsel"; depth:12; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892829/; classtype:trojan-activity;sid:84755929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rawbot_mips"; depth:12; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892830/; classtype:trojan-activity;sid:84755930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_mips"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892831/; classtype:trojan-activity;sid:84755931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm64"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892832/; classtype:trojan-activity;sid:84755932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.arm"; depth:8; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892833/; classtype:trojan-activity;sid:84755933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/real_arm"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892834/; classtype:trojan-activity;sid:84755934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/router_exploit"; depth:15; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892835/; classtype:trojan-activity;sid:84755935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/listen_v3"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892836/; classtype:trojan-activity;sid:84755936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mips"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892825/; classtype:trojan-activity;sid:84755925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boa_attacker"; depth:13; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892826/; classtype:trojan-activity;sid:84755926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.mipsel"; depth:11; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892827/; classtype:trojan-activity;sid:84755927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mips"; depth:9; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892824/; classtype:trojan-activity;sid:84755924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.sql"; depth:12; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892823/; classtype:trojan-activity;sid:84755923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.237.3.199"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892822/; classtype:trojan-activity;sid:84755922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.228.40.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892821/; classtype:trojan-activity;sid:84755921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.204.233.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892820/; classtype:trojan-activity;sid:84755920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.191.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892819/; classtype:trojan-activity;sid:84755919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.229.242.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892818/; classtype:trojan-activity;sid:84755918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.153.223"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892816/; classtype:trojan-activity;sid:84755916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.86.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892817/; classtype:trojan-activity;sid:84755917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.204.233.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892815/; classtype:trojan-activity;sid:84755915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.84.5"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892814/; classtype:trojan-activity;sid:84755914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.153.223"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892813/; classtype:trojan-activity;sid:84755913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.114.76"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892812/; classtype:trojan-activity;sid:84755912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.9.244.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892811/; classtype:trojan-activity;sid:84755911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.93.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892810/; classtype:trojan-activity;sid:84755910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.137.93.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892809/; classtype:trojan-activity;sid:84755909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.118.28"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892808/; classtype:trojan-activity;sid:84755908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.75.251"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892807/; classtype:trojan-activity;sid:84755907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.122.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892806/; classtype:trojan-activity;sid:84755906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.19.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892805/; classtype:trojan-activity;sid:84755905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.118.28"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892804/; classtype:trojan-activity;sid:84755904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.80.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892803/; classtype:trojan-activity;sid:84755903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.21.26.73"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892802/; classtype:trojan-activity;sid:84755902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.118.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892801/; classtype:trojan-activity;sid:84755901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.86.16"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892800/; classtype:trojan-activity;sid:84755900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.244.177"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892799/; classtype:trojan-activity;sid:84755899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.227.48.176"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892798/; classtype:trojan-activity;sid:84755898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.27.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892797/; classtype:trojan-activity;sid:84755897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.201.204"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892796/; classtype:trojan-activity;sid:84755896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.213.145.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892795/; classtype:trojan-activity;sid:84755895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.13.27.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892794/; classtype:trojan-activity;sid:84755894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.160.138.209"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892793/; classtype:trojan-activity;sid:84755893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.58.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892792/; classtype:trojan-activity;sid:84755892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.124.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892791/; classtype:trojan-activity;sid:84755891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.213.145.140"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892790/; classtype:trojan-activity;sid:84755890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.160.138.209"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892789/; classtype:trojan-activity;sid:84755889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.65.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892788/; classtype:trojan-activity;sid:84755888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.226.217.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892787/; classtype:trojan-activity;sid:84755887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.65.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892786/; classtype:trojan-activity;sid:84755886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.228.108"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892785/; classtype:trojan-activity;sid:84755885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.163.66"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892784/; classtype:trojan-activity;sid:84755884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.226.217.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892783/; classtype:trojan-activity;sid:84755883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.26.83.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892782/; classtype:trojan-activity;sid:84755882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.26.83.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892781/; classtype:trojan-activity;sid:84755881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.119.163.66"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892780/; classtype:trojan-activity;sid:84755880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.42.71.239"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892779/; classtype:trojan-activity;sid:84755879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.53.85.165"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892778/; classtype:trojan-activity;sid:84755878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.179.255.108"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892777/; classtype:trojan-activity;sid:84755877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.52.153.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892776/; classtype:trojan-activity;sid:84755876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"85.108.65.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892775/; classtype:trojan-activity;sid:84755875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.43.18.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892773/; classtype:trojan-activity;sid:84755873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.12.27.213"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892774/; classtype:trojan-activity;sid:84755874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.23.67.50"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892772/; classtype:trojan-activity;sid:84755872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"85.108.65.212"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892771/; classtype:trojan-activity;sid:84755871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.125.24.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892770/; classtype:trojan-activity;sid:84755870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.77.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892769/; classtype:trojan-activity;sid:84755869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.247.88.98"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892768/; classtype:trojan-activity;sid:84755868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.252.17.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892767/; classtype:trojan-activity;sid:84755867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.23.67.50"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892766/; classtype:trojan-activity;sid:84755866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.230.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892765/; classtype:trojan-activity;sid:84755865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.81.84"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892764/; classtype:trojan-activity;sid:84755864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"77.247.88.98"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892763/; classtype:trojan-activity;sid:84755863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.7.220.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892762/; classtype:trojan-activity;sid:84755862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.202.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892761/; classtype:trojan-activity;sid:84755861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.13.72.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892760/; classtype:trojan-activity;sid:84755860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"1.58.225.143"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892759/; classtype:trojan-activity;sid:84755859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.230.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892758/; classtype:trojan-activity;sid:84755858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.41.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892757/; classtype:trojan-activity;sid:84755857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.54.83.67"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892756/; classtype:trojan-activity;sid:84755856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.167.3.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892755/; classtype:trojan-activity;sid:84755855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.49.202.73"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892754/; classtype:trojan-activity;sid:84755854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.104.102"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892753/; classtype:trojan-activity;sid:84755853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.252.17.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892752/; classtype:trojan-activity;sid:84755852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.50.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892751/; classtype:trojan-activity;sid:84755851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.41.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892750/; classtype:trojan-activity;sid:84755850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.225.69.32"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892749/; classtype:trojan-activity;sid:84755849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.190.85.135"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892748/; classtype:trojan-activity;sid:84755848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.54.43.141"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892747/; classtype:trojan-activity;sid:84755847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.99.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892746/; classtype:trojan-activity;sid:84755846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"39.74.83.192"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892745/; classtype:trojan-activity;sid:84755845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.114.193.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892744/; classtype:trojan-activity;sid:84755844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.53.219.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892743/; classtype:trojan-activity;sid:84755843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.225.69.32"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892742/; classtype:trojan-activity;sid:84755842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.54.43.141"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892741/; classtype:trojan-activity;sid:84755841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.53.219.93"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892740/; classtype:trojan-activity;sid:84755840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.172.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892739/; classtype:trojan-activity;sid:84755839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.8.183"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892738/; classtype:trojan-activity;sid:84755838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892726/; classtype:trojan-activity;sid:84755826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892727/; classtype:trojan-activity;sid:84755827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892728/; classtype:trojan-activity;sid:84755828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892729/; classtype:trojan-activity;sid:84755829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892730/; classtype:trojan-activity;sid:84755830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892731/; classtype:trojan-activity;sid:84755831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86_64"; depth:12; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892732/; classtype:trojan-activity;sid:84755832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pm68k"; depth:11; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892733/; classtype:trojan-activity;sid:84755833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pspc"; depth:10; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892734/; classtype:trojan-activity;sid:84755834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892735/; classtype:trojan-activity;sid:84755835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892736/; classtype:trojan-activity;sid:84755836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"31.77.227.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892737/; classtype:trojan-activity;sid:84755837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.dat"; depth:12; endswith; nocase; http.host; content:"breakneckridgefarm.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892725/; classtype:trojan-activity;sid:84755825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p.dat"; depth:6; endswith; nocase; http.host; content:"breakneckridgefarm.com"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892723/; classtype:trojan-activity;sid:84755823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s.dat"; depth:6; endswith; nocase; http.host; content:"babydiapersinturkey.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892724/; classtype:trojan-activity;sid:84755824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.11.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892722/; classtype:trojan-activity;sid:84755822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bc66ca0f4630d09d|3f|_=1"; depth:24; endswith; nocase; http.host; content:"auth-clo-id.cc"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892721/; classtype:trojan-activity;sid:84755821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"167.250.158.32"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892720/; classtype:trojan-activity;sid:84755820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bc66ca0f4630d09d"; depth:17; endswith; nocase; http.host; content:"auth-clo-id.cc"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892719/; classtype:trojan-activity;sid:84755819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.11.194"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892718/; classtype:trojan-activity;sid:84755818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/l.dat"; depth:6; endswith; nocase; http.host; content:"babydiapersinturkey.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892717/; classtype:trojan-activity;sid:84755817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/corp_/a"; depth:8; endswith; nocase; http.host; content:"178.16.55.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892716/; classtype:trojan-activity;sid:84755816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lsd"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892715/; classtype:trojan-activity;sid:84755815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/548a4b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892679/; classtype:trojan-activity;sid:84755779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60972b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892680/; classtype:trojan-activity;sid:84755780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efdf59"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892681/; classtype:trojan-activity;sid:84755781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/847891"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892682/; classtype:trojan-activity;sid:84755782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/68cf32"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892683/; classtype:trojan-activity;sid:84755783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e5149f"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892684/; classtype:trojan-activity;sid:84755784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/416c24"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892685/; classtype:trojan-activity;sid:84755785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4f0ee7"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892686/; classtype:trojan-activity;sid:84755786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f4213d"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892687/; classtype:trojan-activity;sid:84755787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8918c0"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892688/; classtype:trojan-activity;sid:84755788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b40728"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892689/; classtype:trojan-activity;sid:84755789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e00c4f"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892690/; classtype:trojan-activity;sid:84755790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/af1816"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892691/; classtype:trojan-activity;sid:84755791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ffc936"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892692/; classtype:trojan-activity;sid:84755792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3f3707"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892693/; classtype:trojan-activity;sid:84755793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/13916c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892694/; classtype:trojan-activity;sid:84755794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1f75c8"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892695/; classtype:trojan-activity;sid:84755795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c41752"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892696/; classtype:trojan-activity;sid:84755796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1d7077"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892697/; classtype:trojan-activity;sid:84755797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c55748"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892698/; classtype:trojan-activity;sid:84755798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1f7e12"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892699/; classtype:trojan-activity;sid:84755799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/07add9"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892700/; classtype:trojan-activity;sid:84755800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/574f6b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892701/; classtype:trojan-activity;sid:84755801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6e493b"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892702/; classtype:trojan-activity;sid:84755802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/294511"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892703/; classtype:trojan-activity;sid:84755803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/30c219"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892704/; classtype:trojan-activity;sid:84755804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2cf376"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892705/; classtype:trojan-activity;sid:84755805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/29dce8"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892706/; classtype:trojan-activity;sid:84755806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e68974"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892707/; classtype:trojan-activity;sid:84755807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/774855"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892708/; classtype:trojan-activity;sid:84755808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e5f05f"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892709/; classtype:trojan-activity;sid:84755809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0a97c9"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892710/; classtype:trojan-activity;sid:84755810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/04c7aa"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892711/; classtype:trojan-activity;sid:84755811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0c5ead"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892712/; classtype:trojan-activity;sid:84755812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4b1651"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892713/; classtype:trojan-activity;sid:84755813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/361156"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892714/; classtype:trojan-activity;sid:84755814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhrm"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892678/; classtype:trojan-activity;sid:84755778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dmff"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892675/; classtype:trojan-activity;sid:84755775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rwh"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892676/; classtype:trojan-activity;sid:84755776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uoa"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892677/; classtype:trojan-activity;sid:84755777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"177.86.229.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892674/; classtype:trojan-activity;sid:84755774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"42.234.144.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892673/; classtype:trojan-activity;sid:84755773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.19.101"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892672/; classtype:trojan-activity;sid:84755772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img/1.jpg"; depth:10; endswith; nocase; http.host; content:"192.255.195.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892671/; classtype:trojan-activity;sid:84755771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_73ed34a7752ecb3a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892670/; classtype:trojan-activity;sid:84755770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/all.sh"; depth:7; endswith; nocase; http.host; content:"159.223.110.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892666/; classtype:trojan-activity;sid:84755766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_cd9c2f76b688ed8a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892667/; classtype:trojan-activity;sid:84755767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_aa93170430df9ad7.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892668/; classtype:trojan-activity;sid:84755768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/all.sh"; depth:7; endswith; nocase; http.host; content:"159.223.110.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892669/; classtype:trojan-activity;sid:84755769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.198.118.73"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892665/; classtype:trojan-activity;sid:84755765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.93.243.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892664/; classtype:trojan-activity;sid:84755764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"177.86.229.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892663/; classtype:trojan-activity;sid:84755763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_d6c984cb6c46bf3c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892662/; classtype:trojan-activity;sid:84755762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.32.46"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892661/; classtype:trojan-activity;sid:84755761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.8.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892660/; classtype:trojan-activity;sid:84755760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.16.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892659/; classtype:trojan-activity;sid:84755759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.225.189.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892658/; classtype:trojan-activity;sid:84755758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.218.170"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892657/; classtype:trojan-activity;sid:84755757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.247.88.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892656/; classtype:trojan-activity;sid:84755756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.176.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892655/; classtype:trojan-activity;sid:84755755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.99.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892654/; classtype:trojan-activity;sid:84755754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"180.107.162.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892652/; classtype:trojan-activity;sid:84755752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.16.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892653/; classtype:trojan-activity;sid:84755753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.225.189.9"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892651/; classtype:trojan-activity;sid:84755751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"77.247.88.121"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892650/; classtype:trojan-activity;sid:84755750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.176.102"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892649/; classtype:trojan-activity;sid:84755749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.62.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892648/; classtype:trojan-activity;sid:84755748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.99.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892647/; classtype:trojan-activity;sid:84755747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.55.62.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892646/; classtype:trojan-activity;sid:84755746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.231.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892645/; classtype:trojan-activity;sid:84755745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.8.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892644/; classtype:trojan-activity;sid:84755744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.245.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892643/; classtype:trojan-activity;sid:84755743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.237.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892642/; classtype:trojan-activity;sid:84755742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.226.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892641/; classtype:trojan-activity;sid:84755741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.237.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892640/; classtype:trojan-activity;sid:84755740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.99.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892639/; classtype:trojan-activity;sid:84755739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.138.149.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892638/; classtype:trojan-activity;sid:84755738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.140.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892637/; classtype:trojan-activity;sid:84755737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.41.226.164"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892636/; classtype:trojan-activity;sid:84755736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.85.98.202"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892635/; classtype:trojan-activity;sid:84755735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.222.99"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892634/; classtype:trojan-activity;sid:84755734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892633/; classtype:trojan-activity;sid:84755733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.84.47"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892628/; classtype:trojan-activity;sid:84755728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/ppc"; depth:9; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892629/; classtype:trojan-activity;sid:84755729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892630/; classtype:trojan-activity;sid:84755730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sh4"; depth:9; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892631/; classtype:trojan-activity;sid:84755731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"45.207.196.86"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892632/; classtype:trojan-activity;sid:84755732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892627/; classtype:trojan-activity;sid:84755727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.249.199.3"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892626/; classtype:trojan-activity;sid:84755726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.85.98.202"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892625/; classtype:trojan-activity;sid:84755725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.15.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892624/; classtype:trojan-activity;sid:84755724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.183.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892623/; classtype:trojan-activity;sid:84755723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"47.22.166.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892622/; classtype:trojan-activity;sid:84755722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.126.188"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892621/; classtype:trojan-activity;sid:84755721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.75.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892620/; classtype:trojan-activity;sid:84755720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.15.250"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892619/; classtype:trojan-activity;sid:84755719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.75.31"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892618/; classtype:trojan-activity;sid:84755718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892617/; classtype:trojan-activity;sid:84755717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.102.198"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892616/; classtype:trojan-activity;sid:84755716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"220.202.88.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892615/; classtype:trojan-activity;sid:84755715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.213.108.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892614/; classtype:trojan-activity;sid:84755714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.62.150.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892613/; classtype:trojan-activity;sid:84755713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.236.121.212"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892612/; classtype:trojan-activity;sid:84755712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.213.108.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892611/; classtype:trojan-activity;sid:84755711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.84.47"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892610/; classtype:trojan-activity;sid:84755710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.53.53"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892609/; classtype:trojan-activity;sid:84755709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.62.150.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892608/; classtype:trojan-activity;sid:84755708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.206.236.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892607/; classtype:trojan-activity;sid:84755707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.236.121.212"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892606/; classtype:trojan-activity;sid:84755706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.53.53"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892605/; classtype:trojan-activity;sid:84755705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.96.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892604/; classtype:trojan-activity;sid:84755704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"162.255.251.91"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892603/; classtype:trojan-activity;sid:84755703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.4.69"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892602/; classtype:trojan-activity;sid:84755702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.47.68.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892601/; classtype:trojan-activity;sid:84755701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pinimg.png"; depth:11; endswith; nocase; http.host; content:"103.20.240.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892600/; classtype:trojan-activity;sid:84755700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ndbnk"; depth:6; endswith; nocase; http.host; content:"sweet-snowflake-8a7e.uploadesclintesss.workers.dev"; depth:50; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892599/; classtype:trojan-activity;sid:84755699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_094830.png"; depth:15; endswith; nocase; http.host; content:"cryptefilea.infy.click"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892598/; classtype:trojan-activity;sid:84755698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.96.59"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892597/; classtype:trojan-activity;sid:84755697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.206.236.100"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892596/; classtype:trojan-activity;sid:84755696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.47.68.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892595/; classtype:trojan-activity;sid:84755695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"heroestales.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892594/; classtype:trojan-activity;sid:84755694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.167.3.49"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892593/; classtype:trojan-activity;sid:84755693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.255.108"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892592/; classtype:trojan-activity;sid:84755692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.7.226"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892591/; classtype:trojan-activity;sid:84755691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm5"; depth:10; endswith; nocase; http.host; content:"45.150.110.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892587/; classtype:trojan-activity;sid:84755687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm6"; depth:10; endswith; nocase; http.host; content:"45.150.110.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892588/; classtype:trojan-activity;sid:84755688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mipsel"; depth:12; endswith; nocase; http.host; content:"45.150.110.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892589/; classtype:trojan-activity;sid:84755689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/x86"; depth:9; endswith; nocase; http.host; content:"45.150.110.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892590/; classtype:trojan-activity;sid:84755690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/mips"; depth:10; endswith; nocase; http.host; content:"45.150.110.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892586/; classtype:trojan-activity;sid:84755686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/arm7"; depth:10; endswith; nocase; http.host; content:"45.150.110.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892585/; classtype:trojan-activity;sid:84755685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.58.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892584/; classtype:trojan-activity;sid:84755684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.164.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892583/; classtype:trojan-activity;sid:84755683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.7.226"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892582/; classtype:trojan-activity;sid:84755682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/332a0c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892579/; classtype:trojan-activity;sid:84755679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b07ab1"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892580/; classtype:trojan-activity;sid:84755680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f1ed24"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892581/; classtype:trojan-activity;sid:84755681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2297af"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892570/; classtype:trojan-activity;sid:84755670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2051fb"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892571/; classtype:trojan-activity;sid:84755671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/81d631"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892572/; classtype:trojan-activity;sid:84755672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3cbe86"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892573/; classtype:trojan-activity;sid:84755673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/599506"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892574/; classtype:trojan-activity;sid:84755674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2573fd"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892575/; classtype:trojan-activity;sid:84755675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/156c25"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892576/; classtype:trojan-activity;sid:84755676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/370ad5"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892577/; classtype:trojan-activity;sid:84755677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2864e0"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892578/; classtype:trojan-activity;sid:84755678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.164.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892569/; classtype:trojan-activity;sid:84755669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.133.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892568/; classtype:trojan-activity;sid:84755668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.48.133.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892567/; classtype:trojan-activity;sid:84755667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/crazy.exe"; depth:25; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892562/; classtype:trojan-activity;sid:84755662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/beb.exe"; depth:22; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892563/; classtype:trojan-activity;sid:84755663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/load/os1/crazy.exe"; depth:19; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892564/; classtype:trojan-activity;sid:84755664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/acr.exe"; depth:22; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892565/; classtype:trojan-activity;sid:84755665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/r2.exe"; depth:21; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892566/; classtype:trojan-activity;sid:84755666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/load/os1/r2.exe"; depth:16; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892560/; classtype:trojan-activity;sid:84755660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/load/os1/beb.exe"; depth:17; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892561/; classtype:trojan-activity;sid:84755661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/acr.exe"; depth:23; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892556/; classtype:trojan-activity;sid:84755656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/mixnew.exe"; depth:25; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892557/; classtype:trojan-activity;sid:84755657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/r5.exe"; depth:21; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892558/; classtype:trojan-activity;sid:84755658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/obsh/crazy.exe"; depth:24; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892559/; classtype:trojan-activity;sid:84755659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yzkgwy.html"; depth:12; endswith; nocase; http.host; content:"uafsoftware.in"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892555/; classtype:trojan-activity;sid:84755655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/r2.exe"; depth:22; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892551/; classtype:trojan-activity;sid:84755651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/r5.exe"; depth:22; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892552/; classtype:trojan-activity;sid:84755652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/beb.exe"; depth:23; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892553/; classtype:trojan-activity;sid:84755653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncrypt/21-32/mixnew.exe"; depth:26; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892554/; classtype:trojan-activity;sid:84755654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.214.219"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892550/; classtype:trojan-activity;sid:84755650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.3.199"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892549/; classtype:trojan-activity;sid:84755649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.212.121.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892548/; classtype:trojan-activity;sid:84755648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"5.166.39.19"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892547/; classtype:trojan-activity;sid:84755647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.0.151"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892546/; classtype:trojan-activity;sid:84755646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"101.59.79.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892545/; classtype:trojan-activity;sid:84755645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.48.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892544/; classtype:trojan-activity;sid:84755644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.212.121.42"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892543/; classtype:trojan-activity;sid:84755643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv4l"; depth:12; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892541/; classtype:trojan-activity;sid:84755641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.sh"; depth:11; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892542/; classtype:trojan-activity;sid:84755642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.i486"; depth:10; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892539/; classtype:trojan-activity;sid:84755639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.36.226"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892540/; classtype:trojan-activity;sid:84755640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mipsel"; depth:12; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892536/; classtype:trojan-activity;sid:84755636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.m68k"; depth:10; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892537/; classtype:trojan-activity;sid:84755637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv7l"; depth:12; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892538/; classtype:trojan-activity;sid:84755638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.x86_64"; depth:12; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892534/; classtype:trojan-activity;sid:84755634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mips"; depth:10; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892535/; classtype:trojan-activity;sid:84755635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/bootsexec64.zip"; depth:24; endswith; nocase; http.host; content:"roblox-xeno.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892533/; classtype:trojan-activity;sid:84755633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm7"; depth:11; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892525/; classtype:trojan-activity;sid:84755625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892526/; classtype:trojan-activity;sid:84755626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892527/; classtype:trojan-activity;sid:84755627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892528/; classtype:trojan-activity;sid:84755628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892529/; classtype:trojan-activity;sid:84755629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm7"; depth:11; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892530/; classtype:trojan-activity;sid:84755630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892531/; classtype:trojan-activity;sid:84755631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892532/; classtype:trojan-activity;sid:84755632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892523/; classtype:trojan-activity;sid:84755623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892524/; classtype:trojan-activity;sid:84755624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892506/; classtype:trojan-activity;sid:84755606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892507/; classtype:trojan-activity;sid:84755607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892508/; classtype:trojan-activity;sid:84755608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892509/; classtype:trojan-activity;sid:84755609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892510/; classtype:trojan-activity;sid:84755610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892511/; classtype:trojan-activity;sid:84755611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892512/; classtype:trojan-activity;sid:84755612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892513/; classtype:trojan-activity;sid:84755613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm7"; depth:11; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892514/; classtype:trojan-activity;sid:84755614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892515/; classtype:trojan-activity;sid:84755615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892516/; classtype:trojan-activity;sid:84755616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892517/; classtype:trojan-activity;sid:84755617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892518/; classtype:trojan-activity;sid:84755618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892519/; classtype:trojan-activity;sid:84755619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892520/; classtype:trojan-activity;sid:84755620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/o.xml"; depth:9; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892521/; classtype:trojan-activity;sid:84755621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892522/; classtype:trojan-activity;sid:84755622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892505/; classtype:trojan-activity;sid:84755605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892498/; classtype:trojan-activity;sid:84755598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892499/; classtype:trojan-activity;sid:84755599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/o.xml"; depth:9; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892500/; classtype:trojan-activity;sid:84755600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892501/; classtype:trojan-activity;sid:84755601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/o.xml"; depth:9; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892502/; classtype:trojan-activity;sid:84755602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892503/; classtype:trojan-activity;sid:84755603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892504/; classtype:trojan-activity;sid:84755604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892496/; classtype:trojan-activity;sid:84755596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892497/; classtype:trojan-activity;sid:84755597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh"; depth:9; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892494/; classtype:trojan-activity;sid:84755594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892495/; classtype:trojan-activity;sid:84755595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892490/; classtype:trojan-activity;sid:84755590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892491/; classtype:trojan-activity;sid:84755591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"wqok85qtq.net"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892492/; classtype:trojan-activity;sid:84755592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892493/; classtype:trojan-activity;sid:84755593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh"; depth:9; endswith; nocase; http.host; content:"s3o65awrf56.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892488/; classtype:trojan-activity;sid:84755588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh"; depth:9; endswith; nocase; http.host; content:"osfjkqoiw382r552q.hopto.org"; depth:27; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892489/; classtype:trojan-activity;sid:84755589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv6l"; depth:12; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892484/; classtype:trojan-activity;sid:84755584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.powerpc"; depth:13; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892485/; classtype:trojan-activity;sid:84755585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.sh4"; depth:9; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892486/; classtype:trojan-activity;sid:84755586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.sparc"; depth:11; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892487/; classtype:trojan-activity;sid:84755587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv5l"; depth:12; endswith; nocase; http.host; content:"dsgagfsahkfsahfjs.shop"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892483/; classtype:trojan-activity;sid:84755583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.127.77.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892482/; classtype:trojan-activity;sid:84755582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.56.149.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892481/; classtype:trojan-activity;sid:84755581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.45.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892480/; classtype:trojan-activity;sid:84755580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.247.88.81"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892479/; classtype:trojan-activity;sid:84755579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.56.149.89"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892478/; classtype:trojan-activity;sid:84755578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.45.91"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892477/; classtype:trojan-activity;sid:84755577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.10.131.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892476/; classtype:trojan-activity;sid:84755576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.44.136.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892475/; classtype:trojan-activity;sid:84755575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.44.136.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892474/; classtype:trojan-activity;sid:84755574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.116.38.141"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892473/; classtype:trojan-activity;sid:84755573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.138.149.25"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892472/; classtype:trojan-activity;sid:84755572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qqfynkce/stego_g4dez65hk6.png"; depth:30; endswith; nocase; http.host; content:"media-aviation.run.place"; depth:24; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892471/; classtype:trojan-activity;sid:84755571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.92.245"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892470/; classtype:trojan-activity;sid:84755570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.34.100"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892469/; classtype:trojan-activity;sid:84755569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.134.164.39"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892468/; classtype:trojan-activity;sid:84755568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.80.57.126"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892466/; classtype:trojan-activity;sid:84755566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.224.251.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892467/; classtype:trojan-activity;sid:84755567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.44.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892465/; classtype:trojan-activity;sid:84755565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.14.156"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892464/; classtype:trojan-activity;sid:84755564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.94.186"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892463/; classtype:trojan-activity;sid:84755563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.53.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892462/; classtype:trojan-activity;sid:84755562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"2.183.135.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892461/; classtype:trojan-activity;sid:84755561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.68.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892460/; classtype:trojan-activity;sid:84755560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.149.73.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892459/; classtype:trojan-activity;sid:84755559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.120.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892458/; classtype:trojan-activity;sid:84755558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"24.54.95.49"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892457/; classtype:trojan-activity;sid:84755557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.176.29"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892456/; classtype:trojan-activity;sid:84755556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.108.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892455/; classtype:trojan-activity;sid:84755555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.44.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892454/; classtype:trojan-activity;sid:84755554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.149.73.167"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892453/; classtype:trojan-activity;sid:84755553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.176.29"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892452/; classtype:trojan-activity;sid:84755552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.108.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892451/; classtype:trojan-activity;sid:84755551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"124.29.194.115"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892449/; classtype:trojan-activity;sid:84755549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"116.76.255.32"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892450/; classtype:trojan-activity;sid:84755550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"83.177.220.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892448/; classtype:trojan-activity;sid:84755548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/beb.exe"; depth:19; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892447/; classtype:trojan-activity;sid:84755547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/arftu.exe"; depth:22; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892446/; classtype:trojan-activity;sid:84755546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/r2.exe"; depth:18; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892444/; classtype:trojan-activity;sid:84755544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jquery.min.js"; depth:14; endswith; nocase; http.host; content:"geo.estimator-undermostshelving.in.net"; depth:38; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892445/; classtype:trojan-activity;sid:84755545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/r5.exe"; depth:18; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892441/; classtype:trojan-activity;sid:84755541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/acr.exe"; depth:19; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892442/; classtype:trojan-activity;sid:84755542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/obsh/crazy.exe"; depth:21; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892443/; classtype:trojan-activity;sid:84755543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wubejack-cmd/yopyop/releases/download/yop/launcher.dmg"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892440/; classtype:trojan-activity;sid:84755540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.119.63.53"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892439/; classtype:trojan-activity;sid:84755539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/kliulij.exe"; depth:24; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892429/; classtype:trojan-activity;sid:84755529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/arbeb.exe"; depth:22; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892430/; classtype:trojan-activity;sid:84755530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/kjhgfds.exe"; depth:24; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892431/; classtype:trojan-activity;sid:84755531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/hjbk.exe"; depth:21; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892432/; classtype:trojan-activity;sid:84755532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/ojujn.exe"; depth:22; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892433/; classtype:trojan-activity;sid:84755533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/hnmh.exe"; depth:21; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892434/; classtype:trojan-activity;sid:84755534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/jhgkuyyg.exe"; depth:25; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892435/; classtype:trojan-activity;sid:84755535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/kllnmf.exe"; depth:23; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892436/; classtype:trojan-activity;sid:84755536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/klhdfs.exe"; depth:23; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892437/; classtype:trojan-activity;sid:84755537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/xqaae.exe"; depth:22; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892438/; classtype:trojan-activity;sid:84755538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crypt/21-32/bjbh.exe"; depth:21; endswith; nocase; http.host; content:"aethersyncmatrix5.lol"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892428/; classtype:trojan-activity;sid:84755528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"95.133.245.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892427/; classtype:trojan-activity;sid:84755527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"122.116.172.87"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892426/; classtype:trojan-activity;sid:84755526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"24.54.95.49"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892425/; classtype:trojan-activity;sid:84755525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"95.133.245.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892424/; classtype:trojan-activity;sid:84755524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"95.133.245.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892423/; classtype:trojan-activity;sid:84755523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"95.133.245.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892422/; classtype:trojan-activity;sid:84755522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i468"; depth:11; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892420/; classtype:trojan-activity;sid:84755520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"95.133.245.15"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892421/; classtype:trojan-activity;sid:84755521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.178.50.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892419/; classtype:trojan-activity;sid:84755519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"reservphotoinstay.one"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892418/; classtype:trojan-activity;sid:84755518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"182.117.107.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892417/; classtype:trojan-activity;sid:84755517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mipsel"; depth:12; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892416/; classtype:trojan-activity;sid:84755516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a58066"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892410/; classtype:trojan-activity;sid:84755510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35ca8a"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892411/; classtype:trojan-activity;sid:84755511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7f36d6"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892412/; classtype:trojan-activity;sid:84755512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/46d337"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892413/; classtype:trojan-activity;sid:84755513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a33a57"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892414/; classtype:trojan-activity;sid:84755514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f13ecd"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892415/; classtype:trojan-activity;sid:84755515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5f6d8c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892404/; classtype:trojan-activity;sid:84755504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2e59c4"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892405/; classtype:trojan-activity;sid:84755505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6e47c0"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892406/; classtype:trojan-activity;sid:84755506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0a1285"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892407/; classtype:trojan-activity;sid:84755507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3e6376"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892408/; classtype:trojan-activity;sid:84755508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/72f275"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892409/; classtype:trojan-activity;sid:84755509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv7l"; depth:12; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892403/; classtype:trojan-activity;sid:84755503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.x86_64"; depth:12; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892399/; classtype:trojan-activity;sid:84755499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv6l"; depth:12; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892400/; classtype:trojan-activity;sid:84755500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv4l"; depth:12; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892401/; classtype:trojan-activity;sid:84755501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.i486"; depth:10; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892402/; classtype:trojan-activity;sid:84755502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.armv5l"; depth:12; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892397/; classtype:trojan-activity;sid:84755497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.sh4"; depth:9; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892398/; classtype:trojan-activity;sid:84755498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.sparc"; depth:11; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892393/; classtype:trojan-activity;sid:84755493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.powerpc"; depth:13; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892394/; classtype:trojan-activity;sid:84755494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.mips"; depth:10; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892395/; classtype:trojan-activity;sid:84755495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.m68k"; depth:10; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892396/; classtype:trojan-activity;sid:84755496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zero.arc"; depth:9; endswith; nocase; http.host; content:"217.60.195.143"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892392/; classtype:trojan-activity;sid:84755492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.178.50.118"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892390/; classtype:trojan-activity;sid:84755490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.132.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892391/; classtype:trojan-activity;sid:84755491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.150.26.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892389/; classtype:trojan-activity;sid:84755489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lib/xxx"; depth:8; endswith; nocase; http.host; content:"47.239.127.71"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892388/; classtype:trojan-activity;sid:84755488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tenis-team-km.zip"; depth:18; endswith; nocase; http.host; content:"tenis-team-km.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892387/; classtype:trojan-activity;sid:84755487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/login"; depth:6; endswith; nocase; http.host; content:"178.20.41.208"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892386/; classtype:trojan-activity;sid:84755486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.196.214.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892385/; classtype:trojan-activity;sid:84755485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.142.195.230"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892384/; classtype:trojan-activity;sid:84755484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"189.127.169.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892383/; classtype:trojan-activity;sid:84755483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.134.47.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892382/; classtype:trojan-activity;sid:84755482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.150.26.8"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892381/; classtype:trojan-activity;sid:84755481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.61.112.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892380/; classtype:trojan-activity;sid:84755480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.196.214.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892379/; classtype:trojan-activity;sid:84755479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.35.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892378/; classtype:trojan-activity;sid:84755478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.155.83.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892377/; classtype:trojan-activity;sid:84755477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.134.47.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892376/; classtype:trojan-activity;sid:84755476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.58.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892374/; classtype:trojan-activity;sid:84755474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.58.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892375/; classtype:trojan-activity;sid:84755475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.133.180"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892372/; classtype:trojan-activity;sid:84755472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.137.5.224"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892373/; classtype:trojan-activity;sid:84755473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.61.112.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892371/; classtype:trojan-activity;sid:84755471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892370/; classtype:trojan-activity;sid:84755470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.237.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892369/; classtype:trojan-activity;sid:84755469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.48.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892368/; classtype:trojan-activity;sid:84755468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.179.252.0"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892367/; classtype:trojan-activity;sid:84755467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"183.23.130.74"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892366/; classtype:trojan-activity;sid:84755466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.66.64"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892365/; classtype:trojan-activity;sid:84755465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892364/; classtype:trojan-activity;sid:84755464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.135.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892363/; classtype:trojan-activity;sid:84755463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.116.172.202"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892362/; classtype:trojan-activity;sid:84755462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.171.67.100"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892361/; classtype:trojan-activity;sid:84755461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.1.200"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892358/; classtype:trojan-activity;sid:84755458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.36.15.218"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892359/; classtype:trojan-activity;sid:84755459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.178.135.78"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892360/; classtype:trojan-activity;sid:84755460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.155.83.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892357/; classtype:trojan-activity;sid:84755457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.45.48.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892356/; classtype:trojan-activity;sid:84755456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.116.172.202"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892355/; classtype:trojan-activity;sid:84755455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.206.131.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892354/; classtype:trojan-activity;sid:84755454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.9.221"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892353/; classtype:trojan-activity;sid:84755453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.200.220.208"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892352/; classtype:trojan-activity;sid:84755452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.147.154.140"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892351/; classtype:trojan-activity;sid:84755451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.45.48.113"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892350/; classtype:trojan-activity;sid:84755450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.9.221"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892349/; classtype:trojan-activity;sid:84755449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.172.243"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892348/; classtype:trojan-activity;sid:84755448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.48.59.106"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892347/; classtype:trojan-activity;sid:84755447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.105.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892346/; classtype:trojan-activity;sid:84755446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.142.18"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892345/; classtype:trojan-activity;sid:84755445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"175.43.178.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892343/; classtype:trojan-activity;sid:84755443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"175.43.178.52"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892344/; classtype:trojan-activity;sid:84755444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.93.243.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892342/; classtype:trojan-activity;sid:84755442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.19.78"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892341/; classtype:trojan-activity;sid:84755441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"36.48.59.106"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892340/; classtype:trojan-activity;sid:84755440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"189.127.169.20"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892339/; classtype:trojan-activity;sid:84755439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.157.142.18"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892338/; classtype:trojan-activity;sid:84755438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.105.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892337/; classtype:trojan-activity;sid:84755437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.206.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892336/; classtype:trojan-activity;sid:84755436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.219.74.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892335/; classtype:trojan-activity;sid:84755435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.48.146.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892333/; classtype:trojan-activity;sid:84755433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.93.243.19"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892334/; classtype:trojan-activity;sid:84755434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.206.131.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892332/; classtype:trojan-activity;sid:84755432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.46.154"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892331/; classtype:trojan-activity;sid:84755431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.15.188"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892330/; classtype:trojan-activity;sid:84755430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.248.37.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892329/; classtype:trojan-activity;sid:84755429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.77.0"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892328/; classtype:trojan-activity;sid:84755428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.221.74.28"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892327/; classtype:trojan-activity;sid:84755427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.108.39"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892326/; classtype:trojan-activity;sid:84755426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"121.202.142.137"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892325/; classtype:trojan-activity;sid:84755425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.153.96"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892324/; classtype:trojan-activity;sid:84755424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.248.37.90"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892323/; classtype:trojan-activity;sid:84755423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.147.48"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892321/; classtype:trojan-activity;sid:84755421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.82.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892322/; classtype:trojan-activity;sid:84755422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.194.171"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892320/; classtype:trojan-activity;sid:84755420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.112.29.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892319/; classtype:trojan-activity;sid:84755419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.53.223.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892318/; classtype:trojan-activity;sid:84755418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"121.202.142.137"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892317/; classtype:trojan-activity;sid:84755417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.52.23.187"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892316/; classtype:trojan-activity;sid:84755416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.145.31"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892315/; classtype:trojan-activity;sid:84755415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.186.184"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892314/; classtype:trojan-activity;sid:84755414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.100.92"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892313/; classtype:trojan-activity;sid:84755413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.233.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892312/; classtype:trojan-activity;sid:84755412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.180.81"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892311/; classtype:trojan-activity;sid:84755411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.139.226.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892310/; classtype:trojan-activity;sid:84755410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.191.13"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892309/; classtype:trojan-activity;sid:84755409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.133.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892308/; classtype:trojan-activity;sid:84755408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.180.81"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892307/; classtype:trojan-activity;sid:84755407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.234.181.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892306/; classtype:trojan-activity;sid:84755406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.5.133.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892305/; classtype:trojan-activity;sid:84755405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"114.234.181.161"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892304/; classtype:trojan-activity;sid:84755404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.234.200.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892303/; classtype:trojan-activity;sid:84755403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.34.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892302/; classtype:trojan-activity;sid:84755402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"79.106.74.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892301/; classtype:trojan-activity;sid:84755401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892300/; classtype:trojan-activity;sid:84755400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892294/; classtype:trojan-activity;sid:84755394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892295/; classtype:trojan-activity;sid:84755395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arc"; depth:10; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892296/; classtype:trojan-activity;sid:84755396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892297/; classtype:trojan-activity;sid:84755397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892298/; classtype:trojan-activity;sid:84755398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892299/; classtype:trojan-activity;sid:84755399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892288/; classtype:trojan-activity;sid:84755388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892289/; classtype:trojan-activity;sid:84755389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm"; depth:10; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892290/; classtype:trojan-activity;sid:84755390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i686"; depth:11; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892291/; classtype:trojan-activity;sid:84755391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892292/; classtype:trojan-activity;sid:84755392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892293/; classtype:trojan-activity;sid:84755393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892286/; classtype:trojan-activity;sid:84755386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"77.239.124.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892287/; classtype:trojan-activity;sid:84755387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.116.34.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892285/; classtype:trojan-activity;sid:84755385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mips"; depth:10; endswith; nocase; http.host; content:"104.252.175.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892284/; classtype:trojan-activity;sid:84755384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data_mipsel"; depth:12; endswith; nocase; http.host; content:"104.252.175.109"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892283/; classtype:trojan-activity;sid:84755383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892282/; classtype:trojan-activity;sid:84755382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892280/; classtype:trojan-activity;sid:84755380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892281/; classtype:trojan-activity;sid:84755381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.249.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892279/; classtype:trojan-activity;sid:84755379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.11.13.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892278/; classtype:trojan-activity;sid:84755378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.3.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892277/; classtype:trojan-activity;sid:84755377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.185.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892276/; classtype:trojan-activity;sid:84755376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.11.13.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892275/; classtype:trojan-activity;sid:84755375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.38.214.61"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892274/; classtype:trojan-activity;sid:84755374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.152.9.9"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892273/; classtype:trojan-activity;sid:84755373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.222.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892272/; classtype:trojan-activity;sid:84755372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.3.76"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892271/; classtype:trojan-activity;sid:84755371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.185.193"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892270/; classtype:trojan-activity;sid:84755370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.34.3"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892269/; classtype:trojan-activity;sid:84755369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.224.42.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892268/; classtype:trojan-activity;sid:84755368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.233.106.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892267/; classtype:trojan-activity;sid:84755367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.24.225"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892266/; classtype:trojan-activity;sid:84755366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.69.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892265/; classtype:trojan-activity;sid:84755365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.233.106.151"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892264/; classtype:trojan-activity;sid:84755364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"120.28.220.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892263/; classtype:trojan-activity;sid:84755363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.46.32"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892262/; classtype:trojan-activity;sid:84755362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.44.146.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892261/; classtype:trojan-activity;sid:84755361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.206.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892260/; classtype:trojan-activity;sid:84755360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"120.28.220.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892259/; classtype:trojan-activity;sid:84755359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.12.168.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892258/; classtype:trojan-activity;sid:84755358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.224.85.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892257/; classtype:trojan-activity;sid:84755357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.55.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892256/; classtype:trojan-activity;sid:84755356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.191.104.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892255/; classtype:trojan-activity;sid:84755355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1da144"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892254/; classtype:trojan-activity;sid:84755354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/305fff"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892243/; classtype:trojan-activity;sid:84755343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ec7f34"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892244/; classtype:trojan-activity;sid:84755344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2f2c84"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892245/; classtype:trojan-activity;sid:84755345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/090c4c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892246/; classtype:trojan-activity;sid:84755346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/905c95"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892247/; classtype:trojan-activity;sid:84755347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/60bf57"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892248/; classtype:trojan-activity;sid:84755348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d930ad"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892249/; classtype:trojan-activity;sid:84755349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c6f42c"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892250/; classtype:trojan-activity;sid:84755350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0faa38"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892251/; classtype:trojan-activity;sid:84755351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c0db3a"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892252/; classtype:trojan-activity;sid:84755352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/acba5d"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892253/; classtype:trojan-activity;sid:84755353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.224.85.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892242/; classtype:trojan-activity;sid:84755342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"59.96.137.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892241/; classtype:trojan-activity;sid:84755341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/1530962677420130375/1530987549349118182/win64.exe|3f|ex=6a6792c4|7c|26|7c|is=6a664144|7c|26|7c|hm=60400ef2b047a5d4bb77d4fc978d1a69cdfa310ea79ff63d6c5e94452f5e98e2|7c|26|7c|"; depth:185; endswith; nocase; http.host; content:"cdn.discordapp.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892240/; classtype:trojan-activity;sid:84755340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_42df558b1d16bfd6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892239/; classtype:trojan-activity;sid:84755339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.55.197"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892238/; classtype:trojan-activity;sid:84755338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.15.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892237/; classtype:trojan-activity;sid:84755337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.191.104.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892236/; classtype:trojan-activity;sid:84755336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.237.17.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892235/; classtype:trojan-activity;sid:84755335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.53.192.166"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892234/; classtype:trojan-activity;sid:84755334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.119.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892233/; classtype:trojan-activity;sid:84755333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm7"; depth:11; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892232/; classtype:trojan-activity;sid:84755332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.55.59.60"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892231/; classtype:trojan-activity;sid:84755331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm5"; depth:11; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892224/; classtype:trojan-activity;sid:84755324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arc"; depth:10; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892225/; classtype:trojan-activity;sid:84755325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm6"; depth:11; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892226/; classtype:trojan-activity;sid:84755326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.spc"; depth:10; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892227/; classtype:trojan-activity;sid:84755327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i686"; depth:11; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892228/; classtype:trojan-activity;sid:84755328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.m68k"; depth:11; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892229/; classtype:trojan-activity;sid:84755329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.arm"; depth:10; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892230/; classtype:trojan-activity;sid:84755330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.sh4"; depth:10; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892215/; classtype:trojan-activity;sid:84755315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/debug"; depth:9; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892216/; classtype:trojan-activity;sid:84755316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/o.xml"; depth:9; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892217/; classtype:trojan-activity;sid:84755317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mips"; depth:11; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892218/; classtype:trojan-activity;sid:84755318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.mpsl"; depth:11; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892219/; classtype:trojan-activity;sid:84755319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz.sh"; depth:6; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892220/; classtype:trojan-activity;sid:84755320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86"; depth:10; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892221/; classtype:trojan-activity;sid:84755321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.ppc"; depth:10; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892222/; classtype:trojan-activity;sid:84755322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.x86_64"; depth:13; endswith; nocase; http.host; content:"31.56.209.153"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892223/; classtype:trojan-activity;sid:84755323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.113.45.237"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892214/; classtype:trojan-activity;sid:84755314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3e42c5177eedf927.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892213/; classtype:trojan-activity;sid:84755313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.96.137.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892212/; classtype:trojan-activity;sid:84755312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.93.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892211/; classtype:trojan-activity;sid:84755311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.86.148"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892210/; classtype:trojan-activity;sid:84755310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.96.137.193"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892209/; classtype:trojan-activity;sid:84755309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arc"; depth:10; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892207/; classtype:trojan-activity;sid:84755307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/sh4"; depth:10; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892208/; classtype:trojan-activity;sid:84755308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86_64"; depth:13; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892206/; classtype:trojan-activity;sid:84755306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mpsl"; depth:11; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892205/; classtype:trojan-activity;sid:84755305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm5"; depth:11; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892203/; classtype:trojan-activity;sid:84755303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm"; depth:10; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892204/; classtype:trojan-activity;sid:84755304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/m68k"; depth:11; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892196/; classtype:trojan-activity;sid:84755296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm7"; depth:11; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892197/; classtype:trojan-activity;sid:84755297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/x86"; depth:10; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892198/; classtype:trojan-activity;sid:84755298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/arm6"; depth:11; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892199/; classtype:trojan-activity;sid:84755299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/spc"; depth:10; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892200/; classtype:trojan-activity;sid:84755300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/mips"; depth:11; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892201/; classtype:trojan-activity;sid:84755301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljezs/ppc"; depth:10; endswith; nocase; http.host; content:"217.60.195.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892202/; classtype:trojan-activity;sid:84755302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/public_files/avlemqb.txt"; depth:25; endswith; nocase; http.host; content:"192.162.199.78"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892195/; classtype:trojan-activity;sid:84755295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl/f293a6dc24a4cfe46895e7bc4f91ffcf276ac71a74b13fed54458ad51af9dbb3"; depth:70; endswith; nocase; http.host; content:"tampareroofing.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892194/; classtype:trojan-activity;sid:84755294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_00d6c04b5fd7e13a.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892193/; classtype:trojan-activity;sid:84755293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.159.127"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892192/; classtype:trojan-activity;sid:84755292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"101.109.207.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892191/; classtype:trojan-activity;sid:84755291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.ppc"; depth:21; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892190/; classtype:trojan-activity;sid:84755290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.39.255.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892188/; classtype:trojan-activity;sid:84755288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.121.193.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892189/; classtype:trojan-activity;sid:84755289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"broadwalkindia.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892187/; classtype:trojan-activity;sid:84755287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.x86_64"; depth:24; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892186/; classtype:trojan-activity;sid:84755286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.m68k"; depth:22; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892184/; classtype:trojan-activity;sid:84755284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.sh4"; depth:21; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892185/; classtype:trojan-activity;sid:84755285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arc"; depth:21; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892183/; classtype:trojan-activity;sid:84755283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arm6"; depth:22; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892178/; classtype:trojan-activity;sid:84755278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.x86"; depth:21; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892179/; classtype:trojan-activity;sid:84755279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/wget.sh"; depth:13; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892180/; classtype:trojan-activity;sid:84755280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.mpsl"; depth:22; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892181/; classtype:trojan-activity;sid:84755281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arm5"; depth:22; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892182/; classtype:trojan-activity;sid:84755282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arm7"; depth:22; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892172/; classtype:trojan-activity;sid:84755272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arm6"; depth:22; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892173/; classtype:trojan-activity;sid:84755273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm6"; depth:17; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892174/; classtype:trojan-activity;sid:84755274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/callaputa.sh"; depth:18; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892175/; classtype:trojan-activity;sid:84755275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.m68k"; depth:17; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892176/; classtype:trojan-activity;sid:84755276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/busywget.sh"; depth:17; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892177/; classtype:trojan-activity;sid:84755277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/busycurl.sh"; depth:17; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892169/; classtype:trojan-activity;sid:84755269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/busycurl.sh"; depth:17; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892170/; classtype:trojan-activity;sid:84755270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/curl.sh"; depth:13; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892171/; classtype:trojan-activity;sid:84755271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.m68k"; depth:22; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892167/; classtype:trojan-activity;sid:84755267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/wget.sh"; depth:13; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892168/; classtype:trojan-activity;sid:84755268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.40.83.207"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892165/; classtype:trojan-activity;sid:84755265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.121.193.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892166/; classtype:trojan-activity;sid:84755266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arm7"; depth:22; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892152/; classtype:trojan-activity;sid:84755252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.i686"; depth:22; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892153/; classtype:trojan-activity;sid:84755253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.mips"; depth:22; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892154/; classtype:trojan-activity;sid:84755254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arm"; depth:21; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892155/; classtype:trojan-activity;sid:84755255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.x86"; depth:21; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892156/; classtype:trojan-activity;sid:84755256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.sh4"; depth:21; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892157/; classtype:trojan-activity;sid:84755257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.spc"; depth:21; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892158/; classtype:trojan-activity;sid:84755258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.spc"; depth:21; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892159/; classtype:trojan-activity;sid:84755259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arc"; depth:21; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892160/; classtype:trojan-activity;sid:84755260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arm5"; depth:22; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892161/; classtype:trojan-activity;sid:84755261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.i686"; depth:22; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892162/; classtype:trojan-activity;sid:84755262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.arm"; depth:21; endswith; nocase; http.host; content:"sandystudiogh.blog"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892163/; classtype:trojan-activity;sid:84755263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.x86_64"; depth:24; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892164/; classtype:trojan-activity;sid:84755264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.mpsl"; depth:22; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892149/; classtype:trojan-activity;sid:84755249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.ppc"; depth:21; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892150/; classtype:trojan-activity;sid:84755250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/zombie.mips"; depth:22; endswith; nocase; http.host; content:"mail.sandystudiogh.blog"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892151/; classtype:trojan-activity;sid:84755251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.x86"; depth:16; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892146/; classtype:trojan-activity;sid:84755246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/callaputa.sh"; depth:18; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892147/; classtype:trojan-activity;sid:84755247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/busywget.sh"; depth:17; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892148/; classtype:trojan-activity;sid:84755248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/curl.sh"; depth:13; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892145/; classtype:trojan-activity;sid:84755245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipmiv2.xml"; depth:11; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892144/; classtype:trojan-activity;sid:84755244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mipsrouter"; depth:23; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892140/; classtype:trojan-activity;sid:84755240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.ppc"; depth:16; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892141/; classtype:trojan-activity;sid:84755241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.m68k"; depth:17; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892142/; classtype:trojan-activity;sid:84755242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mipsrouter"; depth:23; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892143/; classtype:trojan-activity;sid:84755243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm5"; depth:17; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892139/; classtype:trojan-activity;sid:84755239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.ppc"; depth:16; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892131/; classtype:trojan-activity;sid:84755231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm5"; depth:17; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892132/; classtype:trojan-activity;sid:84755232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.x86_64"; depth:19; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892133/; classtype:trojan-activity;sid:84755233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm"; depth:16; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892134/; classtype:trojan-activity;sid:84755234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm7"; depth:17; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892135/; classtype:trojan-activity;sid:84755235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm6"; depth:17; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892136/; classtype:trojan-activity;sid:84755236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mips"; depth:17; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892137/; classtype:trojan-activity;sid:84755237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.sh4"; depth:16; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892138/; classtype:trojan-activity;sid:84755238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm7"; depth:17; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892127/; classtype:trojan-activity;sid:84755227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mpsl"; depth:17; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892128/; classtype:trojan-activity;sid:84755228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mpsl"; depth:17; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892129/; classtype:trojan-activity;sid:84755229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.sh4"; depth:16; endswith; nocase; http.host; content:"www.69cnc.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892130/; classtype:trojan-activity;sid:84755230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mips"; depth:17; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892123/; classtype:trojan-activity;sid:84755223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm"; depth:16; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892124/; classtype:trojan-activity;sid:84755224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.x86_64"; depth:19; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892125/; classtype:trojan-activity;sid:84755225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.x86"; depth:16; endswith; nocase; http.host; content:"69cnc.duckdns.org"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892126/; classtype:trojan-activity;sid:84755226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm"; depth:12; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892122/; classtype:trojan-activity;sid:84755222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.mipsel"; depth:15; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892121/; classtype:trojan-activity;sid:84755221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.ppc"; depth:12; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892119/; classtype:trojan-activity;sid:84755219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm6"; depth:13; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892120/; classtype:trojan-activity;sid:84755220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.mips"; depth:13; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892118/; classtype:trojan-activity;sid:84755218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.m68k"; depth:13; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892117/; classtype:trojan-activity;sid:84755217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.ppc64"; depth:14; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892114/; classtype:trojan-activity;sid:84755214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.x86_64"; depth:15; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892115/; classtype:trojan-activity;sid:84755215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.x86"; depth:12; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892116/; classtype:trojan-activity;sid:84755216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm7"; depth:13; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892112/; classtype:trojan-activity;sid:84755212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm8"; depth:13; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892113/; classtype:trojan-activity;sid:84755213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm5"; depth:13; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892110/; classtype:trojan-activity;sid:84755210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm8"; depth:13; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892111/; classtype:trojan-activity;sid:84755211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm"; depth:12; endswith; nocase; http.host; content:"femboykisser.sbs"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892109/; classtype:trojan-activity;sid:84755209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm6"; depth:13; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892104/; classtype:trojan-activity;sid:84755204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.ppc64"; depth:14; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892105/; classtype:trojan-activity;sid:84755205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.x86"; depth:12; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892106/; classtype:trojan-activity;sid:84755206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm5"; depth:13; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892107/; classtype:trojan-activity;sid:84755207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.mips"; depth:13; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892108/; classtype:trojan-activity;sid:84755208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.x86_64"; depth:15; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892099/; classtype:trojan-activity;sid:84755199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.arm7"; depth:13; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892100/; classtype:trojan-activity;sid:84755200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.mipsel"; depth:15; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892101/; classtype:trojan-activity;sid:84755201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.ppc"; depth:12; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892102/; classtype:trojan-activity;sid:84755202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flutter.m68k"; depth:13; endswith; nocase; http.host; content:"217.60.195.199"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892103/; classtype:trojan-activity;sid:84755203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"110.39.255.227"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892098/; classtype:trojan-activity;sid:84755198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.219.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892096/; classtype:trojan-activity;sid:84755196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892097/; classtype:trojan-activity;sid:84755197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.235.87.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892095/; classtype:trojan-activity;sid:84755195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.230.144"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892094/; classtype:trojan-activity;sid:84755194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.219.88"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892093/; classtype:trojan-activity;sid:84755193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doxanu"; depth:7; endswith; nocase; http.host; content:"45.94.47.226"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892092/; classtype:trojan-activity;sid:84755192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cursor"; depth:7; endswith; nocase; http.host; content:"45.94.47.226"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892091/; classtype:trojan-activity;sid:84755191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.62.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892090/; classtype:trojan-activity;sid:84755190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"118.232.137.101"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892089/; classtype:trojan-activity;sid:84755189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.157.39.0"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892088/; classtype:trojan-activity;sid:84755188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.53.122.167"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892087/; classtype:trojan-activity;sid:84755187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.235.87.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892086/; classtype:trojan-activity;sid:84755186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.18.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892085/; classtype:trojan-activity;sid:84755185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.24.77"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892084/; classtype:trojan-activity;sid:84755184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mia"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892081/; classtype:trojan-activity;sid:84755181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n.exe"; depth:6; endswith; nocase; http.host; content:"209.99.188.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892082/; classtype:trojan-activity;sid:84755182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.ps1"; depth:6; endswith; nocase; http.host; content:"209.99.188.158"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892083/; classtype:trojan-activity;sid:84755183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fe4ca4"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892068/; classtype:trojan-activity;sid:84755168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/27976f"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892069/; classtype:trojan-activity;sid:84755169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/91b24a"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892070/; classtype:trojan-activity;sid:84755170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/92cc1f"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892071/; classtype:trojan-activity;sid:84755171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ea2ba2"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892072/; classtype:trojan-activity;sid:84755172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/635745"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892073/; classtype:trojan-activity;sid:84755173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70f214"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892074/; classtype:trojan-activity;sid:84755174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d35236"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892075/; classtype:trojan-activity;sid:84755175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8365ed"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892076/; classtype:trojan-activity;sid:84755176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2a6676"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892077/; classtype:trojan-activity;sid:84755177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e6e76d"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892078/; classtype:trojan-activity;sid:84755178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e6381a"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892079/; classtype:trojan-activity;sid:84755179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/76fe4e"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892080/; classtype:trojan-activity;sid:84755180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d12003"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892057/; classtype:trojan-activity;sid:84755157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d1e4e6"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892058/; classtype:trojan-activity;sid:84755158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dcce92"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892059/; classtype:trojan-activity;sid:84755159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e77be8"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892060/; classtype:trojan-activity;sid:84755160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9989a1"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892061/; classtype:trojan-activity;sid:84755161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fb6e84"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892062/; classtype:trojan-activity;sid:84755162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e6873a"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892063/; classtype:trojan-activity;sid:84755163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cf8b70"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892064/; classtype:trojan-activity;sid:84755164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b07b84"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892065/; classtype:trojan-activity;sid:84755165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5f7fe7"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892066/; classtype:trojan-activity;sid:84755166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bf96dc"; depth:7; endswith; nocase; http.host; content:"5.182.210.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892067/; classtype:trojan-activity;sid:84755167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xczb"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892056/; classtype:trojan-activity;sid:84755156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ph7"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892053/; classtype:trojan-activity;sid:84755153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pu0"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892054/; classtype:trojan-activity;sid:84755154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sad"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892055/; classtype:trojan-activity;sid:84755155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qak"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892049/; classtype:trojan-activity;sid:84755149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g9zj"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892050/; classtype:trojan-activity;sid:84755150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ybr"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892051/; classtype:trojan-activity;sid:84755151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1un"; depth:4; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892052/; classtype:trojan-activity;sid:84755152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmxw"; depth:5; endswith; nocase; http.host; content:"129.121.110.105"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892048/; classtype:trojan-activity;sid:84755148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gigatex/aarch64"; depth:16; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892047/; classtype:trojan-activity;sid:84755147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.62.169"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892046/; classtype:trojan-activity;sid:84755146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.19.78"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892045/; classtype:trojan-activity;sid:84755145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_f037712e757a5b4c.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892044/; classtype:trojan-activity;sid:84755144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.4.235.143"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892043/; classtype:trojan-activity;sid:84755143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.9.244.135"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892042/; classtype:trojan-activity;sid:84755142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.18.189"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892041/; classtype:trojan-activity;sid:84755141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lc/1.exe"; depth:9; endswith; nocase; http.host; content:"158.94.209.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892040/; classtype:trojan-activity;sid:84755140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lc/3.exe"; depth:9; endswith; nocase; http.host; content:"158.94.209.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892039/; classtype:trojan-activity;sid:84755139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lc/2.exe"; depth:9; endswith; nocase; http.host; content:"158.94.209.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892038/; classtype:trojan-activity;sid:84755138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yipibul"; depth:8; endswith; nocase; http.host; content:"158.94.209.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892037/; classtype:trojan-activity;sid:84755137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.229.185.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892036/; classtype:trojan-activity;sid:84755136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"219.156.105.152"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892035/; classtype:trojan-activity;sid:84755135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agent.bin"; depth:10; endswith; nocase; http.host; content:"158.94.211.63"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892034/; classtype:trojan-activity;sid:84755134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.232.103.253"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892033/; classtype:trojan-activity;sid:84755133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.127.122.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892032/; classtype:trojan-activity;sid:84755132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.230.54.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892031/; classtype:trojan-activity;sid:84755131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sync.sh"; depth:8; endswith; nocase; http.host; content:"2.58.56.170"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892030/; classtype:trojan-activity;sid:84755130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payload.tgz"; depth:12; endswith; nocase; http.host; content:"2.58.56.170"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892029/; classtype:trojan-activity;sid:84755129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.230.54.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892028/; classtype:trojan-activity;sid:84755128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.197.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892027/; classtype:trojan-activity;sid:84755127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update.bin"; depth:11; endswith; nocase; http.host; content:"178.128.151.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892026/; classtype:trojan-activity;sid:84755126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update.exe"; depth:11; endswith; nocase; http.host; content:"178.128.151.248"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892025/; classtype:trojan-activity;sid:84755125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"209.38.75.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892024/; classtype:trojan-activity;sid:84755124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.21.94.139"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892023/; classtype:trojan-activity;sid:84755123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.159.173.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892022/; classtype:trojan-activity;sid:84755122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.127.122.126"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892021/; classtype:trojan-activity;sid:84755121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"185.69.121.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892020/; classtype:trojan-activity;sid:84755120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"185.69.121.139"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892019/; classtype:trojan-activity;sid:84755119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.44.38.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892018/; classtype:trojan-activity;sid:84755118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"198.211.109.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892017/; classtype:trojan-activity;sid:84755117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"198.211.109.187"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892016/; classtype:trojan-activity;sid:84755116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.197.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892015/; classtype:trojan-activity;sid:84755115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.180.170.37"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892014/; classtype:trojan-activity;sid:84755114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86"; depth:22; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892012/; classtype:trojan-activity;sid:84755112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.21.94.139"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892013/; classtype:trojan-activity;sid:84755113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86_64"; depth:25; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892007/; classtype:trojan-activity;sid:84755107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"68.183.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892008/; classtype:trojan-activity;sid:84755108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"68.183.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892009/; classtype:trojan-activity;sid:84755109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"68.183.43.110"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892010/; classtype:trojan-activity;sid:84755110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm7"; depth:23; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892011/; classtype:trojan-activity;sid:84755111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm"; depth:22; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892006/; classtype:trojan-activity;sid:84755106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.sh4"; depth:22; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892004/; classtype:trojan-activity;sid:84755104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.m68k"; depth:23; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892005/; classtype:trojan-activity;sid:84755105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mpsl"; depth:23; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892003/; classtype:trojan-activity;sid:84755103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892002/; classtype:trojan-activity;sid:84755102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892001/; classtype:trojan-activity;sid:84755101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891997/; classtype:trojan-activity;sid:84755097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891998/; classtype:trojan-activity;sid:84755098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm6"; depth:23; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891999/; classtype:trojan-activity;sid:84755099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i686"; depth:23; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892000/; classtype:trojan-activity;sid:84755100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i486"; depth:23; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891992/; classtype:trojan-activity;sid:84755092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.spc"; depth:22; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891993/; classtype:trojan-activity;sid:84755093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mips"; depth:23; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891994/; classtype:trojan-activity;sid:84755094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.ppc"; depth:22; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891995/; classtype:trojan-activity;sid:84755095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm5"; depth:23; endswith; nocase; http.host; content:"mail.rarewingvm.blog"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891996/; classtype:trojan-activity;sid:84755096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm"; depth:22; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891990/; classtype:trojan-activity;sid:84755090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i686"; depth:23; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891991/; classtype:trojan-activity;sid:84755091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.sh4"; depth:22; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891988/; classtype:trojan-activity;sid:84755088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i486"; depth:23; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891989/; classtype:trojan-activity;sid:84755089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.ppc"; depth:22; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891986/; classtype:trojan-activity;sid:84755086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891987/; classtype:trojan-activity;sid:84755087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mips"; depth:23; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891983/; classtype:trojan-activity;sid:84755083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mpsl"; depth:23; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891984/; classtype:trojan-activity;sid:84755084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86"; depth:22; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891985/; classtype:trojan-activity;sid:84755085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.spc"; depth:22; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891980/; classtype:trojan-activity;sid:84755080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.m68k"; depth:23; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891981/; classtype:trojan-activity;sid:84755081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86_64"; depth:25; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891982/; classtype:trojan-activity;sid:84755082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm7"; depth:23; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891978/; classtype:trojan-activity;sid:84755078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm5"; depth:23; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891979/; classtype:trojan-activity;sid:84755079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm6"; depth:23; endswith; nocase; http.host; content:"rarewingvm.blog"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891977/; classtype:trojan-activity;sid:84755077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86_64"; depth:25; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891976/; classtype:trojan-activity;sid:84755076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm5"; depth:23; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891972/; classtype:trojan-activity;sid:84755072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i486"; depth:23; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891973/; classtype:trojan-activity;sid:84755073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mpsl"; depth:23; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891974/; classtype:trojan-activity;sid:84755074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm6"; depth:23; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891975/; classtype:trojan-activity;sid:84755075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm"; depth:22; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891968/; classtype:trojan-activity;sid:84755068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.sh4"; depth:22; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891969/; classtype:trojan-activity;sid:84755069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891970/; classtype:trojan-activity;sid:84755070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mips"; depth:23; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891971/; classtype:trojan-activity;sid:84755071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86"; depth:22; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891964/; classtype:trojan-activity;sid:84755064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.m68k"; depth:23; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891965/; classtype:trojan-activity;sid:84755065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm7"; depth:23; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891966/; classtype:trojan-activity;sid:84755066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891967/; classtype:trojan-activity;sid:84755067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.ppc"; depth:22; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891962/; classtype:trojan-activity;sid:84755062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i686"; depth:23; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891963/; classtype:trojan-activity;sid:84755063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.spc"; depth:22; endswith; nocase; http.host; content:"94.154.43.80"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891961/; classtype:trojan-activity;sid:84755061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.60.241.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891959/; classtype:trojan-activity;sid:84755059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"217.60.241.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891960/; classtype:trojan-activity;sid:84755060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.60.241.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891957/; classtype:trojan-activity;sid:84755057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"217.60.241.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891958/; classtype:trojan-activity;sid:84755058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"158.94.209.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891956/; classtype:trojan-activity;sid:84755056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"158.94.209.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891955/; classtype:trojan-activity;sid:84755055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"185.241.208.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891953/; classtype:trojan-activity;sid:84755053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"158.94.211.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891954/; classtype:trojan-activity;sid:84755054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"158.94.211.110"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891952/; classtype:trojan-activity;sid:84755052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891951/; classtype:trojan-activity;sid:84755051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"91.92.243.254"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891948/; classtype:trojan-activity;sid:84755048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/load.sh"; depth:8; endswith; nocase; http.host; content:"192.159.99.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891949/; classtype:trojan-activity;sid:84755049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svc.exe"; depth:8; endswith; nocase; http.host; content:"94.154.35.240"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891950/; classtype:trojan-activity;sid:84755050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"124.198.131.99"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891945/; classtype:trojan-activity;sid:84755045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"124.198.132.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891946/; classtype:trojan-activity;sid:84755046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"124.198.131.217"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891947/; classtype:trojan-activity;sid:84755047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"178.16.55.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891944/; classtype:trojan-activity;sid:84755044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpsl"; depth:6; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891941/; classtype:trojan-activity;sid:84755041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"91.92.240.17"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891942/; classtype:trojan-activity;sid:84755042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"178.16.52.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891943/; classtype:trojan-activity;sid:84755043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"185.241.208.218"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891940/; classtype:trojan-activity;sid:84755040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"124.198.132.189"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891939/; classtype:trojan-activity;sid:84755039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"178.16.52.160"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891936/; classtype:trojan-activity;sid:84755036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"124.198.131.217"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891937/; classtype:trojan-activity;sid:84755037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"185.241.208.33"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891938/; classtype:trojan-activity;sid:84755038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.144.53"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891933/; classtype:trojan-activity;sid:84755033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"124.198.131.99"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891934/; classtype:trojan-activity;sid:84755034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"185.241.208.33"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891935/; classtype:trojan-activity;sid:84755035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"178.16.55.95"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891932/; classtype:trojan-activity;sid:84755032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.79.85.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891930/; classtype:trojan-activity;sid:84755030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.248.155.45"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891931/; classtype:trojan-activity;sid:84755031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarm"; depth:5; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891928/; classtype:trojan-activity;sid:84755028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.arm"; depth:8; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891929/; classtype:trojan-activity;sid:84755029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ftp.sh"; depth:7; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891927/; classtype:trojan-activity;sid:84755027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.arm7"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891925/; classtype:trojan-activity;sid:84755025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarm5"; depth:6; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891926/; classtype:trojan-activity;sid:84755026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ftp.sh"; depth:7; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891924/; classtype:trojan-activity;sid:84755024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mload.sh"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891923/; classtype:trojan-activity;sid:84755023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mpsl"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891908/; classtype:trojan-activity;sid:84755008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm"; depth:8; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891909/; classtype:trojan-activity;sid:84755009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mload.sh"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891910/; classtype:trojan-activity;sid:84755010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d.sh"; depth:5; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891911/; classtype:trojan-activity;sid:84755011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm7"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891912/; classtype:trojan-activity;sid:84755012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mips"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891913/; classtype:trojan-activity;sid:84755013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm6"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891914/; classtype:trojan-activity;sid:84755014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm5"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891915/; classtype:trojan-activity;sid:84755015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvmsupdate"; depth:11; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891916/; classtype:trojan-activity;sid:84755016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karm6"; depth:6; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891917/; classtype:trojan-activity;sid:84755017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmips"; depth:6; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891918/; classtype:trojan-activity;sid:84755018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarm6"; depth:6; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891919/; classtype:trojan-activity;sid:84755019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarm7"; depth:6; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891920/; classtype:trojan-activity;sid:84755020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w"; depth:2; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891921/; classtype:trojan-activity;sid:84755021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp.sh"; depth:8; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891922/; classtype:trojan-activity;sid:84755022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mips"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891906/; classtype:trojan-activity;sid:84755006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.44.38.211"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891907/; classtype:trojan-activity;sid:84755007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.spc"; depth:50; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891904/; classtype:trojan-activity;sid:84755004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/twget.sh"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891905/; classtype:trojan-activity;sid:84755005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.spc"; depth:50; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891901/; classtype:trojan-activity;sid:84755001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"84.54.33.167"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891902/; classtype:trojan-activity;sid:84755002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"84.54.33.167"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891903/; classtype:trojan-activity;sid:84755003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891899/; classtype:trojan-activity;sid:84754999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svchost.exe"; depth:12; endswith; nocase; http.host; content:"45.141.215.47"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891900/; classtype:trojan-activity;sid:84755000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"84.54.33.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891897/; classtype:trojan-activity;sid:84754997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.arm5"; depth:9; endswith; nocase; http.host; content:"yunvasilsky.mooo.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891898/; classtype:trojan-activity;sid:84754998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mpsl"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891892/; classtype:trojan-activity;sid:84754992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w"; depth:2; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891893/; classtype:trojan-activity;sid:84754993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/twget.sh"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891894/; classtype:trojan-activity;sid:84754994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891895/; classtype:trojan-activity;sid:84754995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.9.0.160"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891896/; classtype:trojan-activity;sid:84754996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.215.110.45"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891880/; classtype:trojan-activity;sid:84754980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm6"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891881/; classtype:trojan-activity;sid:84754981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm5"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891882/; classtype:trojan-activity;sid:84754982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d.sh"; depth:5; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891883/; classtype:trojan-activity;sid:84754983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvmsupdate"; depth:11; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891884/; classtype:trojan-activity;sid:84754984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm7"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891885/; classtype:trojan-activity;sid:84754985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.arm7"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891886/; classtype:trojan-activity;sid:84754986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a"; depth:2; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891887/; classtype:trojan-activity;sid:84754987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.arm"; depth:8; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891888/; classtype:trojan-activity;sid:84754988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm"; depth:8; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891889/; classtype:trojan-activity;sid:84754989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karm6"; depth:6; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891890/; classtype:trojan-activity;sid:84754990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lul.arm5"; depth:9; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891891/; classtype:trojan-activity;sid:84754991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp.sh"; depth:8; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891879/; classtype:trojan-activity;sid:84754979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"84.54.33.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891878/; classtype:trojan-activity;sid:84754978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"181.79.85.69"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891877/; classtype:trojan-activity;sid:84754977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nz/nz.i468"; depth:11; endswith; nocase; http.host; content:"31.56.209.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891876/; classtype:trojan-activity;sid:84754976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarm7"; depth:6; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891874/; classtype:trojan-activity;sid:84754974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm"; depth:22; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891875/; classtype:trojan-activity;sid:84754975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cache"; depth:6; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891864/; classtype:trojan-activity;sid:84754964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cometome"; depth:9; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891865/; classtype:trojan-activity;sid:84754965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm7"; depth:51; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891866/; classtype:trojan-activity;sid:84754966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.m68k"; depth:51; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891867/; classtype:trojan-activity;sid:84754967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i686"; depth:51; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891868/; classtype:trojan-activity;sid:84754968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891869/; classtype:trojan-activity;sid:84754969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.sh4"; depth:50; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891870/; classtype:trojan-activity;sid:84754970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i486"; depth:51; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891871/; classtype:trojan-activity;sid:84754971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm"; depth:50; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891872/; classtype:trojan-activity;sid:84754972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.sh4"; depth:50; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891873/; classtype:trojan-activity;sid:84754973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891862/; classtype:trojan-activity;sid:84754962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.m68k"; depth:51; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891863/; classtype:trojan-activity;sid:84754963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarm5"; depth:6; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891860/; classtype:trojan-activity;sid:84754960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.ppc"; depth:22; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891861/; classtype:trojan-activity;sid:84754961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.sh4"; depth:22; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891859/; classtype:trojan-activity;sid:84754959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cometome"; depth:9; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891858/; classtype:trojan-activity;sid:84754958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmaarriioisectanee/mmaarriioisectanee.mips"; depth:43; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891856/; classtype:trojan-activity;sid:84754956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarm6"; depth:6; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891857/; classtype:trojan-activity;sid:84754957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86"; depth:50; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891855/; classtype:trojan-activity;sid:84754955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gigatex/mipsel"; depth:15; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891834/; classtype:trojan-activity;sid:84754934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/giga.sh"; depth:8; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891835/; classtype:trojan-activity;sid:84754935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm6"; depth:51; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891836/; classtype:trojan-activity;sid:84754936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891837/; classtype:trojan-activity;sid:84754937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarm"; depth:5; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891838/; classtype:trojan-activity;sid:84754938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mpsl"; depth:23; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891839/; classtype:trojan-activity;sid:84754939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arc"; depth:50; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891840/; classtype:trojan-activity;sid:84754940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm6"; depth:23; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891841/; classtype:trojan-activity;sid:84754941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86"; depth:22; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891842/; classtype:trojan-activity;sid:84754942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.spc"; depth:22; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891843/; classtype:trojan-activity;sid:84754943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.mips"; depth:23; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891844/; classtype:trojan-activity;sid:84754944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm5"; depth:23; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891845/; classtype:trojan-activity;sid:84754945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arc"; depth:22; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891846/; classtype:trojan-activity;sid:84754946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891847/; classtype:trojan-activity;sid:84754947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mpsl"; depth:51; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891848/; classtype:trojan-activity;sid:84754948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891849/; classtype:trojan-activity;sid:84754949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmips"; depth:6; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891850/; classtype:trojan-activity;sid:84754950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.ppc"; depth:50; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891851/; classtype:trojan-activity;sid:84754951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mpsl"; depth:51; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891852/; classtype:trojan-activity;sid:84754952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.arm7"; depth:23; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891853/; classtype:trojan-activity;sid:84754953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.m68k"; depth:23; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891854/; classtype:trojan-activity;sid:84754954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arc"; depth:50; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891824/; classtype:trojan-activity;sid:84754924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gigatex/x86"; depth:12; endswith; nocase; http.host; content:"205.237.110.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891825/; classtype:trojan-activity;sid:84754925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mips"; depth:51; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891826/; classtype:trojan-activity;sid:84754926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm6"; depth:51; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891827/; classtype:trojan-activity;sid:84754927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm7"; depth:51; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891828/; classtype:trojan-activity;sid:84754928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mips"; depth:51; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891829/; classtype:trojan-activity;sid:84754929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cache"; depth:6; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891830/; classtype:trojan-activity;sid:84754930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891831/; classtype:trojan-activity;sid:84754931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.ppc"; depth:50; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891832/; classtype:trojan-activity;sid:84754932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891833/; classtype:trojan-activity;sid:84754933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmaarriioisectanee/mmaarriioisectanee.mips"; depth:43; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891822/; classtype:trojan-activity;sid:84754922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm"; depth:50; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891823/; classtype:trojan-activity;sid:84754923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i686"; depth:23; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891821/; classtype:trojan-activity;sid:84754921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.i468"; depth:23; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891818/; classtype:trojan-activity;sid:84754918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiddenbin/boatnet.x86_64"; depth:25; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891819/; classtype:trojan-activity;sid:84754919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cometome"; depth:9; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891820/; classtype:trojan-activity;sid:84754920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpsl"; depth:6; endswith; nocase; http.host; content:"2.26.136.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891817/; classtype:trojan-activity;sid:84754917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i686"; depth:51; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891816/; classtype:trojan-activity;sid:84754916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm5"; depth:51; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891808/; classtype:trojan-activity;sid:84754908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i486"; depth:51; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891809/; classtype:trojan-activity;sid:84754909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891810/; classtype:trojan-activity;sid:84754910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86"; depth:50; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891811/; classtype:trojan-activity;sid:84754911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm5"; depth:51; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891812/; classtype:trojan-activity;sid:84754912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmaarriioisectanee/mmaarriioisectanee.mips"; depth:43; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891813/; classtype:trojan-activity;sid:84754913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cache"; depth:6; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891814/; classtype:trojan-activity;sid:84754914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86_64"; depth:53; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891815/; classtype:trojan-activity;sid:84754915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86_64"; depth:53; endswith; nocase; http.host; content:"mail.fairgroovetr.blog"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891805/; classtype:trojan-activity;sid:84754905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"2.187.249.41"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891806/; classtype:trojan-activity;sid:84754906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"molemole.my.id"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891807/; classtype:trojan-activity;sid:84754907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.sh4"; depth:50; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891802/; classtype:trojan-activity;sid:84754902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mpsl"; depth:51; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891803/; classtype:trojan-activity;sid:84754903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm5"; depth:51; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891804/; classtype:trojan-activity;sid:84754904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.spc"; depth:50; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891796/; classtype:trojan-activity;sid:84754896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm6"; depth:51; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891797/; classtype:trojan-activity;sid:84754897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86_64"; depth:53; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891798/; classtype:trojan-activity;sid:84754898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mips"; depth:51; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891799/; classtype:trojan-activity;sid:84754899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm7"; depth:51; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891800/; classtype:trojan-activity;sid:84754900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i686"; depth:51; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891801/; classtype:trojan-activity;sid:84754901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.m68k"; depth:51; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891791/; classtype:trojan-activity;sid:84754891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86"; depth:50; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891792/; classtype:trojan-activity;sid:84754892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arc"; depth:50; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891793/; classtype:trojan-activity;sid:84754893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.ppc"; depth:50; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891794/; classtype:trojan-activity;sid:84754894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm"; depth:50; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891795/; classtype:trojan-activity;sid:84754895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i486"; depth:51; endswith; nocase; http.host; content:"fairgroovetr.blog"; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891790/; classtype:trojan-activity;sid:84754890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86"; depth:50; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891788/; classtype:trojan-activity;sid:84754888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i486"; depth:51; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891789/; classtype:trojan-activity;sid:84754889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm7"; depth:51; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891785/; classtype:trojan-activity;sid:84754885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm6"; depth:51; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891786/; classtype:trojan-activity;sid:84754886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm5"; depth:51; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891787/; classtype:trojan-activity;sid:84754887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mpsl"; depth:51; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891775/; classtype:trojan-activity;sid:84754875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.m68k"; depth:51; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891776/; classtype:trojan-activity;sid:84754876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.i686"; depth:51; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891777/; classtype:trojan-activity;sid:84754877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.mips"; depth:51; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891778/; classtype:trojan-activity;sid:84754878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.spc"; depth:50; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891779/; classtype:trojan-activity;sid:84754879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.x86_64"; depth:53; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891780/; classtype:trojan-activity;sid:84754880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891781/; classtype:trojan-activity;sid:84754881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arm"; depth:50; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891782/; classtype:trojan-activity;sid:84754882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.ppc"; depth:50; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891783/; classtype:trojan-activity;sid:84754883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.arc"; depth:50; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891784/; classtype:trojan-activity;sid:84754884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cache"; depth:6; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891769/; classtype:trojan-activity;sid:84754869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891770/; classtype:trojan-activity;sid:84754870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmaarriioisectanee/mmaarriioisectanee.mips"; depth:43; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891771/; classtype:trojan-activity;sid:84754871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cometome"; depth:9; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891772/; classtype:trojan-activity;sid:84754872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891773/; classtype:trojan-activity;sid:84754873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z0l1mxjm4mdl4jjfjf7sb2vdmv/mmaarriioisectanee.sh4"; depth:50; endswith; nocase; http.host; content:"94.154.43.61"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891774/; classtype:trojan-activity;sid:84754874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/system.txt"; depth:15; endswith; nocase; http.host; content:"msfconfig.icu"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891768/; classtype:trojan-activity;sid:84754868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"221.15.189.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891767/; classtype:trojan-activity;sid:84754867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.166.31.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891765/; classtype:trojan-activity;sid:84754865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.44.62"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891766/; classtype:trojan-activity;sid:84754866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"38.56.21.66"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891764/; classtype:trojan-activity;sid:84754864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proxy/arm5"; depth:11; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891743/; classtype:trojan-activity;sid:84754843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proxy/aarch64"; depth:14; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891744/; classtype:trojan-activity;sid:84754844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/x86"; depth:8; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891745/; classtype:trojan-activity;sid:84754845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/mips"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891746/; classtype:trojan-activity;sid:84754846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891747/; classtype:trojan-activity;sid:84754847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891748/; classtype:trojan-activity;sid:84754848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proxy/mpsl"; depth:11; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891749/; classtype:trojan-activity;sid:84754849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891750/; classtype:trojan-activity;sid:84754850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/mpsl"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891751/; classtype:trojan-activity;sid:84754851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proxy/arm7"; depth:11; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891752/; classtype:trojan-activity;sid:84754852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891753/; classtype:trojan-activity;sid:84754853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891754/; classtype:trojan-activity;sid:84754854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wget.sh"; depth:8; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891755/; classtype:trojan-activity;sid:84754855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891756/; classtype:trojan-activity;sid:84754856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/arm5"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891757/; classtype:trojan-activity;sid:84754857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gigatex/arm7"; depth:13; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891758/; classtype:trojan-activity;sid:84754858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proxy/mips"; depth:11; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891759/; classtype:trojan-activity;sid:84754859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proxy/arm"; depth:10; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891760/; classtype:trojan-activity;sid:84754860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl.sh"; depth:8; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891761/; classtype:trojan-activity;sid:84754861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proxy/x86"; depth:10; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891762/; classtype:trojan-activity;sid:84754862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891763/; classtype:trojan-activity;sid:84754863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/x86"; depth:14; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891742/; classtype:trojan-activity;sid:84754842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mpsl"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891725/; classtype:trojan-activity;sid:84754825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/arm"; depth:14; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891726/; classtype:trojan-activity;sid:84754826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/mips"; depth:15; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891727/; classtype:trojan-activity;sid:84754827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/aarch64"; depth:12; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891728/; classtype:trojan-activity;sid:84754828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gigatex/mpsl"; depth:13; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891729/; classtype:trojan-activity;sid:84754829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm5"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891730/; classtype:trojan-activity;sid:84754830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm7"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891731/; classtype:trojan-activity;sid:84754831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m"; depth:2; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891732/; classtype:trojan-activity;sid:84754832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t"; depth:2; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891733/; classtype:trojan-activity;sid:84754833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/arm"; depth:8; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891734/; classtype:trojan-activity;sid:84754834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tvt/arm7"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891735/; classtype:trojan-activity;sid:84754835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o"; depth:2; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891736/; classtype:trojan-activity;sid:84754836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/massload"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891737/; classtype:trojan-activity;sid:84754837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.x86"; depth:8; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891738/; classtype:trojan-activity;sid:84754838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/arm7"; depth:15; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891739/; classtype:trojan-activity;sid:84754839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gigatex/mips"; depth:13; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891740/; classtype:trojan-activity;sid:84754840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/arm5"; depth:15; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891741/; classtype:trojan-activity;sid:84754841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gigatex/arm"; depth:12; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891717/; classtype:trojan-activity;sid:84754817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891718/; classtype:trojan-activity;sid:84754818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/no_killer/mpsl"; depth:15; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891719/; classtype:trojan-activity;sid:84754819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.mips"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891720/; classtype:trojan-activity;sid:84754820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gigatex/arm5"; depth:13; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891721/; classtype:trojan-activity;sid:84754821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvr.sh"; depth:7; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891722/; classtype:trojan-activity;sid:84754822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tplink.sh"; depth:10; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891723/; classtype:trojan-activity;sid:84754823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlr.arm4"; depth:9; endswith; nocase; http.host; content:"tractor.trees4sale.net"; depth:22; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891724/; classtype:trojan-activity;sid:84754824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kla.sh"; depth:12; endswith; nocase; http.host; content:"94.154.43.68"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891715/; classtype:trojan-activity;sid:84754815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohshit.sh"; depth:10; endswith; nocase; http.host; content:"103.161.17.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891716/; classtype:trojan-activity;sid:84754816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"130.12.209.147"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891714/; classtype:trojan-activity;sid:84754814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"110.37.97.32"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891713/; classtype:trojan-activity;sid:84754813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; depth:33; endswith; nocase; http.host; content:"31.56.209.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891710/; classtype:trojan-activity;sid:84754810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; depth:30; endswith; nocase; http.host; content:"31.56.209.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891711/; classtype:trojan-activity;sid:84754811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deploy.sh"; depth:10; endswith; nocase; http.host; content:"91.199.133.133"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891712/; classtype:trojan-activity;sid:84754812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; depth:37; endswith; nocase; http.host; content:"31.56.209.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891708/; classtype:trojan-activity;sid:84754808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; depth:30; endswith; nocase; http.host; content:"31.56.209.70"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891709/; classtype:trojan-activity;sid:84754809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_eda3b676565b6736.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891706/; classtype:trojan-activity;sid:84754806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0e649edddaf-12.msi"; depth:19; endswith; nocase; http.host; content:"pub-da43c68507c44a0f89782831aed83484.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891707/; classtype:trojan-activity;sid:84754807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/l2-17-1-wrk-jsdh.msi"; depth:21; endswith; nocase; http.host; content:"pub-272fd20f9e3d49d5864e441b0c7a4fb8.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891705/; classtype:trojan-activity;sid:84754805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sc-2-rm-kjds17-p.exe"; depth:21; endswith; nocase; http.host; content:"pub-991af6d525914bda8f213aaa6c77e161.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891703/; classtype:trojan-activity;sid:84754803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/l2-prm-wrksc.msi"; depth:17; endswith; nocase; http.host; content:"pub-8a311f63df364529b264fa273304d2d9.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891704/; classtype:trojan-activity;sid:84754804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_e387a350c93377c6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891701/; classtype:trojan-activity;sid:84754801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b44b403eb8ff1768.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891702/; classtype:trojan-activity;sid:84754802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/rtn5r2ig6gqvsv2vasqbx/krypton-1.21.1-v15.jar|3f|rlkey=q48p4pfjgt1ygsmd0moc6ihnv|7c|26|7c|st=qlzqzgsy"; depth:108; endswith; nocase; http.host; content:"dl.dropboxusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891700/; classtype:trojan-activity;sid:84754800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"117.26.226.163"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891699/; classtype:trojan-activity;sid:84754799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"61.52.44.62"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891698/; classtype:trojan-activity;sid:84754798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.166.31.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891697/; classtype:trojan-activity;sid:84754797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.42.30.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891696/; classtype:trojan-activity;sid:84754796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.0.122"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891695/; classtype:trojan-activity;sid:84754795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.1.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891694/; classtype:trojan-activity;sid:84754794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.54.189.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891693/; classtype:trojan-activity;sid:84754793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"39.90.187.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891692/; classtype:trojan-activity;sid:84754792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.165.172.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891691/; classtype:trojan-activity;sid:84754791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.54.189.23"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891690/; classtype:trojan-activity;sid:84754790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.161.2.82"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891689/; classtype:trojan-activity;sid:84754789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.190.1.39"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891688/; classtype:trojan-activity;sid:84754788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.0.122"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891687/; classtype:trojan-activity;sid:84754787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"112.248.155.45"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891686/; classtype:trojan-activity;sid:84754786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"45.165.172.91"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891685/; classtype:trojan-activity;sid:84754785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.161.2.82"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891684/; classtype:trojan-activity;sid:84754784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"216.126.86.127"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891683/; classtype:trojan-activity;sid:84754783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.42.30.72"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891682/; classtype:trojan-activity;sid:84754782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"221.15.189.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891681/; classtype:trojan-activity;sid:84754781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.215.138.98"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891680/; classtype:trojan-activity;sid:84754780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"106.40.240.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891679/; classtype:trojan-activity;sid:84754779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.57.74.75"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891678/; classtype:trojan-activity;sid:84754778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.57.74.75"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891677/; classtype:trojan-activity;sid:84754777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.134.175.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891676/; classtype:trojan-activity;sid:84754776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"106.40.240.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891675/; classtype:trojan-activity;sid:84754775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.134.175.71"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891674/; classtype:trojan-activity;sid:84754774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.14.102.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891673/; classtype:trojan-activity;sid:84754773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.37.68.65"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891672/; classtype:trojan-activity;sid:84754772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.8.47.4"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891670/; classtype:trojan-activity;sid:84754770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.101.82"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891671/; classtype:trojan-activity;sid:84754771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.50.66.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891669/; classtype:trojan-activity;sid:84754769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"219.156.105.152"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891668/; classtype:trojan-activity;sid:84754768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.8.47.4"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891667/; classtype:trojan-activity;sid:84754767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.178.61.155"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891666/; classtype:trojan-activity;sid:84754766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.50.66.149"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891665/; classtype:trojan-activity;sid:84754765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.231.47.59"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891664/; classtype:trojan-activity;sid:84754764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.189.198.193"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891663/; classtype:trojan-activity;sid:84754763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.189.198.193"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891662/; classtype:trojan-activity;sid:84754762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.191.137.44"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891661/; classtype:trojan-activity;sid:84754761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.116.80.226"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891660/; classtype:trojan-activity;sid:84754760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.191.104.40"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891659/; classtype:trojan-activity;sid:84754759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"125.40.83.123"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891658/; classtype:trojan-activity;sid:84754758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.37.102.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891657/; classtype:trojan-activity;sid:84754757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.37.102.120"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891656/; classtype:trojan-activity;sid:84754756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"196.191.104.40"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891655/; classtype:trojan-activity;sid:84754755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.165.115.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891654/; classtype:trojan-activity;sid:84754754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.14.102.112"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891653/; classtype:trojan-activity;sid:84754753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.184.26.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891652/; classtype:trojan-activity;sid:84754752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.7.240.14"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891651/; classtype:trojan-activity;sid:84754751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.126.249.0"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891650/; classtype:trojan-activity;sid:84754750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.184.26.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891649/; classtype:trojan-activity;sid:84754749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.126.249.0"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891648/; classtype:trojan-activity;sid:84754748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_26542a4270d4c3a5.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891647/; classtype:trojan-activity;sid:84754747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.23.204.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891646/; classtype:trojan-activity;sid:84754746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"220.158.234.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891643/; classtype:trojan-activity;sid:84754743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"220.158.234.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891644/; classtype:trojan-activity;sid:84754744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"220.158.234.220"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891645/; classtype:trojan-activity;sid:84754745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"222.219.74.179"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891642/; classtype:trojan-activity;sid:84754742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_c7fcb2e3eb5326e6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891641/; classtype:trojan-activity;sid:84754741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.186.248.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891640/; classtype:trojan-activity;sid:84754740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.49.200.94"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891639/; classtype:trojan-activity;sid:84754739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"115.63.11.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891638/; classtype:trojan-activity;sid:84754738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"42.227.203.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891637/; classtype:trojan-activity;sid:84754737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.173.239.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891636/; classtype:trojan-activity;sid:84754736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"125.41.1.174"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891635/; classtype:trojan-activity;sid:84754735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cleen_trs1.exe"; depth:15; endswith; nocase; http.host; content:"lapidorseposoalovbs2.com"; depth:24; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891634/; classtype:trojan-activity;sid:84754734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.5.186.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891633/; classtype:trojan-activity;sid:84754733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.227.203.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891632/; classtype:trojan-activity;sid:84754732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.146.92.46"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891631/; classtype:trojan-activity;sid:84754731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.117.12.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891630/; classtype:trojan-activity;sid:84754730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"182.117.12.120"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891629/; classtype:trojan-activity;sid:84754729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"61.52.159.127"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891628/; classtype:trojan-activity;sid:84754728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"117.26.82.68"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891627/; classtype:trojan-activity;sid:84754727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"42.231.47.59"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891626/; classtype:trojan-activity;sid:84754726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_2e5f4b42399cbea0.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891625/; classtype:trojan-activity;sid:84754725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"110.36.25.33"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891624/; classtype:trojan-activity;sid:84754724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"105.187.42.210"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891623/; classtype:trojan-activity;sid:84754723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.112.29.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891622/; classtype:trojan-activity;sid:84754722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.63.11.85"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891621/; classtype:trojan-activity;sid:84754721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.190.105.170"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891620/; classtype:trojan-activity;sid:84754720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"59.58.188.145"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891619/; classtype:trojan-activity;sid:84754719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"163.142.95.231"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891618/; classtype:trojan-activity;sid:84754718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.240.253.166"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891617/; classtype:trojan-activity;sid:84754717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"59.58.188.145"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891616/; classtype:trojan-activity;sid:84754716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"105.186.248.15"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891615/; classtype:trojan-activity;sid:84754715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cleen_trs1.exe"; depth:15; endswith; nocase; http.host; content:"cleenfoecleen22.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3891614/; classtype:trojan-activity;sid:84754714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/enterprise/student_s.bin"; depth:25; endswith; nocase; http.host; content:"158.94.211.92"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_25; reference:url, urlhaus.abuse.ch/url/3891471/; classtype:trojan-activity;sid:84754571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1eznn9zsmbkarokxijqjnw-p_jnxqhjqz"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_25; reference:url, urlhaus.abuse.ch/url/3891433/; classtype:trojan-activity;sid:84754533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1et9jukcxhkvlaqgxwdxvzylzkqgwl0bo"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_25; reference:url, urlhaus.abuse.ch/url/3891432/; classtype:trojan-activity;sid:84754532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_8a7c2cae7ca4b114.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_25; reference:url, urlhaus.abuse.ch/url/3891404/; classtype:trojan-activity;sid:84754504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/desk.exe"; depth:9; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_24; reference:url, urlhaus.abuse.ch/url/3891252/; classtype:trojan-activity;sid:84754352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"188.233.80.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_24; reference:url, urlhaus.abuse.ch/url/3891251/; classtype:trojan-activity;sid:84754351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.216.199.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_24; reference:url, urlhaus.abuse.ch/url/3891181/; classtype:trojan-activity;sid:84754281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_f309f8496f916deb.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_23; reference:url, urlhaus.abuse.ch/url/3890838/; classtype:trojan-activity;sid:84753938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moll.psm"; depth:9; endswith; nocase; http.host; content:"tangentwaves.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_23; reference:url, urlhaus.abuse.ch/url/3890714/; classtype:trojan-activity;sid:84753814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.216.199.241"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890258/; classtype:trojan-activity;sid:84753358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.96.228.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890252/; classtype:trojan-activity;sid:84753352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.96.228.235"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890250/; classtype:trojan-activity;sid:84753350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"133.130.120.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890232/; classtype:trojan-activity;sid:84753332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"107.175.91.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890231/; classtype:trojan-activity;sid:84753331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"133.130.120.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890228/; classtype:trojan-activity;sid:84753328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"67.230.186.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890198/; classtype:trojan-activity;sid:84753298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"41.87.80.123"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890200/; classtype:trojan-activity;sid:84753300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"67.230.186.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890201/; classtype:trojan-activity;sid:84753301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"152.42.178.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890204/; classtype:trojan-activity;sid:84753304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"140.238.229.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890206/; classtype:trojan-activity;sid:84753306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"208.87.131.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890207/; classtype:trojan-activity;sid:84753307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"140.238.229.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890208/; classtype:trojan-activity;sid:84753308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"208.87.131.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890212/; classtype:trojan-activity;sid:84753312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"152.42.178.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890213/; classtype:trojan-activity;sid:84753313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"107.175.91.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890187/; classtype:trojan-activity;sid:84753287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"41.87.80.123"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890188/; classtype:trojan-activity;sid:84753288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"188.233.80.29"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890181/; classtype:trojan-activity;sid:84753281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"208.87.131.195"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890138/; classtype:trojan-activity;sid:84753238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"140.238.229.80"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890131/; classtype:trojan-activity;sid:84753231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"107.175.91.154"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890132/; classtype:trojan-activity;sid:84753232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"152.42.178.130"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890134/; classtype:trojan-activity;sid:84753234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"41.87.80.123"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890135/; classtype:trojan-activity;sid:84753235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"67.230.186.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890120/; classtype:trojan-activity;sid:84753220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"133.130.120.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890121/; classtype:trojan-activity;sid:84753221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"airtickts.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890046/; classtype:trojan-activity;sid:84753146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v0/b/june-july-dd5c8-91uk3/o/22mondaylincoln.txt|3f|alt=media|7c|26|7c|token=ce3b0c87-e670-4b32-940c-675bdc4fc8d2"; depth:114; endswith; nocase; http.host; content:"firebasestorage.googleapis.com"; depth:30; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890029/; classtype:trojan-activity;sid:84753129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_092444.png"; depth:15; endswith; nocase; http.host; content:"awarenessexhibition.com"; depth:23; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890027/; classtype:trojan-activity;sid:84753127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm4"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3889997/; classtype:trojan-activity;sid:84753097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.27"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3889944/; classtype:trojan-activity;sid:84753044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.27"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3889942/; classtype:trojan-activity;sid:84753042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s.exe"; depth:6; endswith; nocase; http.host; content:"152.42.130.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3889911/; classtype:trojan-activity;sid:84753011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.219.119.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889780/; classtype:trojan-activity;sid:84752880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.219.119.11"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889768/; classtype:trojan-activity;sid:84752868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mugen.sh"; depth:9; endswith; nocase; http.host; content:"lifeisabouthavingfun448.duckdns.org"; depth:35; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889639/; classtype:trojan-activity;sid:84752739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//arm5"; depth:6; endswith; nocase; http.host; content:"lifeisabouthavingfun448.duckdns.org"; depth:35; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889626/; classtype:trojan-activity;sid:84752726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//x86"; depth:5; endswith; nocase; http.host; content:"lifeisabouthavingfun448.duckdns.org"; depth:35; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889628/; classtype:trojan-activity;sid:84752728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//mips"; depth:6; endswith; nocase; http.host; content:"lifeisabouthavingfun448.duckdns.org"; depth:35; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889629/; classtype:trojan-activity;sid:84752729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//mpsl"; depth:6; endswith; nocase; http.host; content:"lifeisabouthavingfun448.duckdns.org"; depth:35; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889630/; classtype:trojan-activity;sid:84752730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//arm4"; depth:6; endswith; nocase; http.host; content:"lifeisabouthavingfun448.duckdns.org"; depth:35; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889633/; classtype:trojan-activity;sid:84752733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//arm7"; depth:6; endswith; nocase; http.host; content:"lifeisabouthavingfun448.duckdns.org"; depth:35; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889638/; classtype:trojan-activity;sid:84752738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mipsrouter"; depth:23; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889599/; classtype:trojan-activity;sid:84752699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889598/; classtype:trojan-activity;sid:84752698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v0/b/june-july-dd5c8/o/cytophil.exe|3f|alt=media|7c|26|7c|token=cb9fe647-a483-4d59-93e6-c044948eb453"; depth:101; endswith; nocase; http.host; content:"firebasestorage.googleapis.com"; depth:30; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889399/; classtype:trojan-activity;sid:84752499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//arm5"; depth:6; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889390/; classtype:trojan-activity;sid:84752490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//x86"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889391/; classtype:trojan-activity;sid:84752491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//mpsl"; depth:6; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889385/; classtype:trojan-activity;sid:84752485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//mips"; depth:6; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889386/; classtype:trojan-activity;sid:84752486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mugen.sh"; depth:9; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889387/; classtype:trojan-activity;sid:84752487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//arm7"; depth:6; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889388/; classtype:trojan-activity;sid:84752488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//arm4"; depth:6; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889389/; classtype:trojan-activity;sid:84752489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.247.88.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889356/; classtype:trojan-activity;sid:84752456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"77.247.88.88"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_20; reference:url, urlhaus.abuse.ch/url/3889141/; classtype:trojan-activity;sid:84752241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app.exe"; depth:8; endswith; nocase; http.host; content:"164.90.210.228"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_20; reference:url, urlhaus.abuse.ch/url/3889044/; classtype:trojan-activity;sid:84752144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"81.236.234.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_20; reference:url, urlhaus.abuse.ch/url/3889037/; classtype:trojan-activity;sid:84752137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3888899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"81.236.234.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_20; reference:url, urlhaus.abuse.ch/url/3888899/; classtype:trojan-activity;sid:84751999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3888879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"5.166.107.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_19; reference:url, urlhaus.abuse.ch/url/3888879/; classtype:trojan-activity;sid:84751979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3888836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scl/fi/58zjwuoe83qjjpj7tt3y2/chilloutvrmod.exe|3f|rlkey=vojb0l0ls4uc32z51ykogot24|7c|26|7c|st=wftymyy8|7c|26|7c|dl=1"; depth:117; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_19; reference:url, urlhaus.abuse.ch/url/3888836/; classtype:trojan-activity;sid:84751936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3888735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clean"; depth:6; endswith; nocase; http.host; content:"147.182.224.216"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_19; reference:url, urlhaus.abuse.ch/url/3888735/; classtype:trojan-activity;sid:84751835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3888197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_18; reference:url, urlhaus.abuse.ch/url/3888197/; classtype:trojan-activity;sid:84751297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3888187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.106"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_18; reference:url, urlhaus.abuse.ch/url/3888187/; classtype:trojan-activity;sid:84751287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3887801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telnet.sh"; depth:10; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_17; reference:url, urlhaus.abuse.ch/url/3887801/; classtype:trojan-activity;sid:84750901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3887780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.135.10.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_17; reference:url, urlhaus.abuse.ch/url/3887780/; classtype:trojan-activity;sid:84750880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3887219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"103.217.215.238"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_16; reference:url, urlhaus.abuse.ch/url/3887219/; classtype:trojan-activity;sid:84750319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3887024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"113.254.36.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_16; reference:url, urlhaus.abuse.ch/url/3887024/; classtype:trojan-activity;sid:84750124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3887001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"113.254.36.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_16; reference:url, urlhaus.abuse.ch/url/3887001/; classtype:trojan-activity;sid:84750101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trichloroflouromethane/order.js"; depth:32; endswith; nocase; http.host; content:"studiogioeli.it"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_15; reference:url, urlhaus.abuse.ch/url/3886852/; classtype:trojan-activity;sid:84749952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armful/atpi_annual_dinner.js"; depth:29; endswith; nocase; http.host; content:"studiogioeli.it"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_15; reference:url, urlhaus.abuse.ch/url/3886828/; classtype:trojan-activity;sid:84749928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/awkwarderf80.java"; depth:18; endswith; nocase; http.host; content:"siaasesoria.com.mx"; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_15; reference:url, urlhaus.abuse.ch/url/3886706/; classtype:trojan-activity;sid:84749806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.189.183.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_15; reference:url, urlhaus.abuse.ch/url/3886571/; classtype:trojan-activity;sid:84749671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"91.189.183.211"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_15; reference:url, urlhaus.abuse.ch/url/3886567/; classtype:trojan-activity;sid:84749667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f/m/libcommon.so_x86_64"; depth:24; endswith; nocase; http.host; content:"endpoint.project0.cc"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_14; reference:url, urlhaus.abuse.ch/url/3886225/; classtype:trojan-activity;sid:84749325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f/m/.x0-lock_x86_64"; depth:20; endswith; nocase; http.host; content:"endpoint.project0.cc"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_14; reference:url, urlhaus.abuse.ch/url/3886226/; classtype:trojan-activity;sid:84749326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_77b5757ae75eb20b.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_13; reference:url, urlhaus.abuse.ch/url/3885754/; classtype:trojan-activity;sid:84748854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.135.10.58"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_13; reference:url, urlhaus.abuse.ch/url/3885732/; classtype:trojan-activity;sid:84748832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.sh4"; depth:16; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885440/; classtype:trojan-activity;sid:84748540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm5"; depth:17; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885288/; classtype:trojan-activity;sid:84748388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.x86_64"; depth:19; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885289/; classtype:trojan-activity;sid:84748389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mips"; depth:17; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885290/; classtype:trojan-activity;sid:84748390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.ppc"; depth:16; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885292/; classtype:trojan-activity;sid:84748392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.m68k"; depth:17; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885293/; classtype:trojan-activity;sid:84748393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.x86"; depth:16; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885283/; classtype:trojan-activity;sid:84748383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.mpsl"; depth:17; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885284/; classtype:trojan-activity;sid:84748384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm6"; depth:17; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885285/; classtype:trojan-activity;sid:84748385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm"; depth:16; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885286/; classtype:trojan-activity;sid:84748386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/putita.arm7"; depth:17; endswith; nocase; http.host; content:"64.89.163.215"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_12; reference:url, urlhaus.abuse.ch/url/3885281/; classtype:trojan-activity;sid:84748381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1jcwgiy3fjjwvb9tapefufcmnv-sf2-ky"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884861/; classtype:trojan-activity;sid:84747961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1n8ludsbc-n2l7ozywfcnlxra4zljwtem"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884862/; classtype:trojan-activity;sid:84747962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1dmm3ndgqp_-n-ksim0-zioctjdqyonyt"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884856/; classtype:trojan-activity;sid:84747956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1obsjrfaxe5d8je8uzdmkgk9kus-nsqxs"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884855/; classtype:trojan-activity;sid:84747955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1pmy1l8vqsy1xdnu-fjshxgc8x3otxafk"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884846/; classtype:trojan-activity;sid:84747946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=17ivr2nqexwoga4m4n2ec3jsnk6u1l3vp"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884841/; classtype:trojan-activity;sid:84747941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s0907.exe"; depth:10; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884702/; classtype:trojan-activity;sid:84747802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a3f8d2/kaizen.x86_64_srv"; depth:25; endswith; nocase; http.host; content:"196.251.121.142"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884452/; classtype:trojan-activity;sid:84747552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z/wr.php"; depth:9; endswith; nocase; http.host; content:"160.119.69.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884409/; classtype:trojan-activity;sid:84747509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z/wr.php"; depth:9; endswith; nocase; http.host; content:"45.95.147.178"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884408/; classtype:trojan-activity;sid:84747508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k.php"; depth:6; endswith; nocase; http.host; content:"160.119.69.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884398/; classtype:trojan-activity;sid:84747498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1q3l8qtxuanbtgsruklb2hq5e9lp75xop"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884319/; classtype:trojan-activity;sid:84747419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=194tdr8jizmjhuah53b9upptkksjos0es"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884268/; classtype:trojan-activity;sid:84747368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t0907.exe"; depth:10; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884167/; classtype:trojan-activity;sid:84747267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"90.224.208.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884137/; classtype:trojan-activity;sid:84747237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"90.224.208.190"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884130/; classtype:trojan-activity;sid:84747230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3a1cc00092af29d0.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_08; reference:url, urlhaus.abuse.ch/url/3883830/; classtype:trojan-activity;sid:84746930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883636/; classtype:trojan-activity;sid:84746736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883631/; classtype:trojan-activity;sid:84746731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i486"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883632/; classtype:trojan-activity;sid:84746732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883635/; classtype:trojan-activity;sid:84746735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883627/; classtype:trojan-activity;sid:84746727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883625/; classtype:trojan-activity;sid:84746725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"45.90.163.37"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883626/; classtype:trojan-activity;sid:84746726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pass.ps1"; depth:9; endswith; nocase; http.host; content:"qv.co.ke"; depth:8; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883569/; classtype:trojan-activity;sid:84746669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download"; depth:9; endswith; nocase; http.host; content:"64.89.161.119"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3881816/; classtype:trojan-activity;sid:84744916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenwillzltd.zip"; depth:16; endswith; nocase; http.host; content:"kenwillzltd.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3881812/; classtype:trojan-activity;sid:84744912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenwillzltd.zip"; depth:16; endswith; nocase; http.host; content:"www.kenwillzltd.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3881813/; classtype:trojan-activity;sid:84744913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tu3929.exe"; depth:11; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3881810/; classtype:trojan-activity;sid:84744910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.m68k"; depth:10; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881585/; classtype:trojan-activity;sid:84744685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv7l"; depth:12; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881586/; classtype:trojan-activity;sid:84744686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv5l"; depth:12; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881587/; classtype:trojan-activity;sid:84744687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mipsel"; depth:12; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881588/; classtype:trojan-activity;sid:84744688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.arc"; depth:9; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881589/; classtype:trojan-activity;sid:84744689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.mips"; depth:10; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881590/; classtype:trojan-activity;sid:84744690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.i486"; depth:10; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881579/; classtype:trojan-activity;sid:84744679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.x86_64"; depth:12; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881580/; classtype:trojan-activity;sid:84744680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sh4"; depth:9; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881581/; classtype:trojan-activity;sid:84744681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv6l"; depth:12; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881582/; classtype:trojan-activity;sid:84744682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.armv4l"; depth:12; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881583/; classtype:trojan-activity;sid:84744683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.powerpc"; depth:13; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881584/; classtype:trojan-activity;sid:84744684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.sparc"; depth:11; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881578/; classtype:trojan-activity;sid:84744678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iran.aarch64"; depth:13; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881577/; classtype:trojan-activity;sid:84744677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rtbqi.js"; depth:9; endswith; nocase; http.host; content:"hdbkell.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881521/; classtype:trojan-activity;sid:84744621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frofg.js"; depth:9; endswith; nocase; http.host; content:"hdbkell.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881522/; classtype:trojan-activity;sid:84744622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/y9nzz.js"; depth:9; endswith; nocase; http.host; content:"hdbkell.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881523/; classtype:trojan-activity;sid:84744623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/minern.tgz"; depth:11; endswith; nocase; http.host; content:"46.151.182.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881308/; classtype:trojan-activity;sid:84744408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/all.sh"; depth:7; endswith; nocase; http.host; content:"46.151.182.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881306/; classtype:trojan-activity;sid:84744406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gh"; depth:3; endswith; nocase; http.host; content:"2.56.10.3"; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881256/; classtype:trojan-activity;sid:84744356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot"; depth:4; endswith; nocase; http.host; content:"46.151.182.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881219/; classtype:trojan-activity;sid:84744319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update.exe"; depth:11; endswith; nocase; http.host; content:"46.151.182.239"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881218/; classtype:trojan-activity;sid:84744318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/setup.exe"; depth:10; endswith; nocase; http.host; content:"192.252.181.68"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881170/; classtype:trojan-activity;sid:84744270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/cnc"; depth:9; endswith; nocase; http.host; content:"38.76.201.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881161/; classtype:trojan-activity;sid:84744261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ven9392.exe"; depth:12; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880816/; classtype:trojan-activity;sid:84743916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qrj3292.exe"; depth:12; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880815/; classtype:trojan-activity;sid:84743915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x93923.exe"; depth:11; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880814/; classtype:trojan-activity;sid:84743914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload/wrm.exe"; depth:15; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880813/; classtype:trojan-activity;sid:84743913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot_x64.exe"; depth:12; endswith; nocase; http.host; content:"196.251.107.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880805/; classtype:trojan-activity;sid:84743905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload/byk4d5tg4nyo.exe"; depth:24; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880807/; classtype:trojan-activity;sid:84743907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload/5fzscnissh1s.exe"; depth:24; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880810/; classtype:trojan-activity;sid:84743910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload/bot_x64.exe"; depth:19; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880761/; classtype:trojan-activity;sid:84743861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload/klr.exe"; depth:15; endswith; nocase; http.host; content:"192.162.199.186"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880771/; classtype:trojan-activity;sid:84743871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ngufre.exe"; depth:11; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880740/; classtype:trojan-activity;sid:84743840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/universalbrowser.exe"; depth:21; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880750/; classtype:trojan-activity;sid:84743850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dcm1-6626/t-1million/raw/refs/heads/main/t2.zip"; depth:48; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880434/; classtype:trojan-activity;sid:84743534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dcm1-6626/t-1million/raw/refs/heads/main/t3.zip"; depth:48; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880433/; classtype:trojan-activity;sid:84743533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dcm1-6626/t-1million/raw/refs/heads/main/t1.zip"; depth:48; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880432/; classtype:trojan-activity;sid:84743532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_3dfa6b71eb1f52a6.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_03; reference:url, urlhaus.abuse.ch/url/3880073/; classtype:trojan-activity;sid:84743173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.37.101.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_03; reference:url, urlhaus.abuse.ch/url/3880062/; classtype:trojan-activity;sid:84743162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"58.37.101.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_03; reference:url, urlhaus.abuse.ch/url/3880052/; classtype:trojan-activity;sid:84743152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b82f2dba4422534f.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_03; reference:url, urlhaus.abuse.ch/url/3880000/; classtype:trojan-activity;sid:84743100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_7abbb1cadc4625ad.ps1"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879852/; classtype:trojan-activity;sid:84742952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file.so"; depth:8; endswith; nocase; http.host; content:"34.45.47.180"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879744/; classtype:trojan-activity;sid:84742844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file-grey.elf"; depth:14; endswith; nocase; http.host; content:"34.45.47.180"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879745/; classtype:trojan-activity;sid:84742845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file-suspicious-elf-header-amd64.elf"; depth:37; endswith; nocase; http.host; content:"34.45.47.180"; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879746/; classtype:trojan-activity;sid:84742846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"81.230.148.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879718/; classtype:trojan-activity;sid:84742818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"60.216.131.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879717/; classtype:trojan-activity;sid:84742817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"60.216.131.62"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879716/; classtype:trojan-activity;sid:84742816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"81.230.148.181"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879691/; classtype:trojan-activity;sid:84742791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.203.158.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879688/; classtype:trojan-activity;sid:84742788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"112.254.223.118"; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879458/; classtype:trojan-activity;sid:84742558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"203.160.9.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879429/; classtype:trojan-activity;sid:84742529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.160.9.182"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879433/; classtype:trojan-activity;sid:84742533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.229.32.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879436/; classtype:trojan-activity;sid:84742536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"124.229.32.123"; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879413/; classtype:trojan-activity;sid:84742513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/latestzoombucket/zoom.msi"; depth:31; endswith; nocase; http.host; content:"f005.backblazeb2.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_07_01; reference:url, urlhaus.abuse.ch/url/3878882/; classtype:trojan-activity;sid:84741982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_ac12f1da1bdab1e0.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_01; reference:url, urlhaus.abuse.ch/url/3878812/; classtype:trojan-activity;sid:84741912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a8b257b458693ac9.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_01; reference:url, urlhaus.abuse.ch/url/3878783/; classtype:trojan-activity;sid:84741883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lkzmnxeqfe/x521"; depth:16; endswith; nocase; http.host; content:"69.169.99.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878376/; classtype:trojan-activity;sid:84741476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wmpbvdf1qa/tcrond"; depth:18; endswith; nocase; http.host; content:"69.169.99.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878366/; classtype:trojan-activity;sid:84741466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/why7rovj4r/x640"; depth:16; endswith; nocase; http.host; content:"69.169.99.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878361/; classtype:trojan-activity;sid:84741461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wtoga9ctxs/x522"; depth:16; endswith; nocase; http.host; content:"69.169.99.158"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878362/; classtype:trojan-activity;sid:84741462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shell/rev.sh"; depth:13; endswith; nocase; http.host; content:"scanbot.me"; depth:10; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878283/; classtype:trojan-activity;sid:84741383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d.sh"; depth:5; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_29; reference:url, urlhaus.abuse.ch/url/3878142/; classtype:trojan-activity;sid:84741242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/check.sh"; depth:9; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_29; reference:url, urlhaus.abuse.ch/url/3878143/; classtype:trojan-activity;sid:84741243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_29; reference:url, urlhaus.abuse.ch/url/3878139/; classtype:trojan-activity;sid:84741239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8.exe"; depth:6; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_29; reference:url, urlhaus.abuse.ch/url/3878140/; classtype:trojan-activity;sid:84741240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"178.16.54.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_29; reference:url, urlhaus.abuse.ch/url/3878136/; classtype:trojan-activity;sid:84741236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"178.16.54.90"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_29; reference:url, urlhaus.abuse.ch/url/3878137/; classtype:trojan-activity;sid:84741237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3876953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jenniferloeffler.zip"; depth:21; endswith; nocase; http.host; content:"jenniferloeffler.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_06_27; reference:url, urlhaus.abuse.ch/url/3876953/; classtype:trojan-activity;sid:84740053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3876827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atom.xml"; depth:9; endswith; nocase; http.host; content:"hoteljune2026.blogspot.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_06_27; reference:url, urlhaus.abuse.ch/url/3876827/; classtype:trojan-activity;sid:84739927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3876167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"103.164.128.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_26; reference:url, urlhaus.abuse.ch/url/3876167/; classtype:trojan-activity;sid:84739267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3876055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.164.128.184"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_25; reference:url, urlhaus.abuse.ch/url/3876055/; classtype:trojan-activity;sid:84739155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3875829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"123.132.166.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_25; reference:url, urlhaus.abuse.ch/url/3875829/; classtype:trojan-activity;sid:84738929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3875795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"123.132.166.255"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_25; reference:url, urlhaus.abuse.ch/url/3875795/; classtype:trojan-activity;sid:84738895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3875186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dutyfree-embroiderystitch433/arcraiderfpsboosterforgithub2026/raw/refs/heads/main/aly/hub_booster_raider_for_git_arc_fps_2.6-alpha.1.zip"; depth:137; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_06_24; reference:url, urlhaus.abuse.ch/url/3875186/; classtype:trojan-activity;sid:84738286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3875024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"155.138.220.70"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_23; reference:url, urlhaus.abuse.ch/url/3875024/; classtype:trojan-activity;sid:84738124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pondescalator/nlp-quickbook-classification/releases/download/release/nlp_quickbook.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_06_23; reference:url, urlhaus.abuse.ch/url/3874894/; classtype:trojan-activity;sid:84737994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chainbarberbear/roblox-client-tracker-versions/releases/download/release/roblox-client-tracker.zip"; depth:99; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_06_23; reference:url, urlhaus.abuse.ch/url/3874892/; classtype:trojan-activity;sid:84737992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pred.inf"; depth:9; endswith; nocase; http.host; content:"grantexx.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874512/; classtype:trojan-activity;sid:84737612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tilsee.cur"; depth:11; endswith; nocase; http.host; content:"grantexx.com"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874505/; classtype:trojan-activity;sid:84737605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skrivem.ocx"; depth:12; endswith; nocase; http.host; content:"pub-364c6b3011ca492cab2354176cfaf3f0.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874488/; classtype:trojan-activity;sid:84737588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/schi.png"; depth:9; endswith; nocase; http.host; content:"pub-1900be17f2994b5580d602f23eb7fb93.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874452/; classtype:trojan-activity;sid:84737552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saucvvg.png"; depth:12; endswith; nocase; http.host; content:"pub-8d59738861b849e5a38b795cc17b1019.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874451/; classtype:trojan-activity;sid:84737551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.well-known/acme-challenge/images/thisweekisnlessedwithriches.png"; depth:66; endswith; nocase; http.host; content:"www.controliumbt.com"; depth:20; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874427/; classtype:trojan-activity;sid:84737527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.well-known/acme-challenge/images/thenewweekisblessed.png"; depth:58; endswith; nocase; http.host; content:"kits.frog.tw"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874426/; classtype:trojan-activity;sid:84737526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/romanticisationphallales546/openrgb-scripts/main/staphylinid/scripts-openrgb-2.2-alpha.2.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874372/; classtype:trojan-activity;sid:84737472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unavowed-easternchurch142/telegram-to-obsidian/main/config/workspace/skills/obsidian/obsidian_to_telegram_1.3.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874363/; classtype:trojan-activity;sid:84737463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/waweruv170/by-binds-yourself/main/completions/by-binds-yourself_1.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874364/; classtype:trojan-activity;sid:84737464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tradmousebutton692/flussonic-exporter/main/deploy/prometheus/flussonic_exporter_1.8.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874365/; classtype:trojan-activity;sid:84737465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hacker193/cmtat-icma-tokenized-bonds/main/contracts/cmtat_tokenized_icma_bonds_3.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874366/; classtype:trojan-activity;sid:84737466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alpercepni/gommit/main/internal/install/software-2.1.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874367/; classtype:trojan-activity;sid:84737467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/holocentrusascensionisbadegg868/pantheon/main/patterns/carve-at-joints/adapters/software_1.3.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874368/; classtype:trojan-activity;sid:84737468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rotund-episcopate534/hotkeys/main/flowerpecker/software_2.8.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874369/; classtype:trojan-activity;sid:84737469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krissiesmudgy575/aip-foundry-themis-starter/main/scripts/aip-themis-foundry-starter-1.6.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874370/; classtype:trojan-activity;sid:84737470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luiselius/streamd/main/diglottist/software_v1.5.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874348/; classtype:trojan-activity;sid:84737448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaydenplayz/agent-skills-guide/main/aportoise/guide-skills-agent-1.7.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874349/; classtype:trojan-activity;sid:84737449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/indrasurya12/theme_changing_template/main/components/card/theme_changing_template_2.6.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874350/; classtype:trojan-activity;sid:84737450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sah-arch/legalysis/main/legalysis/software-3.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874351/; classtype:trojan-activity;sid:84737451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/timesukkumnerd/resonant-archive/main/skills/archive_resonant_3.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874352/; classtype:trojan-activity;sid:84737452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/65y6650/hermes-lcm/main/scripts/hermes_lcm_v1.2.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874353/; classtype:trojan-activity;sid:84737453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ammarahmed12/ai-resume-analyzer/main/puparium/ai_analyzer_resume_1.9.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874354/; classtype:trojan-activity;sid:84737454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rainbowlight-pixel/claude-cowork-content-plugin/main/content-repurposing/skills/twitter-thread/content-plugin-claude-cowork-v1.1-beta.1.zip"; depth:140; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874355/; classtype:trojan-activity;sid:84737455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isletkreisler490/rawq/main/upwell/software-3.7-beta.2.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874356/; classtype:trojan-activity;sid:84737456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fauniethermal3522/agentic-dart/main/examples/sample-evidence/web/var/www/html/agentic_dart_v3.4.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874357/; classtype:trojan-activity;sid:84737457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elpit0grande/awesome-free-movies/main/ramfeezled/movies-awesome-free-v2.9.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874358/; classtype:trojan-activity;sid:84737458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filiberto97/iptv-streamwatcher/main/src/iptv_monitor/watcher-ipt-stream-2.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874359/; classtype:trojan-activity;sid:84737459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/resolvable-glia938/annexa/main/iceland/software_2.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874360/; classtype:trojan-activity;sid:84737460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gittysb10/movie_recommend/main/data/recommend_movie_v3.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874361/; classtype:trojan-activity;sid:84737461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashu1436/amazon-scraper/main/ogum/scraper-amazon-1.8.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874362/; classtype:trojan-activity;sid:84737462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naltalib/isumsoft-cloner-repack/main/preinsert/i_cloner_sumsoft_repack_v2.7.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874343/; classtype:trojan-activity;sid:84737443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wwwsegunogundeji11-stack/gpt-voyager/main/src/content/gp-voyager-v1.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874344/; classtype:trojan-activity;sid:84737444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pachydermatous-teuton9386/api-manager/main/rules/api_manager_v2.2-beta.1.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874345/; classtype:trojan-activity;sid:84737445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/twylatrumpetlike730/pi-psst/main/extensions/psst_pi_v1.8.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874346/; classtype:trojan-activity;sid:84737446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lannascreaming580/flowscroll/main/flowscroll/locales/scroll-flow-v1.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874347/; classtype:trojan-activity;sid:84737447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daynastraight594/portfolio-template/main/screenshots/portfolio_template_1.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874342/; classtype:trojan-activity;sid:84737442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/senjusenpai18/javascript-interview/main/undesirousness/javascript_interview_v3.6.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874341/; classtype:trojan-activity;sid:84737441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/misterioul/jobs/main/src/api/services/software-v3.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874340/; classtype:trojan-activity;sid:84737440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rust8709/tourino/main/src/software_1.8-beta.4.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874338/; classtype:trojan-activity;sid:84737438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/socrates19/cloudflare-hono-starter/main/node_modules/reveal.js/test/starter_cloudflare_hono_1.3.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874339/; classtype:trojan-activity;sid:84737439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/afefnayeem/menustow/main/menustow/menubar/search/software_v3.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874336/; classtype:trojan-activity;sid:84737436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zohaib-0/computer-vision-deep-learning-stack/main/implead/deep-computer-vision-learning-stack-2.7.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874337/; classtype:trojan-activity;sid:84737437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/osbertbilled424/macros-log/main/celibacy/log-macros-v2.7.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874329/; classtype:trojan-activity;sid:84737429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connieverbal484/anthropic_hackathon/main/spongoid/hackathon_anthropic_v2.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874330/; classtype:trojan-activity;sid:84737430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svmiizzz/conventional-commit-batcher/main/agents/batcher-commit-conventional-v1.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874331/; classtype:trojan-activity;sid:84737431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maumanto/jenkins-mcp-server/main/laborant/mcp-server-jenkins-3.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874334/; classtype:trojan-activity;sid:84737434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rampant-zionism337/phoenix-framework/main/src/core/phoenix-framework-v3.7-alpha.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874328/; classtype:trojan-activity;sid:84737428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/purpletrainwreck/complete-guide-for-secure-boot-on-arch-linux-with-refind/main/summons/arch_ind_with_secure_guide_ef_linux_boot_r_complete_for_on_v3.8-alpha.1.zip"; depth:163; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874327/; classtype:trojan-activity;sid:84737427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucas-camilo-dados/linkme/main/themes/software_1.5.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874323/; classtype:trojan-activity;sid:84737423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bigcola2020/openclaw-jarvis-memory/main/skills/mem-redis/openclaw_memory_jarvis_2.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874324/; classtype:trojan-activity;sid:84737424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ordered-tincture209/open-zeu/main/ui/open_zeu_3.6.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874325/; classtype:trojan-activity;sid:84737425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shadowy-screed33/mindful-trail/main/laang/trail-mindful-1.1-alpha.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874326/; classtype:trojan-activity;sid:84737426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdhsdfgjh/nestify-project/main/public/css/nestify_project_1.0.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874319/; classtype:trojan-activity;sid:84737419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/catengue/stillepost/main/python_code/software-v3.0.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874320/; classtype:trojan-activity;sid:84737420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neocortical-one877/ts-quality/main/packages/legitimacy/ts-quality-v3.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874321/; classtype:trojan-activity;sid:84737421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justdvp/claude-code-templates/main/cli-tool/src/analytics/utils/templates_code_claude_1.8.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874322/; classtype:trojan-activity;sid:84737422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secretresell/ai-finance-trading-agent/main/oppugnant/agent_trading_finance_ai_v2.8.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874315/; classtype:trojan-activity;sid:84737415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayvapourisable154/stratum/main/klipfish/software_v2.4-alpha.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874316/; classtype:trojan-activity;sid:84737416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rudge0/dynamo-rl/main/examples/sft/multiturn/dyna-m-rl-v1.2-alpha.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874317/; classtype:trojan-activity;sid:84737417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oscine-mustercall181/advanced-excel-retail-sales-analysis/main/cutworm/advanced-sales-analysis-retail-excel-v3.6.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874318/; classtype:trojan-activity;sid:84737418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kermithermit/agentic-commerce-protocol/main/changelog/agentic_commerce_protocol_v3.6-beta.5.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874310/; classtype:trojan-activity;sid:84737410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ikramahmadmemon13/grant-thinking-skill/main/agents/skill_thinking_grant_v3.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874311/; classtype:trojan-activity;sid:84737411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lakshmi2655/myclaw/main/assets/my_claw_1.6.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874312/; classtype:trojan-activity;sid:84737412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/annonymouskali10/redbookskills/main/nucleohyaloplasma/red_book_skills_2.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874313/; classtype:trojan-activity;sid:84737413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aloneboyktk1/medical-resource-simulator/main/.devcontainer/medical-resource-simulator-v1.7.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874308/; classtype:trojan-activity;sid:84737408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scorjr1/envirowatch/main/components/ui/watch-enviro-v3.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874309/; classtype:trojan-activity;sid:84737409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/benxt512/bsutils/main/stream/utils-bs-2.5.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874307/; classtype:trojan-activity;sid:84737407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dessert9431/awesome-ai-friendly-cli/main/presuperficially/friendly-awesome-ai-cli-v2.9.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874302/; classtype:trojan-activity;sid:84737402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbk-man/claude-code-owasp/main/.claude/skills/owasp_code_claude_v1.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874303/; classtype:trojan-activity;sid:84737403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alzoube103/openkit/main/examples/styles/software_v3.2.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874304/; classtype:trojan-activity;sid:84737404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uncorrected-nova574/playtranslate/main/app/src/main/res/software-v3.1-alpha.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874305/; classtype:trojan-activity;sid:84737405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/duahmcclean/erp-selenium-qa/main/docs/qa_selenium_erp_1.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874306/; classtype:trojan-activity;sid:84737406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/helanzhiyi/audio-annotation-platform/main/examples/audio_platform_annotation_v2.4-beta.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874297/; classtype:trojan-activity;sid:84737397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arigotek/auto_cythonizer_tests/main/cython_cache/build_lib/fibonacci/auto_cythonizer_tests_2.7-alpha.3.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874298/; classtype:trojan-activity;sid:84737398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notboiii/walletgpt-ai-copilot-for-wallets/main/repineful/for-wallet-wallets-gp-copilot-a-v3.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874299/; classtype:trojan-activity;sid:84737399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jjvm2000/terminal-mcp/main/src/terminal/terminal_mcp_2.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874300/; classtype:trojan-activity;sid:84737400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chance6969-hue/__2025_07_08_tvdi_crawler__/main/lesson7/tvdi-crawler-v3.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874301/; classtype:trojan-activity;sid:84737401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anathi-c/backup-linux/main/troutflower/linux-backup-3.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874295/; classtype:trojan-activity;sid:84737395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/footbathfungusgnat32/ghostty-cursor-shaders/main/isodurene/ghostty-cursor-shaders-1.3-beta.1.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874296/; classtype:trojan-activity;sid:84737396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toonjn123456789/constants-float16-eulergamma/main/docs/types/constants-eulergamma-float-v3.8.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874292/; classtype:trojan-activity;sid:84737392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tophole-alphabetizer167/fino/main/client/src/test/software-v2.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874293/; classtype:trojan-activity;sid:84737393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prentisskiplingesque84/focustask/main/public/task_focus_1.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874294/; classtype:trojan-activity;sid:84737394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/denis-arc/is4310-232m4_user_manual/main/rovet/manual_i_user_v1.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874290/; classtype:trojan-activity;sid:84737390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filearsip/wapp/main/helices/software_v3.5-beta.2.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874291/; classtype:trojan-activity;sid:84737391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qboosttt/awesome-openclaw/main/docs/blog/openclaw-awesome-3.5-alpha.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874288/; classtype:trojan-activity;sid:84737388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ramaritacreations/sql-injection-attack-detection/main/dataset/sql_attack_detection_injection_v1.8.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874289/; classtype:trojan-activity;sid:84737389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amansuthar0/microapi-hub/main/clients/web/lib/hub_microapi_2.2-beta.1.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874285/; classtype:trojan-activity;sid:84737385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ra7701/aulite/main/dashboard/src/lib/software_1.6.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874286/; classtype:trojan-activity;sid:84737386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/conceited-watergillyflower311/meilisearch-desktop/main/src/pages/project/meilisearch-desktop-2.6.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874287/; classtype:trojan-activity;sid:84737387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/montycongolese277/awesome-ai-pulse-georgia/main/assets/awesome_ai_pulse_georgia_2.1-beta.3.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874284/; classtype:trojan-activity;sid:84737384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/koxov/comfyui-ayang_node/main/undescribably/node-comfyui-ayang-v1.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874279/; classtype:trojan-activity;sid:84737379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ozii-z/zx-ddos/main/file/do_z_d_s_v2.4.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874280/; classtype:trojan-activity;sid:84737380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucasoil1234799/online-course-pricing-eda-analysis/main/poly/analysis-online-pricing-course-eda-v3.2.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874282/; classtype:trojan-activity;sid:84737382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jesnn123/vibe/main/examples/software-v2.7.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874283/; classtype:trojan-activity;sid:84737383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marinhodomingosm/post-stroke-aphasia-risk-analysis/main/github-pages/src/.observablehq/cache/_npm/aphasia-stroke-analysis-post-risk-1.4-beta.3.zip"; depth:147; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874277/; classtype:trojan-activity;sid:84737377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akroutabdelrrezak/dht11/main/guiser/dh_v3.8.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874278/; classtype:trojan-activity;sid:84737378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phongvthanh/discord-bot/main/startlingly/bot_discord_v2.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874273/; classtype:trojan-activity;sid:84737373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fastks/wedding-photography-web/main/griffade/web_wedding_photography_v2.0.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874274/; classtype:trojan-activity;sid:84737374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emperormode/starus-data-restore-pack-latest-patch/main/berrugate/latest-patch-restore-starus-pack-data-v2.2.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874275/; classtype:trojan-activity;sid:84737375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eror5/visionos-ui-framework/main/documentation/u_o_framework_vision_v2.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874276/; classtype:trojan-activity;sid:84737376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/immunogenic-prismspectroscope589/blender_mcp/main/scripts/quality/mcp-blender-v1.7.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874265/; classtype:trojan-activity;sid:84737365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unfavorable-sutra74/apl-evs/main/headchair/apl-evs_1.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874266/; classtype:trojan-activity;sid:84737366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cane4ka777/qwer/main/.devcontainer/software-v1.3.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874267/; classtype:trojan-activity;sid:84737367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeynepornek/.github/main/profile/github_v1.8-beta.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874268/; classtype:trojan-activity;sid:84737368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adidashyperspace-lab/geosilo/main/scripts/software_v2.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874269/; classtype:trojan-activity;sid:84737369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/logiiiii/unity-agent-skills/main/skills/jahro-logging/skills-agent-unity-v3.9-alpha.2.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874272/; classtype:trojan-activity;sid:84737372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paul-selvi/impellersharp/main/build/scripts/impeller_sharp_1.5-alpha.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874262/; classtype:trojan-activity;sid:84737362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ieroglifgd/notabeen-ai-email-assistant/main/src/app/privacy-policy/ai_notabeen_assistant_email_3.0.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874263/; classtype:trojan-activity;sid:84737363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/klkape6358/mouse-p.i.-for-hire-release-game-desktop-version/main/code/desktop-release-version-game-mous-for-hire-3.3-beta.1.zip"; depth:128; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874264/; classtype:trojan-activity;sid:84737364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mr-mrs-xx1/claude-watch/main/dashboard/claude-watch-1.5.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874261/; classtype:trojan-activity;sid:84737361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bvuz/django-multi-tenant-saas-starter-template/main/apps/authentication/tests/template-multi-saa-starter-django-tenant-1.9.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874260/; classtype:trojan-activity;sid:84737360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thainereflecting360/otexum-pulse/main/properties/publishprofiles/otexum_pulse_v1.8-alpha.3.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874255/; classtype:trojan-activity;sid:84737355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhuiyan17/ai-novel-editor/main/src/gui/viewer/novel-ai-editor-v1.8-beta.3.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874256/; classtype:trojan-activity;sid:84737356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/caudalappendagemarmite540/tarantool-bzw/main/jun/tarantool-bzw_v1.0.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874257/; classtype:trojan-activity;sid:84737357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/significancemoloch680/driftcheck/main/internal/driftcheck/software-v3.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874258/; classtype:trojan-activity;sid:84737358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isabre5796/mlb-the-show-26-pc/main/portable-port/ml-show-pc-the-3.4-beta.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874254/; classtype:trojan-activity;sid:84737354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/panoptic-septuagenarian481/oscp-notes/main/autodiffusion/notes_osc_2.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874251/; classtype:trojan-activity;sid:84737351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cldestiny/key-maestro/main/growingupness/key-maestro-2.3-alpha.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874252/; classtype:trojan-activity;sid:84737352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/discernible-racoon7161/sql-shield/main/examples/sql_shield_v2.0-beta.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874253/; classtype:trojan-activity;sid:84737353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/persona-net/rag-pipeline-dashboard/main/frontend/tests/dashboard-rag-pipeline-3.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874247/; classtype:trojan-activity;sid:84737347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sayto97j/detectron2/main/detectron2/layers/csrc/roialignrotated/detectron_v3.7.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874250/; classtype:trojan-activity;sid:84737350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/idkidk02020202/claude-opus-4.6-prompt-optimizer/main/mnt/user-data/optimizer-prompt-opus-claude-1.6.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874243/; classtype:trojan-activity;sid:84737343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hirak123github/rebecca-minkoff-scraper/main/exhalant/scraper-rebecca-minkoff-v2.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874244/; classtype:trojan-activity;sid:84737344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/el4rjoun/python-noadmin/main/scripts/admin-python-no-1.8-alpha.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874245/; classtype:trojan-activity;sid:84737345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rommai123/rodel.player.public/main/assets/public-rodel-player-v3.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874246/; classtype:trojan-activity;sid:84737346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhanush-td/loginorreg/main/src/or-login-reg-2.7.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874238/; classtype:trojan-activity;sid:84737338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rightsideup-rubiales387/airca-fractal-decision-architecture/main/docs/fractal-decision-making/fractal-decision-airca-architecture-v3.7-beta.5.zip"; depth:146; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874240/; classtype:trojan-activity;sid:84737340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ritik250505/tokenfirewall/main/src/core/software-v2.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874241/; classtype:trojan-activity;sid:84737341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joicesmart40/yii2-vscode-bridge/main/src/vscode_bridge_yii_3.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874242/; classtype:trojan-activity;sid:84737342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xpiderservice/mvggt/main/mvggt/models/__pycache__/software-v3.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874234/; classtype:trojan-activity;sid:84737334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zenialeaky136/live-to-100-skills/main/live-to-100/agents/live_to_skills_v1.8.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874235/; classtype:trojan-activity;sid:84737335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/allans4635/memctx/main/lib/api-spec/software-1.7.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874236/; classtype:trojan-activity;sid:84737336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fresh-mexicanrevolution306/clearly/main/website/software_v2.8.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874231/; classtype:trojan-activity;sid:84737331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/duffelcoatterpsichore141/iam-lite/main/tests/iam-lite-v2.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874232/; classtype:trojan-activity;sid:84737332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evansamarh/stm32-led-button-ctrl-register-coding-method/main/drivers/cmsis/device/st/stm32f4xx/st_butto_ctr_method_le_register_coding_1.8.zip"; depth:142; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874233/; classtype:trojan-activity;sid:84737333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naungphyo/ecoai-environmental-intelligence-agent/main/screenshots/a-eco-environmental-intelligence-agent-3.5.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874228/; classtype:trojan-activity;sid:84737328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeckef/unnamed_game_1_v2/main/epidictical/game-unnamed-v-1.3-beta.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874229/; classtype:trojan-activity;sid:84737329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/entity107/rlmgw/main/docs/src/components/software-2.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874230/; classtype:trojan-activity;sid:84737330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pearltelluric497/adobe-lightroom-professional/main/eunomy/adobe-lightroom-professional-v2.1.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874226/; classtype:trojan-activity;sid:84737326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darryltoroidal630/ninjaripper-210-freeversion/main/paradoxicalness/ninja_free_version_ripper_1.1.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874227/; classtype:trojan-activity;sid:84737327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dezmuz93/atom-ui/main/src/components/ato-ui-2.3.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874224/; classtype:trojan-activity;sid:84737324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lookdawn1337/agentic-github-code-reviewer/main/agents/hub-code-git-agentic-reviewer-3.0.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874223/; classtype:trojan-activity;sid:84737323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/incensecedarthreepointswitch884/moda/main/libs/moda_triton/fla/models/mamba/da-mo-v1.4.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874220/; classtype:trojan-activity;sid:84737320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0klartkarlsson/ode-comfyui-wanvideowrapper/main/wanvideo/schedulers/wrapper_video_ode_u_wan_comfy_1.5.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874221/; classtype:trojan-activity;sid:84737321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r1ghtoo/firefox-fingerprint-analyzer/main/bilsh/analyzer-print-firefox-finger-3.1.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874222/; classtype:trojan-activity;sid:84737322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/theeterminetor21811/notploy-website/main/skidder/website_notploy_v1.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874216/; classtype:trojan-activity;sid:84737316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akshay1010567/tp_final_pulseras_inteligentes/main/pulseras_inteligentes/datawarehouse/tp_pulseras_inteligentes_final_1.1-beta.2.zip"; depth:132; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874217/; classtype:trojan-activity;sid:84737317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amazo5385/lfn/main/docs/software_v3.3.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874218/; classtype:trojan-activity;sid:84737318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rpsandygaming/awesome-terminal-for-ai/main/docs/assets/ai_terminal_for_awesome_1.8.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874219/; classtype:trojan-activity;sid:84737319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nobita5609/mcp.zig/main/docs/guide/mcp-zig-v2.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874213/; classtype:trojan-activity;sid:84737313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teresinatrackless687/gamineai/main/homeland/ai_gamine_v2.9.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874214/; classtype:trojan-activity;sid:84737314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gainesvillefamilyenterobacteriaceae551/dmarc-parser/main/src/components/ui/dmarc_parser_2.9-beta.4.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874215/; classtype:trojan-activity;sid:84737315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/janemcfadden1090/110-sequence-detector/main/gansey/sequence_detector_v3.6-alpha.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874211/; classtype:trojan-activity;sid:84737311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hermiogg-arch/product_picker/main/blog/.vitepress/theme/product_picker_v3.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874212/; classtype:trojan-activity;sid:84737312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/greenap7654/trendingcontent-agent/main/examples/trendingcontent-agent-3.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874209/; classtype:trojan-activity;sid:84737309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/basketmakerfaitaccompli622/awesome-claude-code-security/main/diovular/claude-security-code-awesome-v1.4.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874205/; classtype:trojan-activity;sid:84737305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kopoku-69/dashboard-1771921898-3/main/pkg/dashboard-2.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874206/; classtype:trojan-activity;sid:84737306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/willz1/ai-config-search-guide/main/blithebread/guide-ai-search-config-v1.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874207/; classtype:trojan-activity;sid:84737307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hassan1829/sigil-dfir/main/backend/tools/dfir-sigil-1.9-beta.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874208/; classtype:trojan-activity;sid:84737308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ironputtycreditworthiness366/asoplay/main/sql/software_3.6.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874203/; classtype:trojan-activity;sid:84737303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kotty2998/claude-plugins-official/main/external_plugins/laravel-boost/.claude-plugin/claude-official-plugins-1.1.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874204/; classtype:trojan-activity;sid:84737304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bko2023/bliss_browser_pep8/main/regionary/pep-browser-bliss-3.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874195/; classtype:trojan-activity;sid:84737295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/themountainboy19/dojops/main/packages/skill-registry/src/software_v2.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874196/; classtype:trojan-activity;sid:84737296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/commutable-poilu834/parlor/main/artifacts/software_v1.5.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874198/; classtype:trojan-activity;sid:84737298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ukiyooooo/multimodal-rag-engine/main/myeloencephalitis/engine-multimodal-rag-v2.0.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874199/; classtype:trojan-activity;sid:84737299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nguyenphammc/whisperer/main/bin/software-v2.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874200/; classtype:trojan-activity;sid:84737300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/torresantm12/poof/main/sources/poof/resources/software_3.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874201/; classtype:trojan-activity;sid:84737301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/burhansaleem1961/axie-infinity/main/amnionic/axie_infinity_v1.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874202/; classtype:trojan-activity;sid:84737302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manishrathore12/astro-preact-typescript-tailwind-boilerplate/main/src/pages/tailwind-typescript-boilerplate-preact-astro-v2.2.zip"; depth:130; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874193/; classtype:trojan-activity;sid:84737293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ziiyoung/macro-recorder/main/src/macro_recorder/observers/recorder-macro-v1.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874194/; classtype:trojan-activity;sid:84737294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itsvis9313/logifadefix/main/coadjutress/fade-logi-fix-v3.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874191/; classtype:trojan-activity;sid:84737291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rifkialmahdi/archivist-project-denoiser/main/archived_2024/archivist_denoiser_project_v2.7.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874192/; classtype:trojan-activity;sid:84737292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/equalizerklystron781/research-mode/main/commands/research-mode-v3.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874189/; classtype:trojan-activity;sid:84737289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iqrama2006/black-usdt/main/cycloscope/black_usdt_v2.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874190/; classtype:trojan-activity;sid:84737290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nevatry6660/telbot/main/telkomsel/software_1.0-alpha.5.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874188/; classtype:trojan-activity;sid:84737288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kmen4/lvgl9-sdl2-windows-simulator/main/screenshots/lvgl-windows-sdl-simulator-v3.3-beta.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874187/; classtype:trojan-activity;sid:84737287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdelazizfouad/internshala-ds-projects/main/internshala-pgc-tableau/internshala_ds_projects_1.6-beta.3.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874183/; classtype:trojan-activity;sid:84737283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/christatantalising631/nimble/main/stdlib/software_2.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874184/; classtype:trojan-activity;sid:84737284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skippermain626/rust-cheat-2026-best-aim-esp-no-recoil-misc-visuals-for-pc/main/zymolyis/best_pc_misc_cheat_no_esp_recoil_aim_visuals_rust_for_3.1.zip"; depth:150; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874185/; classtype:trojan-activity;sid:84737285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chizzy04062003/aws-lex-cloud-chatbot/main/images/aw_chatbot_lex_cloud_v3.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874186/; classtype:trojan-activity;sid:84737286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/edmundm9/stemlab/main/src/core/lab-stem-1.9.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874182/; classtype:trojan-activity;sid:84737282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucaducapuca/alibabacloud-bigdata-skills/main/skills/dataworks/alibabacloud-skills-bigdata-v1.7.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874181/; classtype:trojan-activity;sid:84737281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salmajibeh/brutal/main/assets/software_1.6.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874178/; classtype:trojan-activity;sid:84737278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hih24337/tabb2/main/routes/tabb_1.5.zip"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874179/; classtype:trojan-activity;sid:84737279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bradro/ict-infrastructure-monitoring-splunk/main/crabbed/splunk_ic_infrastructure_monitoring_3.5.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874180/; classtype:trojan-activity;sid:84737280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ricarddefensive803/caveman-skill/main/windsurf/caveman-skill-2.2-beta.3.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874176/; classtype:trojan-activity;sid:84737276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nshutidev/clojure-vsr/main/uncluttered/clojure-vsr-3.1-alpha.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874174/; classtype:trojan-activity;sid:84737274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krkrrom5/opendoor/main/opendoor/io_layer/software-3.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874175/; classtype:trojan-activity;sid:84737275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/valedictory-tundra426/iot-prd-generator/main/assets/templates/prd-iot-generator-v2.9-beta.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874171/; classtype:trojan-activity;sid:84737271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajfrrr/cryptoschema-extractor/main/cryptoschema_extractor/cryptoschema_extractor_3.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874172/; classtype:trojan-activity;sid:84737272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rokia258/luminara-cookie-jar/main/test-cli/tests/luminara-cookie-jar_v2.9.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874173/; classtype:trojan-activity;sid:84737273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nmerr2212/iv4rbone-source/main/reboundable/iv4rbone-source-3.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874167/; classtype:trojan-activity;sid:84737267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naserhajipour/dupefinder/main/lib/dupe-finder-3.5-beta.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874168/; classtype:trojan-activity;sid:84737268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matrixneoexpressionism381/inframon/main/equiprobabilism/infra_mon_3.9-beta.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874169/; classtype:trojan-activity;sid:84737269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/magneticlineofforceplaymaker9843/shi-yigong-skill/main/references/research/yigong-skill-shi-2.6.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874170/; classtype:trojan-activity;sid:84737270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auntara-toma/envcrypt/main/libs/rust/src/software-v1.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874155/; classtype:trojan-activity;sid:84737255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/corryrevokable963/claude-code-book/main/throatily/claude_book_code_v3.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874156/; classtype:trojan-activity;sid:84737256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rhizopuselbow112/servo-control-esp8266-blynk-oled-temp-humidity/main/outstroke/blynk-ole-es-control-temp-servo-humidity-v1.4.zip"; depth:129; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874157/; classtype:trojan-activity;sid:84737257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daviepredatory192/battlefield-2-project-reality-setup/main/spiranthy/project_setup_reality_battlefield_2.4.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874158/; classtype:trojan-activity;sid:84737258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamsage001/awesome-video-forcing/main/sphingal/forcing-awesome-video-v3.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874160/; classtype:trojan-activity;sid:84737260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/partitive-comma396/nayuyyyu/main/proxy/codex2api/software-2.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874161/; classtype:trojan-activity;sid:84737261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shraz237/quorum/main/services/dashboard/frontend/src/components/software-1.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874162/; classtype:trojan-activity;sid:84737262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suppressorplaybill4170/remocn/main/registry/remocn/marker-highlight/software_v2.0-beta.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874163/; classtype:trojan-activity;sid:84737263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeeldabhi24/auhikari-802.1x/main/files/x-uhikari-a-2.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874164/; classtype:trojan-activity;sid:84737264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anshu987/davinci-magihuman/main/atlantite/da_human_magi_vinci_3.0.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874165/; classtype:trojan-activity;sid:84737265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/histologic-tenderfoot400/pdf2md/main/halite/pdf-md-v2.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874166/; classtype:trojan-activity;sid:84737266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nguyengiabinh23-prog/tadpole/main/packages/ts-config/software_3.5.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874152/; classtype:trojan-activity;sid:84737252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ksaf43a/plarix-scan/main/internal/ledger/plarix-scan-v3.7-beta.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874153/; classtype:trojan-activity;sid:84737253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riohari07/ai-assisted-insights-agent/main/02_examples/python-client/agent_assisted_ai_insights_v2.7.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874154/; classtype:trojan-activity;sid:84737254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannaggiacristo556/nvim/main/lua/neo-tree/sources/distant/software-3.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874151/; classtype:trojan-activity;sid:84737251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matiasv6193/pwnagotchi_app/main/uncohesive/pwnagotchi-app-3.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874148/; classtype:trojan-activity;sid:84737248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prdo0985/07-fpga-itch-parser-v5/main/constraints/itch_v_parser_fpga_v1.7.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874149/; classtype:trojan-activity;sid:84737249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alejandro920/zhouyi/main/kittysol/software_v2.1.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874150/; classtype:trojan-activity;sid:84737250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salah15cl/ai-gaming-strategy-coach-chatbot/main/hebraic/gaming_chatbot_ai_strategy_coach_v1.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874145/; classtype:trojan-activity;sid:84737245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oebeledrijfhout/attorney-directory-scraper/main/naifly/scraper_attorney_directory_3.9.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874146/; classtype:trojan-activity;sid:84737246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nicollas76143/powersub-demo-4146/main/wamara/demo-powersub-3.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874147/; classtype:trojan-activity;sid:84737247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/valublearctic/docker2vm/main/src/bin/docker_vm_2.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874144/; classtype:trojan-activity;sid:84737244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pete731/sati/main/examples/basic-agent-registration/software_2.9.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874143/; classtype:trojan-activity;sid:84737243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wijewardhanagayashi/awesome-dotnet/main/impersonize/awesome-dotnet-v2.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874141/; classtype:trojan-activity;sid:84737241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayyyyyuuu/veniai-hukuk-emsalkarar-mcpserver/main/src/database/server_veni_hukuk_emsal_karar_mcp_a_1.2.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874142/; classtype:trojan-activity;sid:84737242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohdmahsoof/ii-researcher/main/ii_researcher/ii_researcher_2.6-beta.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874140/; classtype:trojan-activity;sid:84737240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guilhermepelido/hermes-optimization-guide/main/screenshots/optimization-hermes-guide-v2.0.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874138/; classtype:trojan-activity;sid:84737238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kmilink/opennmt-indonesia-bima/main/docs/_layouts/nm_bima_open_indonesia_3.2.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874139/; classtype:trojan-activity;sid:84737239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pale-mayenne964/devdocs-forge-agent/main/src/transcript/devdocs_agent_forge_3.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874137/; classtype:trojan-activity;sid:84737237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nogame154/legacylauncher/main/unrich/legacy-launcher-v3.1-beta.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874135/; classtype:trojan-activity;sid:84737235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/antaraaaaaaa/software_maps_tcc/main/docs/docs/software_maps_tcc_2.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874136/; classtype:trojan-activity;sid:84737236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thementh/ai-zhuqi-battle/main/app/api/llm/zhuqi-battle-ai-v3.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874126/; classtype:trojan-activity;sid:84737226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evanneimmoral547/atlasrv-32-bit-risc-v-pipelined-processor/main/docs/ris-pipelined-atlas-r-bit-processor-3.3.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874127/; classtype:trojan-activity;sid:84737227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clabsresults-mohp-gov-eg/sri-balaji-plastics/main/assets/balaji_sri_plastics_v1.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874128/; classtype:trojan-activity;sid:84737228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fafarras22/aura/main/src/components/layout/sidebar/software_v1.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874129/; classtype:trojan-activity;sid:84737229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/softineerdanish/faahhh-notifier-plugin-intellij/main/docs/faahhh-plugin-notifier-intellij-2.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874130/; classtype:trojan-activity;sid:84737230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrakhajv70/st7796s-particle/main/src/s-particle-1.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874131/; classtype:trojan-activity;sid:84737231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wander210/planning-with-teams/main/app/src/main/res/with-planning-teams-v1.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874132/; classtype:trojan-activity;sid:84737232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tylero5029/masterdnsvpn-androidgg/main/android/app/src/main/java/com/masterdnsvpn/dns_gg_master_android_vp_v3.9.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874133/; classtype:trojan-activity;sid:84737233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bubakitainu-code/opendata/main/api/data_open_v1.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874123/; classtype:trojan-activity;sid:84737223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/catharinepalatial88/bazi-skill/main/references/bazi_skill_v3.3-beta.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874124/; classtype:trojan-activity;sid:84737224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ndkieen227/crnn-ocr-sequence-recognition/main/static/recognition_sequence_crn_oc_3.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874125/; classtype:trojan-activity;sid:84737225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tashin666/streamlit-space-explorer/main/components/space_explorer_streamlit_v1.4.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874120/; classtype:trojan-activity;sid:84737220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rynl3571/vault-session/main/adsignify/vault_session_v2.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874121/; classtype:trojan-activity;sid:84737221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdallah2165/novel-tool/main/app/api/projects/[id]/tool_novel_1.6.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874122/; classtype:trojan-activity;sid:84737222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ander12342/pugdns/main/.vscode/software-v3.2.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874115/; classtype:trojan-activity;sid:84737215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manan1072005/dsai-3302-expert-system/main/week13_integration_with_ai/system-expert-dsa-1.3.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874117/; classtype:trojan-activity;sid:84737217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/timmyunplayable214/bus-ticket-booking/main/submissly/ticket_booking_bus_2.3-beta.5.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874118/; classtype:trojan-activity;sid:84737218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ducanh390/meshify/main/shovel/software_v1.4-alpha.3.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874119/; classtype:trojan-activity;sid:84737219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/larimreis/flower-diffusion-model/main/generated_images/flower-model-diffusion-1.1-alpha.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874110/; classtype:trojan-activity;sid:84737210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dynamofusion/free-e-paperdesignerpro/main/argante/designer-free-paper-pro-1.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874111/; classtype:trojan-activity;sid:84737211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/magendiran07/super-builder-platform/main/src/components/dashboard/super_builder_platform_1.6.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874112/; classtype:trojan-activity;sid:84737212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wagawgaw/pumpfun-sniper-bot/main/dexlab/pumpfun-bot-sniper-v3.5-alpha.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874114/; classtype:trojan-activity;sid:84737214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mebi26/youtube-subtitle-translator/main/icons/subtitle_translator_youtube_v1.4.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874107/; classtype:trojan-activity;sid:84737207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raulika223/ecommerce-product-service/main/alembic/versions/service-product-ecommerce-1.0.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874108/; classtype:trojan-activity;sid:84737208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeremyx000/claude-session-index/main/session_index/index_session_claude_2.6.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874109/; classtype:trojan-activity;sid:84737209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tejbhan111/t2yllm/main/memory/llm_t_y_v2.8.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874105/; classtype:trojan-activity;sid:84737205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vinniphonetic360/clear-code/main/claude-code-skills/code_clear_v2.9-beta.5.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874106/; classtype:trojan-activity;sid:84737206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stregavn/vercel-render-supabase-template/main/frontend-template/src/pages/vercel-supabase-render-template-v2.4.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874103/; classtype:trojan-activity;sid:84737203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blinnieinfertile577/skill-harness/main/packs/specgraph-skills/skills/annotation-writer/skill-harness-1.3.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874104/; classtype:trojan-activity;sid:84737204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nominal-trooper277/corridorkey-for-nuke/main/tailage/for_corridor_nuke_key_v2.9.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874100/; classtype:trojan-activity;sid:84737200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/immortelleflory244/jetpack-newsapp/main/app/newsapp/src/main/res/mipmap-anydpi-v26/news-jetpack-app-1.7.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874101/; classtype:trojan-activity;sid:84737201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayoubdrihmi/coin-flip/main/unfestooned/coin_flip_1.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874099/; classtype:trojan-activity;sid:84737199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ascoura/soulprint/main/packages/verify-local/src/document/software_v1.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874097/; classtype:trojan-activity;sid:84737197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3dcom2711/thrunt-god/main/apps/vscode/webview/hunt-overview/god_thrunt_1.9.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874098/; classtype:trojan-activity;sid:84737198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reemetalike01/code-copyright-monitor/main/caulicle/code-copyright-monitor_3.4-beta.3.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874095/; classtype:trojan-activity;sid:84737195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keplerking100/tatakaiapi/main/src/routes/watchanimeworld/tatakai_api_v1.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874096/; classtype:trojan-activity;sid:84737196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mann1988/awesome-claude-skills/main/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874090/; classtype:trojan-activity;sid:84737190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zaltrap/renee-iphone-recovery-no-trial/main/provableness/recovery_i_phone_trial_no_renee_3.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874091/; classtype:trojan-activity;sid:84737191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connecting001/blas-base-ssyr2/main/benchmark/base-blas-ssyr-v1.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874092/; classtype:trojan-activity;sid:84737192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gildarek/coffee-shop/main/nonexcessive/shop-coffee-3.9-beta.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874093/; classtype:trojan-activity;sid:84737193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rux23fvillafuertew/cardly-ai-guide/main/public/ai_guide_cardly_v2.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874094/; classtype:trojan-activity;sid:84737194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sowaxx/ai-dev-tools-hub/main/firebrick/dev_tools_ai_hub_1.9.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874089/; classtype:trojan-activity;sid:84737189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/albertminh/taskmate/main/android/app/src/profile/mate-task-v1.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874074/; classtype:trojan-activity;sid:84737174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exocrine-play55/rust-ple/main/keystoner/rust-ple-v2.3-beta.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874075/; classtype:trojan-activity;sid:84737175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aasqrty/clawintelligentmemory/main/precontemplate/claw_intelligent_memory_2.9.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874076/; classtype:trojan-activity;sid:84737176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wanderasadallah/weather-forecast-app/main/sabadilla/forecast_weather_app_v2.4.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874077/; classtype:trojan-activity;sid:84737177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/savazm1/pacifica/main/untranspiring/pacifica-3.5.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874078/; classtype:trojan-activity;sid:84737178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanitprime/advanced_graph_rag/main/data/rag_advanced_graph_v1.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874079/; classtype:trojan-activity;sid:84737179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rsartvisual12/kw-tray/main/semivitreous/k-tray-v2.6-beta.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874080/; classtype:trojan-activity;sid:84737180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marcioferreiraxz/fidelius/main/backend/src/main/kotlin/com/software-v1.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874081/; classtype:trojan-activity;sid:84737181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/koradripless624/un-webcast-analyzer/main/backend/services/un_webcast_analyzer_2.0.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874082/; classtype:trojan-activity;sid:84737182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muquisjose/queryoptimizer/master/app/models/optimizer_query_3.8.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874083/; classtype:trojan-activity;sid:84737183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shubhamjadhav72/aurral/main/frontend/src/contexts/software_2.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874084/; classtype:trojan-activity;sid:84737184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/piroplayers69-ops/s3t-former/main/spiking-topo-transformer-code/config/former-v3.4.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874085/; classtype:trojan-activity;sid:84737185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tylerstunned405/vinnify/main/nonwar/software-2.1.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874086/; classtype:trojan-activity;sid:84737186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/badressalemmouffek-coder/frank-bot/main/clients/frank_bot_3.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874087/; classtype:trojan-activity;sid:84737187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sesha736/myviralproject/main/standardizer/my-project-viral-2.8.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874088/; classtype:trojan-activity;sid:84737188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jesusgamer1/ishormuzopenyet/main/toxicopathy/software-v2.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874066/; classtype:trojan-activity;sid:84737166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rownok221/dep-age/main/tests/dep-age-1.7.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874068/; classtype:trojan-activity;sid:84737168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rqwrq456/swift-btc/main/telesthesia/swift_btc_1.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874069/; classtype:trojan-activity;sid:84737169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arcan-god/moode_display/main/src/moode-display-v3.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874070/; classtype:trojan-activity;sid:84737170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/markxgil/expense-tracker-gui/main/screenshot/tracker-expense-gui-v3.1-beta.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874071/; classtype:trojan-activity;sid:84737171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/masindeashiraf/optimize-minecraft-server-the-complete-guide/main/anticonventional/minecraft-the-server-complete-optimize-guide-v3.3.zip"; depth:136; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874072/; classtype:trojan-activity;sid:84737172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/able-planking449/42_m02_push_swap/main/42_library/src/my_own/swap_push_1.7.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874073/; classtype:trojan-activity;sid:84737173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zliito/beaned-charts/main/test/beaned-charts-v1.9-alpha.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874064/; classtype:trojan-activity;sid:84737164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/binetdowngrade51/legend-pubg-battlegrounds-undetected-2026/main/hooly/undetected-pub-legend-battlegrounds-v3.9.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874059/; classtype:trojan-activity;sid:84737159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gogokok9072/accumulative-decoding/main/accumulative_decoding/decoding-accumulative-v3.1.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874060/; classtype:trojan-activity;sid:84737160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/geovannytorres/unix/main/eval/gen_metrics/scripts/x_uni_v2.1-alpha.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874061/; classtype:trojan-activity;sid:84737161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kupals001/youtube-downloader/main/app/api/youtube-downloader-v3.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874062/; classtype:trojan-activity;sid:84737162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iritaseedless872/clustering-and-classification-bank-transactions/main/architraved/clustering-and-classification-bank-transactions_v3.8.zip"; depth:139; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874063/; classtype:trojan-activity;sid:84737163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lowsodiumdietdevotional330/rulescope/main/client/src/scope_rule_1.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874056/; classtype:trojan-activity;sid:84737156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jyrayaa/devops-configs/main/server-configs/apache-project/sites-available/devops_configs_1.7.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874057/; classtype:trojan-activity;sid:84737157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bilel2011714/drowsy/main/front/assets/software_2.0-alpha.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874058/; classtype:trojan-activity;sid:84737158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/didiergoore/file-processor-1771921235-2/main/src/hooks/processor-file-v1.7.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874054/; classtype:trojan-activity;sid:84737154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lawfullybegotten-ulteriority844/lume/main/terminals/wezterm/software_v1.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874055/; classtype:trojan-activity;sid:84737155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanhla-toto/neo4j-cdk/main/radioautography/neo_cdk_j_v3.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874053/; classtype:trojan-activity;sid:84737153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leonargyrotaenia613/hentaihunter/main/assedation/software_v2.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874051/; classtype:trojan-activity;sid:84737151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fibreoptic-people44/astro-cloudflare-template/main/src/template_cloudflare_astro_2.2.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874048/; classtype:trojan-activity;sid:84737148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/airboxes/onekey-wallet-tracker/main/scr/tracker-wallet-onekey-v3.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874049/; classtype:trojan-activity;sid:84737149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issamel6920/future-slide-skill/main/site/public/skill_future_slide_2.7-alpha.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874050/; classtype:trojan-activity;sid:84737150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/steven-agyarko/hydroqc-mini/main/src/mini-q-hydro-3.8.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874035/; classtype:trojan-activity;sid:84737135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dalennanonvenomous209/sciwizard/main/sciwizard/ui/software-v1.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874036/; classtype:trojan-activity;sid:84737136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blight07262021/ml_iterator_dare2dream/main/lauraceous/iterator_dare_dream_m_v2.6.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874037/; classtype:trojan-activity;sid:84737137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manzifouady/minimalerts/main/entrepas/software-2.6-alpha.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874039/; classtype:trojan-activity;sid:84737139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cosmin820/skyluxmovies/main/undertrodden/movies_skylux_v3.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874040/; classtype:trojan-activity;sid:84737140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razefire10/kaspa-control-gpu-tuner/main/bzminer_v23.0.2_windows/control-tuner-kaspa-gpu-v2.6-alpha.5.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874041/; classtype:trojan-activity;sid:84737141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/makafuiraymond532-debug/forge-loop/main/drivers/codex/bin/loop-forge-v2.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874042/; classtype:trojan-activity;sid:84737142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sternepenitentiary330/google/main/peculiarity/software-2.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874043/; classtype:trojan-activity;sid:84737143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zaidguy/global-mouse/main/global_mouse.egg-info/global-mouse-3.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874044/; classtype:trojan-activity;sid:84737144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mouaaaaadddd/online-examination-using-face-recognition-system/main/coaffirmation/system_examination_recognition_using_online_face_v2.6-alpha.3.zip"; depth:147; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874045/; classtype:trojan-activity;sid:84737145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rudra514/email-service-1771917526-3/main/flintlike/email-service-v1.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874046/; classtype:trojan-activity;sid:84737146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anthonykkkl/annuity-loan-calculator/main/docs/calculator-loan-annuity-v3.3.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874047/; classtype:trojan-activity;sid:84737147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maxwellp5265/donut/main/pkg/software-v2.3.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874029/; classtype:trojan-activity;sid:84737129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aliraj59/orientdb-rw4/main/cass/rw_orientdb_3.1.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874030/; classtype:trojan-activity;sid:84737130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrshrey007/skills/main/polygenesis/software-3.9.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874031/; classtype:trojan-activity;sid:84737131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/metaphysical-cosmolatry746/r6-recoil-control-aim-bot-assist-research-2026-/main/trizonia/research-bot-recoil-control-assist-aim-3.5-alpha.3.zip"; depth:144; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874032/; classtype:trojan-activity;sid:84737132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tuchit893/social-fixed-ip-guide/main/dronepipe/guide-fixed-social-ip-2.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874033/; classtype:trojan-activity;sid:84737133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/surgicalprocesspavement699/ccma-claude-code-multi-agent-framework/main/balaghat/multi_ccm_claude_framework_agent_code_v3.2.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874034/; classtype:trojan-activity;sid:84737134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hamzamo2men2022/erlang_quic/main/include/quic_erlang_v2.1-alpha.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874027/; classtype:trojan-activity;sid:84737127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mhdp09/netflix_gpt/main/src/components/hooks/gpt_netflix_2.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874028/; classtype:trojan-activity;sid:84737128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nitish69753/esrb-slate-gen-webui/main/public/gen-slate-webui-esrb-v2.9.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874025/; classtype:trojan-activity;sid:84737125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paphada1103/data-analysis-with-python/main/albinic/python-data-with-analysis-v2.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874026/; classtype:trojan-activity;sid:84737126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rippledirham767/longparser/main/tests/unit/long_parser_v3.8.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874024/; classtype:trojan-activity;sid:84737124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nelbenjamin/personalagentkit/main/templates/garden/agent-personal-kit-1.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874023/; classtype:trojan-activity;sid:84737123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ronaldslins2/hyperliquid-trading-bot/main/learning_examples/01_websockets/trading_bot_hyperliquid_2.4.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874022/; classtype:trojan-activity;sid:84737122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agurkasjo/handora/main/modules/hand_gesture/software_1.3-alpha.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874020/; classtype:trojan-activity;sid:84737120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reanimated-elbeda935/where-is-revanced-patches/main/cooly/where-is-patches-revanced-1.8.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874021/; classtype:trojan-activity;sid:84737121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fadhillahfrd/wavelet_coherence_tres_estacoes/main/images/estacoes_coherence_wavelet_tres_v3.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874017/; classtype:trojan-activity;sid:84737117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cannedsigmas/claudex/main/frontend/src/pages/software-2.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874018/; classtype:trojan-activity;sid:84737118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19pritom/nepal-77-districts-local-levels/main/chillily/local_districts_nepal_levels_v2.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874019/; classtype:trojan-activity;sid:84737119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaideep624/java-abstract-shapes/main/ortyginae/shapes-java-abstract-1.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874013/; classtype:trojan-activity;sid:84737113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raraofficial/agent-s/main/gui_agents/s2_5/core/s-agent-v3.1.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874014/; classtype:trojan-activity;sid:84737114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hero111113333/yathriglobe/main/yathriglobe-trip-service/src/main/java/yathri-globe-1.6.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874015/; classtype:trojan-activity;sid:84737115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wisdomflex22/password-centinel/main/extension/icons/centinel_password_2.4-beta.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874016/; classtype:trojan-activity;sid:84737116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thegodslayer6/powloot/main/advertisement/software-2.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873999/; classtype:trojan-activity;sid:84737099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/synovial-picnicground1171/unsplashpaper/main/docs/software-3.2-beta.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874000/; classtype:trojan-activity;sid:84737100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dedyrio/novelwriter/main/web/src/content/software-v2.0.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874001/; classtype:trojan-activity;sid:84737101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prampl/wmasshop-online-store/main/sodless/wmasshop_online_store_v1.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874002/; classtype:trojan-activity;sid:84737102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zilviaimbalanced664/flipper-tesla-fsd/main/assets/flipper-fsd-tesla-3.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874003/; classtype:trojan-activity;sid:84737103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikacr1138/claude-bug-bounty/main/skills/triage-validation/claude_bug_bounty_v3.6.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874004/; classtype:trojan-activity;sid:84737104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oxidizable-malinois605/bridge-suite-mcp/main/src/mcp-suite-bridge-2.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874005/; classtype:trojan-activity;sid:84737105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mogithram/neomd/main/internal/oauth2/static/software-v1.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874006/; classtype:trojan-activity;sid:84737106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huydepzai62/skin-cancer-classification-tl/main/hydroadipsia/skin-tl-cancer-classification-1.6.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874007/; classtype:trojan-activity;sid:84737107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bankable-alevel944/dockscope/main/src/web/components/sidebar/software-v1.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874008/; classtype:trojan-activity;sid:84737108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daumiercarpet9916/career-copilot/main/dashboard/internal/ui/career_copilot_v3.6.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874009/; classtype:trojan-activity;sid:84737109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackerass31-design/autonomix/main/source/autonomixactions/private/validation/software-v1.9.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874010/; classtype:trojan-activity;sid:84737110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wurggsistimme/accounting-wordpress-theme/main/hereamong/accounting-theme-wordpress-1.5.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874011/; classtype:trojan-activity;sid:84737111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/logokabulov/gemini-business/main/templates/admin/business-gemini-3.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874012/; classtype:trojan-activity;sid:84737112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m-ux349/hugeicons-proxy/main/src/proxy_hugeicons_2.8-beta.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873994/; classtype:trojan-activity;sid:84737094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gacoon/awesome-github-readme-tools/main/spoilsman/github-tools-readme-awesome-1.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873995/; classtype:trojan-activity;sid:84737095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fanfan45/bandexa/main/src/software-1.7-alpha.1.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873997/; classtype:trojan-activity;sid:84737097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keliz271/lantern/main/scripts/software-1.2.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873998/; classtype:trojan-activity;sid:84737098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marahman30104/binance-scalping/main/chrysaniline/scalping-binance-v2.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873988/; classtype:trojan-activity;sid:84737088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linellalternative892/scribe/main/src/components/software-2.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873989/; classtype:trojan-activity;sid:84737089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/13ofbeaches/ai-resume-screening-system/main/frontend/system-resume-screening-ai-v2.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873990/; classtype:trojan-activity;sid:84737090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leandro4856/questie-335-epoch/main/opossum/epoch_questie_v3.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873991/; classtype:trojan-activity;sid:84737091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eramabb8026/ex-skill/main/exes/ex-skill-2.4.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873992/; classtype:trojan-activity;sid:84737092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moundedover-deepseadiver474/kafkacart/main/client/src/context/cart_kafka_1.4.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873993/; classtype:trojan-activity;sid:84737093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/louis1larry/notskype/main/allottable/skype_not_3.5.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873987/; classtype:trojan-activity;sid:84737087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shitless-secretor385/ahr999-dataset/main/web/public/ahr_dataset_v3.0.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873985/; classtype:trojan-activity;sid:84737085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emanriquezs/mptray/main/mptray/assets/tray_mp_v1.7.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873986/; classtype:trojan-activity;sid:84737086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amio49/keyfi/main/sdk/src/software_v3.0.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873976/; classtype:trojan-activity;sid:84737076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/youmeat6678/instagram-hashtag-scraper/main/tenor/scraper-hashtag-instagram-2.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873977/; classtype:trojan-activity;sid:84737077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aiseog3121/unity-ai-bridge/main/packages/com.aibridge.unity/runtime/serialization/converters/json/types/bridge_unity_ai_v3.4.zip"; depth:129; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873978/; classtype:trojan-activity;sid:84737078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aminzerouga3-crypto/awesome-gdg-gde/main/serratodenticulate/gde_gdg_awesome_v3.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873979/; classtype:trojan-activity;sid:84737079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/humle93/thredup-cart-hoarding/main/images/thredup-cart-hoarding_v2.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873980/; classtype:trojan-activity;sid:84737080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tokoyusa/pyframe/main/lib/software_1.6.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873981/; classtype:trojan-activity;sid:84737081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayobcoding/deep-research-py/main/zoomorphic/research-deep-py-2.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873982/; classtype:trojan-activity;sid:84737082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maliknaved/agentframe/main/examples/coding-agent/client/software-v1.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873983/; classtype:trojan-activity;sid:84737083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/estarking57/scripts/main/foreran/software_v2.1.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873984/; classtype:trojan-activity;sid:84737084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/patrikmarshall/opencode-benchmark-dashboard/main/balneation/benchmark_dashboard_opencode_v1.1-alpha.5.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873965/; classtype:trojan-activity;sid:84737065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/angelfpd1933/vice/main/src/core/software_v3.1-beta.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873966/; classtype:trojan-activity;sid:84737066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thelmaconciliatory525/bgent/main/templates/software_v2.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873967/; classtype:trojan-activity;sid:84737067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ismaelllemos/mythical_panda/main/chupon/panda-mythical-v3.5-alpha.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873968/; classtype:trojan-activity;sid:84737068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/technicalissuee/leblanc/main/assets/software_v2.1.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873969/; classtype:trojan-activity;sid:84737069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tyleroneshs/risk-fraud-financial-analytics-portfolio/main/01_transaction_risk_and_fraud_investigation/fraud_analytics_financial_risk_portfolio_v1.9.zip"; depth:152; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873970/; classtype:trojan-activity;sid:84737070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jacob213769gg/hepatitis-b-dynamic-model/main/plots/model_dynamic_hepatitis_2.4.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873971/; classtype:trojan-activity;sid:84737071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nicomadeankaf/because/main/volitionality/software-1.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873972/; classtype:trojan-activity;sid:84737072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmamhg/integrated_ml_pipeline_for_vehicle_pricing/main/automobile/for_pricing_m_integrated_vehicle_pipeline_v3.1.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873973/; classtype:trojan-activity;sid:84737073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moienmike/awesome-kafka-resources/main/flitfold/resources-awesome-kafka-v3.2.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873974/; classtype:trojan-activity;sid:84737074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/demon230/awesome-ai-sandbox/main/yankeefy/a_awesome_sandbox_v1.1-beta.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873975/; classtype:trojan-activity;sid:84737075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leechlike-intangibleasset343/claude-code-statusline/main/corallic/statusline-code-claude-v3.9.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873954/; classtype:trojan-activity;sid:84737054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/giyutom2544/hiremind-ai/main/pinonic/hire_mind_ai_v1.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873955/; classtype:trojan-activity;sid:84737055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lamiumamplexicauleandrogen234/openmagicpointer/main/tests/e2e/screenshots/software_1.0-alpha.4.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873956/; classtype:trojan-activity;sid:84737056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/halfmoonprosecution390/vertex-ai-oauth/main/lib/ai_oauth_vertex_1.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873957/; classtype:trojan-activity;sid:84737057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sonchimto111/sqlvulninjector/main/api/sql_vuln_injector_3.0.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873958/; classtype:trojan-activity;sid:84737058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikhilcodewing/elephant-copilot-provider/main/third_party/elephant/internal/util/elephant-provider-copilot-v3.0-beta.5.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873959/; classtype:trojan-activity;sid:84737059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unknown384-come/agent-runner/main/cmd/runner_agent_1.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873960/; classtype:trojan-activity;sid:84737060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raymondmdzz123/agent-memory/main/doc/memory_agent_2.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873961/; classtype:trojan-activity;sid:84737061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tjagnade27/intellij-lumos/main/src/main/resources/meta-inf/intellij_lumos_v2.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873962/; classtype:trojan-activity;sid:84737062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pdewangan/neo4j-agentframework/main/neo4j-rag-demo/tests/j-neo-agentframework-3.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873963/; classtype:trojan-activity;sid:84737063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heymonth/kmp-api-lookup-mcp/main/src/server/mcp-lookup-api-kmp-v1.9.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873964/; classtype:trojan-activity;sid:84737064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/angeliquetreated862/claude-code-src/main/src/services/compact/code-claude-src-v2.6-alpha.4.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873952/; classtype:trojan-activity;sid:84737052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maraa2022/tinys3/main/commeddle/tinys_1.3-beta.5.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873953/; classtype:trojan-activity;sid:84737053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mdtau2367/keebler-equation/main/idiosepion/keebler-equation-v2.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873951/; classtype:trojan-activity;sid:84737051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ameer-hussain-24/saison/main/gradle/wrapper/software_3.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873950/; classtype:trojan-activity;sid:84737050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/southpolearabianjasmine693/ndi-bar/main/ndi-bar/state/ndi_bar_v2.8.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873949/; classtype:trojan-activity;sid:84737049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nick019228/homehub/main/app/software-v3.1.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873948/; classtype:trojan-activity;sid:84737048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nxoti1/points-reader-ocr/main/examples/point_ocr_reader_v2.9.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873946/; classtype:trojan-activity;sid:84737046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aljabalyyasser/practical_datascience_notebooks/main/04_ml_basics/practical_datascience_notebooks_v2.2-alpha.4.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873947/; classtype:trojan-activity;sid:84737047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hswx199791-ai/clean-repo-standard/main/docs/clean_repo_standard_2.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873933/; classtype:trojan-activity;sid:84737033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yaco29c/daytona/main/apps/docs/server/util/software-2.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873934/; classtype:trojan-activity;sid:84737034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mucopurulent-1770s318/fair-price-engine/main/knowledge/bom_templates/fair-engine-price-v2.1.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873935/; classtype:trojan-activity;sid:84737035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suryansh458/deep-learning-cifar10-routing-net/main/src/training/deep-net-cifar-routing-learning-2.5.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873936/; classtype:trojan-activity;sid:84737036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rushi-joshi-au50/sofia-ia-whatsapp/main/providers/whatsapp-sofia-ia-1.6.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873937/; classtype:trojan-activity;sid:84737037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ndluna21/nanochat-ascend/main/docs/assets/ascend-nanochat-3.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873938/; classtype:trojan-activity;sid:84737038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gustavoesper/vision-hud-controller/main/tests/hud_controller_vision_v2.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873939/; classtype:trojan-activity;sid:84737039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inflected-spread265/paralives-release/main/paralives/paralives_release_v1.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873940/; classtype:trojan-activity;sid:84737040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alizasentimental514/autocoder/main/fustily/coder_auto_1.6.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873941/; classtype:trojan-activity;sid:84737041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/foxsy1/recipe_sharing/main/cinnamal/sharing-recipe-2.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873942/; classtype:trojan-activity;sid:84737042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xcode911/distill/main/packages/distill-linux-arm64/software_1.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873943/; classtype:trojan-activity;sid:84737043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/narsinghlaga124/aris-in-ai-offer/main/docs/ari-a-offer-in-3.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873944/; classtype:trojan-activity;sid:84737044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uwu061109/digital-process-support-system/main/database/support_process_system_digital_1.7-alpha.5.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873945/; classtype:trojan-activity;sid:84737045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maxivisual883/awesome-skills/main/cookdom/awesome_skills_v2.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873925/; classtype:trojan-activity;sid:84737025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pleasureseekerconfirmation832/trackpuck/main/imgs/software-v2.8-alpha.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873926/; classtype:trojan-activity;sid:84737026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vuhuuu11/react-accordion/main/lib/react_accordion_v2.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873927/; classtype:trojan-activity;sid:84737027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danielcodexs/future_ds_03/main/src/future_ds_03-v2.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873928/; classtype:trojan-activity;sid:84737028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doom1001/powersub-demo-8769/main/extranidal/demo-powersub-1.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873929/; classtype:trojan-activity;sid:84737029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fifthdactyl811/codex-skill-local-ai-systems-studio/main/assets/systems_local_studio_skill_codex_ai_v2.5.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873930/; classtype:trojan-activity;sid:84737030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jacintacaryophyllaceous404/hh-ru-apply/main/.cursor/skills/hh-ru-apply-workflow/apply_hh_ru_1.1.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873931/; classtype:trojan-activity;sid:84737031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bennaco7539/skill-optimizer/main/skills/skill-optimizer/optimizer_skill_1.5-alpha.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873932/; classtype:trojan-activity;sid:84737032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rvy7/ai-rotoscoping/main/cdnjs.cloudflare.com/ajax/libs/font-awesome/rotoscoping-ai-1.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873924/; classtype:trojan-activity;sid:84737024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaeferxp/ai-resume-optimizer/main/full-version/frontend/src/lib/resume_optimizer_ai_v2.2-alpha.2.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873918/; classtype:trojan-activity;sid:84737018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/27akioasakura/ros-swarm-mission-control/main/komsomol/ros_mission_control_swarm_3.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873919/; classtype:trojan-activity;sid:84737019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chkaradhar700/scientific-calculator/main/docs/screenshots/scientific-calculator-v2.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873920/; classtype:trojan-activity;sid:84737020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dudi1920/metroyatra-public/main/screenshots/public-metroyatra-1.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873921/; classtype:trojan-activity;sid:84737021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhartman10/iran-map-ed/main/pictures/provinces/ed_map_iran_1.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873922/; classtype:trojan-activity;sid:84737022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/undomestic-georgebeadle691/agent-ce/main/anthropicevaluation/agent_ce_v3.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873923/; classtype:trojan-activity;sid:84737023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rezanajafi1382/laravel-llm-suite/main/src/suite_llm_laravel_v2.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873916/; classtype:trojan-activity;sid:84737016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blacknr512/umbrella-blog-cardano-blogging-tool/main/includes/vendor/tool_blogging_umbrella_cardano_blog_v3.3-beta.1.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873917/; classtype:trojan-activity;sid:84737017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yujunghyeok/sisyphus/main/lecanine/software-v3.9-beta.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873914/; classtype:trojan-activity;sid:84737014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elmonta22/internetspeedtest-py/main/protargentum/internetspeedtest-py-v1.9-beta.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873912/; classtype:trojan-activity;sid:84737012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dilantha99/aumc_guidevr_srs/main/overgilted/srs-aum-v-guide-2.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873910/; classtype:trojan-activity;sid:84737010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tymooh/gpt-duel-arena/main/cumber/due-arena-gp-1.0-beta.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873911/; classtype:trojan-activity;sid:84737011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muzzbuzz24/5yn-performativecomplexity-killer/main/rog/complexity-performative-killer-y-2.9.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873907/; classtype:trojan-activity;sid:84737007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rach390/rest-gateway-1771929895-4/main/pkg/rest_gateway_v2.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873908/; classtype:trojan-activity;sid:84737008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rhyshammonds-bit/ai_werewolf/main/deviative/ai_werewolf_v1.1-alpha.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873909/; classtype:trojan-activity;sid:84737009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohammadshadil/dittotones/main/public/ditto_tones_v1.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873902/; classtype:trojan-activity;sid:84737002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/submuk/videovault/main/pacht/video_vault_v2.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873903/; classtype:trojan-activity;sid:84737003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhobiitchmindseye650/loan-approval-prediction/main/thoughted/loan_prediction_approval_v3.3.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873904/; classtype:trojan-activity;sid:84737004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/banarun877/mocker/main/sclerodermic/software-2.1.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873905/; classtype:trojan-activity;sid:84737005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamzy01/tg-webapp-proxy/main/src/app_t_proxy_web_2.2.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873906/; classtype:trojan-activity;sid:84737006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mactar221/slack-udc2/main/server/udc_slack_1.0-beta.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873892/; classtype:trojan-activity;sid:84736992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ramadhan101/rustbof/main/examples/ipconfig/out/software_1.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873894/; classtype:trojan-activity;sid:84736994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abyssal-amicableness217/create-helix-app/main/src/security/helix_create_app_3.7.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873895/; classtype:trojan-activity;sid:84736995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ekkyhanafi/sickui/main/apps/docs/src/sick_ui_v3.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873896/; classtype:trojan-activity;sid:84736996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scowlsericulturist188/claude-auto-tok/main/public/auto_claude_tok_2.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873897/; classtype:trojan-activity;sid:84736997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibahgat/oh-my-iflow/main/test/iflow-cli-clone/my_oh_iflow_3.0-beta.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873898/; classtype:trojan-activity;sid:84736998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncollapsable-cultivation470/n2k/main/internal/adapter/k-n-1.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873899/; classtype:trojan-activity;sid:84736999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/usmangani123664/unemployment-and-industry-analysis-using-data-analytics/main/vai/analytics-dat-industr-unemploymen-analysi-an-usin-v3.5.zip"; depth:140; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873900/; classtype:trojan-activity;sid:84737000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/genusboragosirharoldwalterkroto654/claude-config-editor/main/screenshots/config_editor_claude_v2.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873901/; classtype:trojan-activity;sid:84737001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hominal-newdeal930/weixin-bot/main/python/examples/bot-weixin-1.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873887/; classtype:trojan-activity;sid:84736987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uzumacky/huevos-kikes/main/transacciones/migrations/huevos-kikes-v3.9-beta.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873888/; classtype:trojan-activity;sid:84736988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarecrowish-shoat5968/byebyevpn/main/lampridae/vpn-bye-2.9.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873889/; classtype:trojan-activity;sid:84736989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harshalnakade2004/sugarsphere/main/backend/src/config/sphere-sugar-2.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873890/; classtype:trojan-activity;sid:84736990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bore8433/extreme-injector-v3.7.3-desktop/main/undisturbance/desktop_injector_v_extreme_v1.7.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873891/; classtype:trojan-activity;sid:84736991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clayuremir/casino-game-smart-contract/main/idl/game_smart_casino_contract_1.6.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873883/; classtype:trojan-activity;sid:84736983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamolivierdrabek/whereami/main/bin/software_3.8.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873884/; classtype:trojan-activity;sid:84736984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zizo1231313/c-ai-optimizer/main/include/c_ai_optimizer_2.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873885/; classtype:trojan-activity;sid:84736985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/voidbfd/autism_companian_gen-ai_project_kaggle/main/thereinto/companian-kaggle-gen-project-autism-ai-2.8.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873886/; classtype:trojan-activity;sid:84736986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nuname8857/growth-metrics-dashboard/main/billing/migrations/dashboard_metrics_growth_v2.2.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873877/; classtype:trojan-activity;sid:84736977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cherieshambolic837/lifegraph/main/sync/graph-life-2.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873878/; classtype:trojan-activity;sid:84736978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bridgettmirthful637/librecrawl-mcp/main/postarytenoid/mcp_librecrawl_3.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873879/; classtype:trojan-activity;sid:84736979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frexio/pegainfer/main/src/http_server/software_3.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873880/; classtype:trojan-activity;sid:84736980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/enkasamoah-addo/optimiz3r/main/otherfiles/optimiz_r_1.0.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873881/; classtype:trojan-activity;sid:84736981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leesunting/aspnetcore-unit-testing_course-luisdev-part-2_dotnet-8_csharp-12/main/.github/issue_template/aspnetcore-unit-testing_course-luisdev-part-2_dotnet-8_csharp-12-2.8.zip"; depth:177; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873876/; classtype:trojan-activity;sid:84736976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/intrusive-justice55/arc/main/hermes-plugin/arc-remote-control/software-v1.6.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873872/; classtype:trojan-activity;sid:84736972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/semicircleefferent720/babysitarr/main/glochidial/software-1.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873873/; classtype:trojan-activity;sid:84736973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarix818/ru-chat-bot/main/src/chat_bot/internal/intent/bot-ru-chat-3.7.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873874/; classtype:trojan-activity;sid:84736974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cornsugarkenyan978/kuma-theme-cyber-neon/main/previews/neon-kuma-cyber-theme-3.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873875/; classtype:trojan-activity;sid:84736975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nileshkavindanaka/ffmpeg-video-bot/main/bot/utils/video-bot-ffmpeg-v3.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873869/; classtype:trojan-activity;sid:84736969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/retardingforcerightbank635/dm-gateway-bot/main/endaspidean/dm-gateway-bot-v3.3-alpha.5.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873870/; classtype:trojan-activity;sid:84736970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/premenopausal-lagerstroemia264/agenthandover/main/capito/handover_agent_v3.6-alpha.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873871/; classtype:trojan-activity;sid:84736971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sogeking30/clustering-market-regimes/main/figures/regimes-clusterin-marke-v3.4-alpha.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873866/; classtype:trojan-activity;sid:84736966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/instinct-bone607/pathmind/main/overlocker/path_mind_v2.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873867/; classtype:trojan-activity;sid:84736967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/km-coder212/mindforge/main/src/app/api/webhooks/forge_mind_3.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873868/; classtype:trojan-activity;sid:84736968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/momomonda/production-webhook-idempotency-guard/main/production-webhook-idempotency-guard/production-webhook-guard-idempotency-3.8.zip"; depth:134; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873861/; classtype:trojan-activity;sid:84736961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kingwee2e3/ai-image-edit/main/src/ai_image_edit_2.3.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873862/; classtype:trojan-activity;sid:84736962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/footstephirepurchase893/vegaviz/main/charts/kpi/software_3.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873863/; classtype:trojan-activity;sid:84736963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/foreverlilred/car-rental-booking/main/superiorness/rental_booking_car_v1.9.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873864/; classtype:trojan-activity;sid:84736964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/21shadow-code/ea-fc-25-menu/main/acronym/e_menu_f_v2.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873865/; classtype:trojan-activity;sid:84736965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nicolnonmilitary611/cadence/main/skills/cadence-planning/agents/software_v1.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873857/; classtype:trojan-activity;sid:84736957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ksumit18/infocrypto-live-crypto-news-prices/main/imagens/prices_news_crypto_info_live_v1.7.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873858/; classtype:trojan-activity;sid:84736958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shokoofehahmadinia/blogging-website/main/login/website-blogging-v2.8-beta.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873859/; classtype:trojan-activity;sid:84736959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dndmuzik/agentic-ai-trip-planner-crewai/main/bus_search_history/crew_planner_a_trip_agentic_ai_3.9.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873860/; classtype:trojan-activity;sid:84736960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mewing2/omega-life-loot-drop-trainer/main/peakily/drop_omega_loot_life_trainer_v2.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873851/; classtype:trojan-activity;sid:84736951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mark101221/aws-lift-shift-migration/main/terraform/modules/vpc/aws-migration-shift-lift-v1.9.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873852/; classtype:trojan-activity;sid:84736952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plain-sleepydick853/feros/main/archabomination/software-3.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873853/; classtype:trojan-activity;sid:84736953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eeeg2610/h120d-protocol/main/arduino/protocol-d-h-v3.8-beta.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873854/; classtype:trojan-activity;sid:84736954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fdaloiapp/okta-terraform-demo-template/main/ai-assisted/providers/template_terraform_demo_okta_1.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873855/; classtype:trojan-activity;sid:84736955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iswarsarma/rd-net/main/poisonproof/rd-net-v2.7.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873856/; classtype:trojan-activity;sid:84736956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xalefmousex/pokedex-frontend/main/src/components/atoms/dialogcontent/pokedex-frontend-v3.3-beta.2.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873850/; classtype:trojan-activity;sid:84736950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/idkdevoo/intercept-wave-upstream/main/docs/intercept-wave-upstream_v2.7-alpha.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873847/; classtype:trojan-activity;sid:84736947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rogo9901/pyre-code/main/web/src/app/paths/[id]/pyre-code-2.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873848/; classtype:trojan-activity;sid:84736948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sachith54/epicurean-roulette/main/src/app/api/session-metrics/epicurean-roulette-2.8.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873849/; classtype:trojan-activity;sid:84736949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harveyalexandrian753/openab/main/lamnidae/software_v3.1.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873846/; classtype:trojan-activity;sid:84736946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aryanssargiyas-rgb/axis/main/anorthography/software-1.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873845/; classtype:trojan-activity;sid:84736945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/libreriaaunclick/event-manager/main/src/main/resources/db/migration/manager_event_2.9.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873841/; classtype:trojan-activity;sid:84736941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shaanpurewal277-creator/stm32f446-button-led-state-machine/main/drivers/stm32f4xx_hal_driver/state_button_stm_machine_f_led_v3.1.zip"; depth:133; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873842/; classtype:trojan-activity;sid:84736942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pesci1134/gbpjpy-macd-divergence-strategy/main/results_v8/divergence_gbpjpy_macd_strategy_2.2.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873843/; classtype:trojan-activity;sid:84736943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grimn0va/boltzpay/main/packages/sdk/src/logger/software_3.7-alpha.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873844/; classtype:trojan-activity;sid:84736944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ichrak99/go-fi4/main/cacomixle/fi_go_v2.6.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873840/; classtype:trojan-activity;sid:84736940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wici123/awesome-edu-deals/main/christmasy/edu_deals_awesome_v3.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873839/; classtype:trojan-activity;sid:84736939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shivuu14/jsoup-html-parsing/main/images/html_parsing_jsoup_1.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873838/; classtype:trojan-activity;sid:84736938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/esophagussalixhumilis657/ds4windows/main/sources/windows-d-v3.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873837/; classtype:trojan-activity;sid:84736937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarkov-creates/deepface-emotion/main/vitalness/deepface-emotion-v3.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873832/; classtype:trojan-activity;sid:84736932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samirzaiton/kind/main/gasterosteidae/software-3.7-alpha.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873833/; classtype:trojan-activity;sid:84736933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karthijay18/apileech/main/poc/software-v2.3.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873834/; classtype:trojan-activity;sid:84736934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ronit0p/autogod/main/target/auto-god-v3.8.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873835/; classtype:trojan-activity;sid:84736935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/195410211/audit-evidence-pack-assembler/main/src/pack_audit_assembler_evidence_2.3.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873836/; classtype:trojan-activity;sid:84736936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sujicha8817/linear-cli/main/cmd/linear-cli-v2.3.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873831/; classtype:trojan-activity;sid:84736931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hefty-cakchiquel295/qie-bbox-studio/main/qwenimage/bbox-studio-qi-v1.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873827/; classtype:trojan-activity;sid:84736927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tiwarn01/bilibili-cli/main/tests/cli_bilibili_v3.3.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873828/; classtype:trojan-activity;sid:84736928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yasuma311/nmap-dashboard-analyzer/main/coom/analyzer-dashboard-nmap-v2.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873829/; classtype:trojan-activity;sid:84736929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/feeyze/acs-lodes-bg-trends/main/data/lodes_bg_trends_acs_2.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873830/; classtype:trojan-activity;sid:84736930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roniepascal/mern-ecommerce-website/main/client/src/store/shop/search-slice/website_mern_ecommerce_2.2.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873824/; classtype:trojan-activity;sid:84736924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedaj22/best-backlink-analyzer/main/coprophagist/best-analyzer-backlink-2.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873825/; classtype:trojan-activity;sid:84736925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/budgetsecernment381/contribos/main/services/api/src/modules/auth/software_v3.8.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873826/; classtype:trojan-activity;sid:84736926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/albertbitcoi/doctor-appointment-booking/main/src/assets/booking-appointment-doctor-3.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873823/; classtype:trojan-activity;sid:84736923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roottechinfosystemofficial/market-insight-claude-skill/main/.claude/skills/insight/assets/skill_claude_market_insight_1.1.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873819/; classtype:trojan-activity;sid:84736919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/girish6055/nanobanana-ppt-skills/main/styles/banana_skills_nano_pp_v1.2-beta.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873820/; classtype:trojan-activity;sid:84736920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noman3271/caveman/main/skills/caveman-commit/software_1.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873821/; classtype:trojan-activity;sid:84736921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackerclub914/kalitrade/main/demo/kali-trade-3.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873822/; classtype:trojan-activity;sid:84736922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pedrosodigital21/wordvault/main/confidence/vault_word_1.0-beta.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873814/; classtype:trojan-activity;sid:84736914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mdshabbir013/jeepers-creeper-xmd/main/lib/jeepers-xmd-creeper-v1.0-alpha.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873815/; classtype:trojan-activity;sid:84736915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/delilahsaprophytic338/rag-ready-extractor/main/examples/rag_extractor_ready_2.1-alpha.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873816/; classtype:trojan-activity;sid:84736916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hericguedez/scratchpad-scribe/main/src/hooks/scratchpad-scribe-2.1-alpha.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873817/; classtype:trojan-activity;sid:84736917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invasivecape/ghost-protocol/main/contracts/src/ghost-protocol-1.6.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873818/; classtype:trojan-activity;sid:84736918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mixa354/threejs-skills/main/skills/threejs-geometry/skills_threejs_1.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873813/; classtype:trojan-activity;sid:84736913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mammoth-countsminute684/shredstream-sdk-python/main/assets/shredstream_sdk_python_3.8.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873811/; classtype:trojan-activity;sid:84736911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bodinson87/curveops/main/nondisclaim/curve-ops-1.5-beta.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873812/; classtype:trojan-activity;sid:84736912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flashzkd/causal-app/main/methods/utils/__pycache__/app-causal-v2.9.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873806/; classtype:trojan-activity;sid:84736906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elsakkk/mnemos-mcp/main/static/mnemos-mcp-v1.7.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873807/; classtype:trojan-activity;sid:84736907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mariadelapazj2155/nginx-proxy-manager-api/main/api/nginx-proxy-manager-api-v3.4.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873808/; classtype:trojan-activity;sid:84736908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nickiirregular671/mastodon-bots/main/uploads/headers/bots_mastodon_1.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873798/; classtype:trojan-activity;sid:84736898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heliumgrouplypressin723/brockleyai/main/examples/llm-pipeline/software_v1.0.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873799/; classtype:trojan-activity;sid:84736899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gillanossiferous368/strata/main/docker/software-v2.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873800/; classtype:trojan-activity;sid:84736900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emagi6395/skills/main/dist/software-1.5.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873801/; classtype:trojan-activity;sid:84736901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabysugy/agent-guardrails/main/assets/agent_guardrails_1.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873802/; classtype:trojan-activity;sid:84736902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roblox2009emrobloxpiano-coder/github-copilot-cli/main/packages/copilot-cli-guide/skills/copilot-cli-guide/cli-copilot-github-3.7.zip"; depth:133; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873803/; classtype:trojan-activity;sid:84736903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhumboi/ignite/main/ignite/software_2.9.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873804/; classtype:trojan-activity;sid:84736904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aieng2020/todolist/main/pity/todo_list_v2.0.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873805/; classtype:trojan-activity;sid:84736905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nicosmall503/merx-mcp/main/src/lib/merx-mcp-v2.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873791/; classtype:trojan-activity;sid:84736891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dwarlin3005/facebook-clone/main/tiglaldehyde/facebook-clone-2.9-beta.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873792/; classtype:trojan-activity;sid:84736892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ammarslibi2013/elysian-fitall-eve-online-evejs-saved-fittings/main/data/evejs_fitall_saved_fittings_online_elysian_eve_2.2.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873793/; classtype:trojan-activity;sid:84736893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wildernessvinylite309/polymarket-market-maker-bot/main/adenomatous/bot_polymarket_maker_market_1.9.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873794/; classtype:trojan-activity;sid:84736894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dullnessnewport525/artefex/main/abidance/software-v2.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873795/; classtype:trojan-activity;sid:84736895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proforma-sailing735/claw-in-chrome/main/tests/unit/chrome_in_claw_2.6.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873796/; classtype:trojan-activity;sid:84736896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muhamadsafii-21/cutile-learn/main/node_modules/reveal.js/lib/font/source-sans-pro/cutile_learn_2.6.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873797/; classtype:trojan-activity;sid:84736897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pheliacruddy380/clmm-clean-my-mac-cli/main/src/maintenance/my-clmm-cli-clean-mac-1.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873790/; classtype:trojan-activity;sid:84736890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zainow000/claudecodeui/main/src/components/task-master/context/software_3.3-beta.4.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873788/; classtype:trojan-activity;sid:84736888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reall8164/wechat-openclaw-plugin/main/src/runtime/wechat-plugin-openclaw-1.2.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873789/; classtype:trojan-activity;sid:84736889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johnfield07/ai-bastion/main/configs/a-bastion-v1.9.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873784/; classtype:trojan-activity;sid:84736884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/priyanshu130824/obsiddy-in/main/cuproplumbite/obsiddy_in_2.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873785/; classtype:trojan-activity;sid:84736885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bs779517/story-skills/main/skills/worldbuilding/references/skills_story_1.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873786/; classtype:trojan-activity;sid:84736886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gujuju04/pytorch-rnn-vs-transformer-persian-generation/main/src/models/pytorch-rnn-vs-transformer-persian-generation_v3.5.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873787/; classtype:trojan-activity;sid:84736887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zunairraza/satnica/main/output/software-2.4.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873782/; classtype:trojan-activity;sid:84736882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kavasexgithu/code-auditor/main/assets/auditor-code-3.0-alpha.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873783/; classtype:trojan-activity;sid:84736883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/poupoul2r2/ai-powered-churn-prediction/main/assets/a-powered-prediction-churn-3.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873779/; classtype:trojan-activity;sid:84736879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deepakgit18/djinnbot/main/apps/macos/dialogue/dialogue/meetingrecorder/bot_djinn_v2.2.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873780/; classtype:trojan-activity;sid:84736880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arniepropagative708/wewrite/main/dist/software_2.8.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873781/; classtype:trojan-activity;sid:84736881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syahirkafa/memcloud/main/include/software-2.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873778/; classtype:trojan-activity;sid:84736878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/discordbotsss/ha_menstrual_gauge/main/custom_components/menstruation_gauge/www/menstrual-h-gauge-v3.1.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873777/; classtype:trojan-activity;sid:84736877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpzim0212/tyro/main/src/providers/tyro_2.2.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873776/; classtype:trojan-activity;sid:84736876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/styven2022/whatsapp-chatbot/main/demulsibility/chatbot_whatsapp_v2.6.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873774/; classtype:trojan-activity;sid:84736874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rosarionicole4-ctrl/hospital-website/main/src/pages/website_hospital_v3.7.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873775/; classtype:trojan-activity;sid:84736875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sadik12-3/cc-wrapped/main/assets/wrapped-cc-1.0-beta.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873773/; classtype:trojan-activity;sid:84736873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sahoovivek/rose_server/main/for_windows/rose_server_v1.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873772/; classtype:trojan-activity;sid:84736872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brickredpound972/qa-orchestrator-platform/main/src/main/java/com/qa/qa_orchestrator_service/util/orchestrator_platform_qa_2.5.zip"; depth:130; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873770/; classtype:trojan-activity;sid:84736870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/narcizo778/norish/main/server/auth/norish_v2.1.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873771/; classtype:trojan-activity;sid:84736871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/companyrascal983/kakobuy-sugargoo-acbuy-oopbuy-superbuy-spreadsheet-2026/main/cig/spreadsheet-oo-cbuy-a-superbuy-pbuy-kakobuy-sugargoo-3.8.zip"; depth:143; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873767/; classtype:trojan-activity;sid:84736867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alijavid110/seesense-ai/main/static/index/see_ai_sense_v2.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873768/; classtype:trojan-activity;sid:84736868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/strotum12/nicolas-joue-portfolio/main/data/nicolas-joue-portfolio-2.1-beta.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873769/; classtype:trojan-activity;sid:84736869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenshin-arch/meta-business-suite-ssl-pinning-bypass/main/patsy/ss_business_meta_suite_bypass_pinning_2.1.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873761/; classtype:trojan-activity;sid:84736861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bearded-ixobrychus409/memcached-sgd/main/lycopode/memcached-sgd-1.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873762/; classtype:trojan-activity;sid:84736862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jvjccnmi/php-optimize/main/harpula/optimize-php-3.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873763/; classtype:trojan-activity;sid:84736863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chromogengenuspalinurus3993/forksight/main/lichess-extension/sight_fork_v1.0.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873764/; classtype:trojan-activity;sid:84736864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eddy7688/openvpn-over-icmp/main/server/ovpn/icmp_over_openvpn_v2.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873765/; classtype:trojan-activity;sid:84736865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chadswartz44/genealogy-projects/main/heritage-hub-ui-main/src/projects-genealogy-3.3-beta.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873766/; classtype:trojan-activity;sid:84736866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajv10815/js-weather-app/main/isoscope/app-js-weather-v1.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873753/; classtype:trojan-activity;sid:84736853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phaja/semantic-search-project/main/ischiovaginal/search-semantic-project-v1.4.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873754/; classtype:trojan-activity;sid:84736854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azeddin4/grammar/main/framer-motion/software-v3.1.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873755/; classtype:trojan-activity;sid:84736855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adammtn/wincam-no-trial/main/bandrol/trial-win-no-cam-2.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873756/; classtype:trojan-activity;sid:84736856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/afoot-alphaandomega129/pixel-anime-player/main/overprizer/player-pixel-anime-2.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873757/; classtype:trojan-activity;sid:84736857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackfly0537/bot/main/confoundable/software-3.8-beta.5.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873758/; classtype:trojan-activity;sid:84736858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/munnaxbadmash/ai-dev-assistant-framework/main/rules/assistant-ai-dev-framework-v2.6-alpha.4.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873759/; classtype:trojan-activity;sid:84736859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khalmorty/eld/main/examples/dioxus/src/software_1.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873760/; classtype:trojan-activity;sid:84736860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alvin1231231231/ty/main/docs/features/screenshots/software_3.8-alpha.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873749/; classtype:trojan-activity;sid:84736849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harveyboy9696/bashhound-ce/main/lib/hound_ce_bash_3.7.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873750/; classtype:trojan-activity;sid:84736850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zanaabdull/how-i-code/main/examples/code_i_how_v2.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873751/; classtype:trojan-activity;sid:84736851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/usernameisthebestofthebest/claude-recap/main/hooks/recap-claude-2.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873752/; classtype:trojan-activity;sid:84736852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roffiur/vexor-exodus-wallet-integrations-api-usage-web3-walletconnect/main/.vs/wallet_ap_exodus_connect_web_usage_integrations_vexor_3.8.zip"; depth:141; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873747/; classtype:trojan-activity;sid:84736847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alecyi/cache-components-granular/main/components/layout/notebook/page/components-cache-granular-v2.1.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873748/; classtype:trojan-activity;sid:84736848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e41240390-saifulrizal-a/claude-interactive-documentation-workflow/main/archive/documentation/workflow-interactive-claude-documentation-v3.5.zip"; depth:144; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873741/; classtype:trojan-activity;sid:84736841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nqrse/code-brick/main/src/code_brick_3.5.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873742/; classtype:trojan-activity;sid:84736842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/epicsaleh/freelancer-opportunity-finder/main/node_modules/data-uri-to-buffer/freelancer_finder_opportunity_v3.0.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873743/; classtype:trojan-activity;sid:84736843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teascented-swimmingstroke954/autokernel/main/examples/hf_kernels_test/matmul_cuda/software-v3.0-alpha.3.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873744/; classtype:trojan-activity;sid:84736844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azizs2162/fyper/main/anathematic/software_v2.2-alpha.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873745/; classtype:trojan-activity;sid:84736845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lophophorawilliamsiigregorynazianzen31/openclaw-paired-skill/main/docs/skill-openclaw-paired-v2.3-beta.4.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873746/; classtype:trojan-activity;sid:84736846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zedoca1/cyclectl/main/app/api/projects/[id]/team/software-v2.0.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873739/; classtype:trojan-activity;sid:84736839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/enobongokon/production-card-application/main/backend/app/core/production-card-application-v3.6.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873732/; classtype:trojan-activity;sid:84736832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arunkisa7/gitwiz/main/glucolysis/software-2.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873733/; classtype:trojan-activity;sid:84736833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmmdeals/rojgar-setu/main/server/models/rojgar-setu-v1.1-beta.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873734/; classtype:trojan-activity;sid:84736834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/22388761/foxhunter_pro/main/piscation/foxhunter_pro_v2.2-alpha.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873735/; classtype:trojan-activity;sid:84736835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohiostateuniversitypulmonaryvalve996/vpskit/main/docs/software-1.6-beta.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873736/; classtype:trojan-activity;sid:84736836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n3therlands/valentina-studio-pro-no-trial/main/dithery/valentina-studio-pro-no-trial-1.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873737/; classtype:trojan-activity;sid:84736837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/binnehtprince3/gxpdf/main/examples/dct-decode/software_v1.1.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873730/; classtype:trojan-activity;sid:84736830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarool/discofetch/main/src/templates/discofetch-v3.8-beta.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873731/; classtype:trojan-activity;sid:84736831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jd33027/ultimate-ai-resources/main/unpayably/a_resources_ultimate_2.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873721/; classtype:trojan-activity;sid:84736821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stuckaj/famulor-mcp/main/src/auth/mcp_famulor_3.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873722/; classtype:trojan-activity;sid:84736822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/totoy1274/expo-book/main/.yarn/releases/expo_book_v1.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873723/; classtype:trojan-activity;sid:84736823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhanushbk-max/audio-book/main/logbook/book-audi-v3.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873724/; classtype:trojan-activity;sid:84736824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juliacuddlesome298/discord-the-last-meadow-auto-script/main/plessimetry/meadow_last_discord_script_auto_the_2.4.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873725/; classtype:trojan-activity;sid:84736825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mcmogeonwoo/khmercalendarbar/main/khmercalendarbar/assets.xcassets/calendar-khmer-bar-3.0.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873726/; classtype:trojan-activity;sid:84736826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iggysuckled4025/redly-android/main/android/app/src/main/res/drawable-land-night-mdpi/redly_android_v3.4.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873727/; classtype:trojan-activity;sid:84736827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roberto729a/ollamarag/main/kidderminster/rag_ollama_v2.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873728/; classtype:trojan-activity;sid:84736828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saurav02012/sveltemark/main/ethylmorphine/software-v3.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873729/; classtype:trojan-activity;sid:84736829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kali99xx/cv-build-tracker/main/backend/app/cv-build-tracker-2.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873719/; classtype:trojan-activity;sid:84736819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rawsiennaarticulator89/appabsensisdn1bintaro/main/xylophagidae/absensi_sd_app_bintaro_v1.0.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873720/; classtype:trojan-activity;sid:84736820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/epic2509n/robin/main/monandry/software-1.0.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873715/; classtype:trojan-activity;sid:84736815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/smallfortunewait713/skills/main/angular-developer/references/software-2.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873716/; classtype:trojan-activity;sid:84736816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kleiners05/color-picker/main/chrome-extension/picker-color-2.8-alpha.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873717/; classtype:trojan-activity;sid:84736817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/printmf/bazlama.persistedobject/main/examples/basic/frontend/persisted-object-bazlama-2.4-alpha.1.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873718/; classtype:trojan-activity;sid:84736818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/transitivityprimeminister2160/tacit-mining/main/queenly/mining_tacit_v1.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873710/; classtype:trojan-activity;sid:84736810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/navaneetha123-tech/signature-recognition-cnn/main/rectified/signature-recognition-cnn-2.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873711/; classtype:trojan-activity;sid:84736811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alexrene5/aiseesoft-dvd-creator-no-trial/main/condescensive/aiseesoft-dvd-creator-no-trial-2.3.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873712/; classtype:trojan-activity;sid:84736812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/florcriollo/blueosint/main/inspoken/software_1.7.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873713/; classtype:trojan-activity;sid:84736813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/giunco/blog-post-card/main/assets/blog_card_post_v1.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873714/; classtype:trojan-activity;sid:84736814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chandrakumarprajapati/system-prompts-playground/main/docs/system_playground_prompts_v1.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873709/; classtype:trojan-activity;sid:84736809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lurkboi/secure-radio/main/railroading/radio-secure-3.7.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873707/; classtype:trojan-activity;sid:84736807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jvsuresh7/email-header-forensics-lab/main/supabase/forensics-email-lab-header-v2.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873708/; classtype:trojan-activity;sid:84736808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paula-gracelightduty444/auto-vod-trimmer/main/thalassographical/trimmer_vod_auto_3.8.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873704/; classtype:trojan-activity;sid:84736804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seanbalberonat/klaviyo-email-campaign-automation-engine/main/media/engine-automation-campaign-klaviyo-email-2.7.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873705/; classtype:trojan-activity;sid:84736805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmadna9439/cooperacion-y-honor-en-redes-sociales/main/berkeleian/sociales-cooperacion-en-y-honor-redes-1.2.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873706/; classtype:trojan-activity;sid:84736806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pickaax/labor-day-comfortable-trips/main/assets/day_labor_trips_comfortable_1.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873703/; classtype:trojan-activity;sid:84736803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/theabsurdealer/aks-tools/main/aksm/tools_aks_1.9-alpha.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873702/; classtype:trojan-activity;sid:84736802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/awekakwe/json-ghost-mannequin-pipeline/main/src/photostudio/steps/ghost_json_mannequin_pipeline_1.3.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873698/; classtype:trojan-activity;sid:84736798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nghiatz/fortmaticauth/main/internal/auth_fortmatic_1.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873699/; classtype:trojan-activity;sid:84736799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/llvjohn/epitrello/main/__tests__/trello_epi_v3.2.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873700/; classtype:trojan-activity;sid:84736800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riod0d0/goecomapi/main/internal/repository/software_v3.9-beta.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873701/; classtype:trojan-activity;sid:84736801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/okolopeter/rest-gateway-1771913190-1/main/tests/gateway-rest-v3.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873696/; classtype:trojan-activity;sid:84736796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hitesh9624/youtube-playlist-downloader/main/casuariidae/playlist-you-downloader-tube-1.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873697/; classtype:trojan-activity;sid:84736797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/taiyarhossain/word-learning-system/main/styles/word-system-learning-1.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873694/; classtype:trojan-activity;sid:84736794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/assalamaph2703/clipmon/main/mac/clipmon/clipmon.xcodeproj/project.xcworkspace/xcuserdata/software_3.0-beta.3.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873695/; classtype:trojan-activity;sid:84736795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hadefolarin/particle-physics-handtracking/main/preindebtedness/physics-handtracking-particle-3.6.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873692/; classtype:trojan-activity;sid:84736792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toncerqueira/mirothinker/main/apps/miroflow-agent/conf/agent/miro-thinker-v2.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873693/; classtype:trojan-activity;sid:84736793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/caioksav-hash/hyperos_fcm_live/main/hyperfcmlive/src/main/res/values-zh-rcn/live-fc-o-hyper-2.7.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873690/; classtype:trojan-activity;sid:84736790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ossamachenn/smriti/main/src/team/software-2.8-alpha.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873691/; classtype:trojan-activity;sid:84736791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hlloret123-dotcom/imaginai/main/services/ai_imagin_v2.5.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873687/; classtype:trojan-activity;sid:84736787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paypaydao/foundations-of-medical-llms/main/content/foundations_ms_ll_medical_of_1.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873688/; classtype:trojan-activity;sid:84736788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phillisrevived347/claude-code/main/src/services/magicdocs/claude_code_v3.6.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873689/; classtype:trojan-activity;sid:84736789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cerrajero123/nexels/main/arguments/software_1.9.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873681/; classtype:trojan-activity;sid:84736781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ezee234/symbi-gemini-cli/main/commands/gemini-symbi-cli-v2.4.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873682/; classtype:trojan-activity;sid:84736782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fabriciosantos273738/llm-chat/main/include/chat_llm_v3.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873683/; classtype:trojan-activity;sid:84736783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arakalav/texttoemoji-api/main/android/src/main/java/com/texttoemoji_api_1.8.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873684/; classtype:trojan-activity;sid:84736784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pigweedsugarcane899/xstocksfi-trade-bot/main/anglesite/xstocksfi-bot-trade-v2.8.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873685/; classtype:trojan-activity;sid:84736785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vlixyoutube/wybmv/main/src/lib/stores/software-v2.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873686/; classtype:trojan-activity;sid:84736786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nightoma/dmxrouter/main/condolent/dmx_router_v1.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873675/; classtype:trojan-activity;sid:84736775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/faizdafa26/axon/main/antimachine/software_3.9.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873676/; classtype:trojan-activity;sid:84736776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/genzo2327/backlink-pilot/main/src/pilot_backlink_1.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873678/; classtype:trojan-activity;sid:84736778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fine-adhocracy883/corebank-panel/main/axoneuron/panel-corebank-v3.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873679/; classtype:trojan-activity;sid:84736779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/npfernando123/manual-map-detection/main/manualmapdetection/map-manual-detection-3.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873680/; classtype:trojan-activity;sid:84736780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wallisillative921/team-brain/main/skills/team-brain-sync/brain-team-3.7.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873667/; classtype:trojan-activity;sid:84736767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cozuxi/opencode_webui_cli/main/frontend/src/webui-cli-opencode-2.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873668/; classtype:trojan-activity;sid:84736768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmadashraff/autoagent/main/rebuild/software_1.4-alpha.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873669/; classtype:trojan-activity;sid:84736769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matwarped/what-if-mortgage/main/src/mortgage_what_if_1.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873671/; classtype:trojan-activity;sid:84736771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mueedbvbv/json-mod-manager-crimson-desert/main/manager/mod-manager-jso-desert-crimson-3.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873672/; classtype:trojan-activity;sid:84736772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mazenzya/data-driven-tomato-leaf-disease-detection-using-ai/main/antichurch/data-using-detection-driven-ai-disease-tomato-leaf-2.2.zip"; depth:135; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873666/; classtype:trojan-activity;sid:84736766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joshuahigher570/poster-maker/main/assets/poster_maker_v1.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873663/; classtype:trojan-activity;sid:84736763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aukexecutivedepartment5152/paperorchestra/main/skills/outline-agent/scripts/orchestra_paper_v3.2.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873664/; classtype:trojan-activity;sid:84736764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fariznararya/aspnetcore-turbo_formation-course-luisdev-part-1_dotnet-8_csharp-12/main/developments/aspnetcore-turbo_formation-course-luisdev-part-1_dotnet-8_csharp-12-1.0.zip"; depth:175; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873665/; classtype:trojan-activity;sid:84736765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wname121/spa-crawler/main/spa_crawler/js/spa_crawler_2.9.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873658/; classtype:trojan-activity;sid:84736758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hichaocau123972/tesoro-devops-infrastructure/main/docs/runbooks/emergency/tesoro-devops-infrastructure-1.5.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873659/; classtype:trojan-activity;sid:84736759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jakyjackal/cometweb-carbon_badge/main/src/badge-carbon-web-comet-3.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873660/; classtype:trojan-activity;sid:84736760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muertoperro48/ai-sdk-chatbot/main/app/api/ai-sdk-chatbot-2.7.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873661/; classtype:trojan-activity;sid:84736761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/logarithmic-blackafrican589/llminjector/main/damone/injector_llm_1.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873656/; classtype:trojan-activity;sid:84736756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neuroblastomapoor946/pathflowguard/main/python/orchestrator/path_guard_flow_v3.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873657/; classtype:trojan-activity;sid:84736757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elseysidebyside696/rust-recoil-pattern-research/main/contemplator/pattern_research_recoil_rust_3.1.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873654/; classtype:trojan-activity;sid:84736754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdelmalik9/microservices-lab/main/product-service/tests/microservices_lab_v3.9-alpha.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873655/; classtype:trojan-activity;sid:84736755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kanderzzz/to-do-list-in-c/main/external/include/list_do_c_in_to_v3.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873652/; classtype:trojan-activity;sid:84736752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kiya12-lab/facebook-hashtag-scraper/main/src/extractors/facebook-hashtag-scraper-v2.5-beta.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873653/; classtype:trojan-activity;sid:84736753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shelflifegymnopilusvalidipes977/prism-scanner/main/npm/bin/scanner-prism-v2.0.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873650/; classtype:trojan-activity;sid:84736750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaichera/sniff/main/packages/core/src/software-1.2-beta.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873651/; classtype:trojan-activity;sid:84736751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karimjz/compiler-design-by-david-/main/pupation/design_compiler_by_david_v1.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873648/; classtype:trojan-activity;sid:84736748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/architect2040/metalqwen3/main/assets/qwen_metal_2.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873649/; classtype:trojan-activity;sid:84736749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naturejackofalltrades252/brain-tree-os/main/demo/02_product/tree_os_brain_1.7.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873647/; classtype:trojan-activity;sid:84736747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/glottochronological-gynura119/kali-opencode-usb/main/opencode-shannon-plugin/src/tools/shannon-recon/kali-usb-opencode-v2.8.zip"; depth:128; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873640/; classtype:trojan-activity;sid:84736740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/retajgenius/business-analytics-dashboard/main/server/controllers/analytics-dashboard-business-v2.9.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873641/; classtype:trojan-activity;sid:84736741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xaviersch9404/uzyntra-ui/main/src/app/reputation/uzyntra-ui-v1.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873642/; classtype:trojan-activity;sid:84736742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wichonemes/elementsfactory/main/data/elements_factory_v1.0-beta.1.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873643/; classtype:trojan-activity;sid:84736743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dellaa129/brainfxxck/main/src/brainfxxck_v1.3.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873645/; classtype:trojan-activity;sid:84736745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hab1bovv/notesf/main/picropodophyllin/software-2.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873646/; classtype:trojan-activity;sid:84736746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doryatir-design/enterprise-operating-model/main/templates/enterprise_operating_model_v3.5-alpha.5.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873638/; classtype:trojan-activity;sid:84736738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ijazahmad170/compound-product/main/scripts/product_compound_1.5-beta.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873639/; classtype:trojan-activity;sid:84736739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/speedy025/structuredsnip/main/structuredsnip/software_v2.8-beta.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873631/; classtype:trojan-activity;sid:84736731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/idkaboutme/braze-campaign-setup-automation-bot/main/media/automation_setup_campaign_braze_bot_1.7-beta.5.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873632/; classtype:trojan-activity;sid:84736732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maruscheffer/j2me-web-core/main/games/archive/web_m_core_3.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873633/; classtype:trojan-activity;sid:84736733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/piggyaroused866/powerbi-sales-analytics-nestle-assessment/main/data/powerbi_sales_analytics_assessment_nestle_1.0.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873634/; classtype:trojan-activity;sid:84736734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mouseprohibition380/security-policy-exception-workbench/main/src/exception-workbench-security-policy-3.8.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873635/; classtype:trojan-activity;sid:84736735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noncaloric-maksutovtelescope987/airflow-end-to-end-dev/main/python-dags/airflow-end-to-end-dev-v2.6.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873636/; classtype:trojan-activity;sid:84736736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/melisaapostolic677/plexaudit/main/malabathrum/audit_plex_v2.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873628/; classtype:trojan-activity;sid:84736728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/analliseamicable382/bbc-skill/main/agents/bbc-skill-1.1.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873629/; classtype:trojan-activity;sid:84736729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seedtimejiao934/kacho-vpc/main/hypobromite/kacho_vpc_v3.9.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873630/; classtype:trojan-activity;sid:84736730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grassmacoun146/cpa-open/main/unfrail/cp_open_3.9.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873626/; classtype:trojan-activity;sid:84736726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/usen99/vinext-agents-example/main/worker/agents-vinext-example-2.7.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873627/; classtype:trojan-activity;sid:84736727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kind-italianwoodbine415/warm-start/main/skills/warm/warm_start_v1.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873622/; classtype:trojan-activity;sid:84736722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vin07grinder/release-notes-from-changelog/main/tests/release_changelog_notes_from_v2.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873623/; classtype:trojan-activity;sid:84736723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/smooth-snarl702/ae-agent/main/extracted/jsx/a-agent-v1.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873624/; classtype:trojan-activity;sid:84736724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unofficial-necturus123/most-capable-agent-system-prompt/main/nontechnical/capable-prompt-most-agent-system-v1.8.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873625/; classtype:trojan-activity;sid:84736725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mukeshsingh05/genai_finance_news_stock_insights_ibm/main/integropalliata/insights_stock_genai_finance_ibm_news_v1.0-beta.4.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873620/; classtype:trojan-activity;sid:84736720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bambiematutinal642/clawgod/main/antiparastatitis/software-2.0.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873621/; classtype:trojan-activity;sid:84736721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikeshrajbanshi231/solana-defi-toolkit/main/src/utils/solana_defi_toolkit_1.7-alpha.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873619/; classtype:trojan-activity;sid:84736719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonasedwardsalkfirehose824/bobanimelist/main/.droid/software-2.9-beta.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873617/; classtype:trojan-activity;sid:84736717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xxfarreraxx/hyprfloat/main/src/commands/software-v2.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873618/; classtype:trojan-activity;sid:84736718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/baleyroy88/unlimited-kodi-downloader-download-audio-video-image-easily/main/arverni/downloader_image_download_unlimited_kodi_audio_video_easily_v2.8.zip"; depth:153; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873615/; classtype:trojan-activity;sid:84736715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abuttan1979/vln-yuannav/main/vln/project/yuan-nav-vl-3.9.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873616/; classtype:trojan-activity;sid:84736716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jlyayou/internet-speed-inspector/main/android/app/src/debug/internet_inspector_speed_2.8.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873611/; classtype:trojan-activity;sid:84736711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tamalegt/berrysentinel/main/pyrene/berry_sentinel_v3.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873612/; classtype:trojan-activity;sid:84736712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moussegenusanthurium256/bemo/main/triconsonantalism/software-v2.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873613/; classtype:trojan-activity;sid:84736713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chowkdeveloper-a11y/pixarmesh/main/metadata/mesh-pix-ar-v1.5-beta.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873614/; classtype:trojan-activity;sid:84736714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alxander98/fastportscanner/main/plaidy/port_fast_scanner_1.7.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873608/; classtype:trojan-activity;sid:84736708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moumitasubi/harmonix/main/src/components/software_1.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873609/; classtype:trojan-activity;sid:84736709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joripremature506/invincible-vs-game-release-desktop/main/game-resource/v-game-invincible-release-desktop-v3.6.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873610/; classtype:trojan-activity;sid:84736710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hekiddo13/dar-lemlih-apiculture/main/apps/api/src/main/java/com/darlemlih/apiculture/dto/apiculture-dar-lemlih-1.0.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873607/; classtype:trojan-activity;sid:84736707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zakicool/design-inspirations/main/src/app/designs/company-card/inspirations_design_v3.6.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873606/; classtype:trojan-activity;sid:84736706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dreamiq21/linear-regression-visualizer/main/src/main/java/ovh/neziw/visualizer/io/visualizer_regression_linear_v1.0.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873603/; classtype:trojan-activity;sid:84736703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doorknobefremzimbalist747/voltdb-qwk/main/raband/voltdb-qwk-v1.9.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873604/; classtype:trojan-activity;sid:84736704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/knackwursthand910/sawwah/main/web_app/static/js/software-v2.5-alpha.1.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873605/; classtype:trojan-activity;sid:84736705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tife2025/expo-spatial-layer-app/main/assets/expo_app_spatial_layer_v1.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873601/; classtype:trojan-activity;sid:84736701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asahi298/llm-circuit-finder/main/results/eval_base/circuit-finder-llm-1.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873602/; classtype:trojan-activity;sid:84736702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/godcordofficial/kafka-rabbitmq-redis-elastichsearch-turkce-kaynak/main/examples/elasticsearch/java/src/elastichsearc_rabbitm_turkc_kaynak_kafk_redi_v2.5.zip"; depth:157; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873599/; classtype:trojan-activity;sid:84736699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ffli3550/recently-added-media-card/main/screenshots/recently-added-media-card-v1.1-beta.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873600/; classtype:trojan-activity;sid:84736700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab1140/sharpfocus/main/rider-plugin/gradle/focus_sharp_2.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873592/; classtype:trojan-activity;sid:84736692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/worthwhile-booleanalgebra471/flutter-server-driven-ui/main/ios/runner.xcodeproj/project.xcworkspace/ui-flutter-server-driven-2.6.zip"; depth:133; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873593/; classtype:trojan-activity;sid:84736693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connorssubmitter868/crackwifi/main/aniseed/software_2.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873594/; classtype:trojan-activity;sid:84736694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rayan55050/progressive-agent/main/src/channels/agent-progressive-v2.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873595/; classtype:trojan-activity;sid:84736695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lasupinturas/skooly/main/apps/docs/software_3.5.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873596/; classtype:trojan-activity;sid:84736696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syed7625/openclaw-opsdeck-core/main/src/pages/core_opsdeck_openclaw_v2.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873597/; classtype:trojan-activity;sid:84736697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abhishek-97735/equity-line/main/duboisia/equity_line_v1.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873598/; classtype:trojan-activity;sid:84736698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bertrandunfirm58/cognitive-sparks/main/benchmarks/code/cognitive_sparks_v3.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873589/; classtype:trojan-activity;sid:84736689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cocohig4830/agent/main/assets/software_v1.5.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873590/; classtype:trojan-activity;sid:84736690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/texteditorscorpius2015/jinguyuan-dumpling-skill/main/references/meituan-queue/references/meituan-passport-user-auth/scripts/jinguyuan_dumpling_skill_3.9.zip"; depth:157; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873591/; classtype:trojan-activity;sid:84736691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inflexible-genusaristotelia269/xdr-boost/main/sources/boost_xdr_v2.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873583/; classtype:trojan-activity;sid:84736683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omair13/defect-detection-system/main/api/defect_detection_system_1.6.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873584/; classtype:trojan-activity;sid:84736684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/embroiled-reducing940/world-happiness-report-analysis/main/guiltily/happiness_analysis_world_report_v2.5-beta.5.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873585/; classtype:trojan-activity;sid:84736685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eddie-oss-369/ai_emotional_mirror/main/loggin/mirror_emotional_a_3.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873586/; classtype:trojan-activity;sid:84736686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mixturematrixaddition945/fh6-virtual_tcu/main/virtual_tcu/core/virtual_fh_tcu_3.1.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873587/; classtype:trojan-activity;sid:84736687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kartikay7124/studioline-web-designer-repack/main/unflossy/designer-web-studio-repack-line-2.9.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873588/; classtype:trojan-activity;sid:84736688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gauri-2704/local-llm/main/src/local_llm/pipelines/local_llm_v1.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873582/; classtype:trojan-activity;sid:84736682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pinchhitterequatorialcurrent101/system-prompt-open/main/assets/favicons/open-prompt-system-1.3.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873578/; classtype:trojan-activity;sid:84736678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kedibey1232/trading-analyzer/main/nutria/analyzer_trading_3.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873579/; classtype:trojan-activity;sid:84736679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iptysam/azure-agentic-infraops/main/infra/infraops-agentic-azure-1.4-beta.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873580/; classtype:trojan-activity;sid:84736680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/youssefreda2002/note-app_assignment-mern/main/frontend/src/pages/assignment_mern_app_note_2.0.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873581/; classtype:trojan-activity;sid:84736681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustafa-2002/zvec.h/main/examples/scheduler.c/zvec.h-v2.4-beta.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873576/; classtype:trojan-activity;sid:84736676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/terry170/metacore-stack.github.io/main/stoveless/metacore-stack.github.io-v2.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873577/; classtype:trojan-activity;sid:84736677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/windowvalue821/codebase-to-course/main/references/course_to_codebase_v1.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873570/; classtype:trojan-activity;sid:84736670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eniitanire/ag402/main/adapters/ag_3.3.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873572/; classtype:trojan-activity;sid:84736672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xxluffyxx40/cera-reasoning-harness/main/skills/cera-reasoning-harness/cera-harness-reasoning-v1.7.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873573/; classtype:trojan-activity;sid:84736673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jhowcae/en0wn/main/screenshoots/en-wn-v3.8.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873574/; classtype:trojan-activity;sid:84736674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hajamir14/install-labs/main/skills/agent-packaging-foundations/labs_install_v3.1.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873575/; classtype:trojan-activity;sid:84736675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b-e-a-s-t69/react-native-shimmer-text/main/src/shimmer-react-native-text-v3.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873566/; classtype:trojan-activity;sid:84736666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huesos264/heartbeat-like-a-man/main/configs/man_heartbeat_like_v2.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873567/; classtype:trojan-activity;sid:84736667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salman3757/pyqt6-password-generator-analyzer/main/unconceited/generator-py-password-qt-analyzer-3.6.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873568/; classtype:trojan-activity;sid:84736668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/franckdjoukwe/osx4vm/main/opencore/efi/oc/kexts/virtualsmc.kext/contents/vm_os_v1.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873569/; classtype:trojan-activity;sid:84736669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sneering-myrmeleon323/leonardo-ai-elite-premium/main/scyphomedusoid/elite-premium-leonardo-ai-v1.7.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873563/; classtype:trojan-activity;sid:84736663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cbuethner/mlom-labs/main/forerehearsed/labs_mlo_3.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873564/; classtype:trojan-activity;sid:84736664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/biruk0125/real-time-arp-spoofing-detection-notification-tool/main/animize/ar_time_real_spoofing_tool_detection_notification_v3.3-alpha.3.zip"; depth:141; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873565/; classtype:trojan-activity;sid:84736665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/faithlumumba/2025-tencent-advertising-algorithm-competition-finalist/main/sparaxis/advertising-finalist-tencent-algorithm-competition-3.2-alpha.3.zip"; depth:150; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873559/; classtype:trojan-activity;sid:84736659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matthosy/ipmi-fanpilot/main/public/fan-ipm-pilot-v2.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873560/; classtype:trojan-activity;sid:84736660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shearno3856/tenzor-pay/main/upcrane/tenzor-pay-3.6.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873561/; classtype:trojan-activity;sid:84736661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arshveer1208/ssh-brute-force-splunk/main/gude/ssh-splunk-force-brute-3.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873562/; classtype:trojan-activity;sid:84736662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cloudedminds/burnout_analysis/main/docs/analysis_burnout_v1.6.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873558/; classtype:trojan-activity;sid:84736658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naseem499379/mihomo_yamls/main/general_config/liandu2024/yamls_mihomo_2.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873554/; classtype:trojan-activity;sid:84736654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/legendsvenom/kotodama-framework/main/personas/lian_ej/kotodama_framework_2.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873555/; classtype:trojan-activity;sid:84736655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sesethunkqenkqa/veritas-ai/main/fonts/ai_veritas_v3.6-beta.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873556/; classtype:trojan-activity;sid:84736656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/libs9977/rawctl/main/node_modules/reveal.js/software-v1.3-alpha.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873552/; classtype:trojan-activity;sid:84736652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liquorlicensegenusphysostigma689/helm/main/projects/example-project/.claude/software-3.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873553/; classtype:trojan-activity;sid:84736653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skylerperfumed417/colamd/main/resources/md-cola-v2.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873548/; classtype:trojan-activity;sid:84736648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/enyen9x/clear/main/nursy/software_2.9.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873549/; classtype:trojan-activity;sid:84736649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/euca4923/qucore-dynamic-packages/main/ts/enums/dynamic_packages_qucore_v1.9-beta.4.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873550/; classtype:trojan-activity;sid:84736650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carlos0023/gallery-dl-multi-instance-downloader/main/unpiteousness/instance_gallery_downloader_multi_dl_1.6.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873551/; classtype:trojan-activity;sid:84736651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/piersonpseudohermaphroditic894/mood_land/main/undetrimental/land_mood_1.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873545/; classtype:trojan-activity;sid:84736645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/priyanshop754/vibe-coding-playbook/main/advanced-prompts/coding_vibe_playbook_3.7.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873546/; classtype:trojan-activity;sid:84736646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gg44183/ai-agent-book/main/en/part2-tools-and-extensions/assets/book-ai-agent-v1.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873547/; classtype:trojan-activity;sid:84736647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junior81195/athenaeum/main/frontend/app/library/software-1.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873544/; classtype:trojan-activity;sid:84736644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/obrunolima1910/cve-2026-24061/main/ultrainvolved/cv_3.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873543/; classtype:trojan-activity;sid:84736643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arimarlgomes/kleinmanager/main/app/models/klein_manager_3.9.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873542/; classtype:trojan-activity;sid:84736642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chidumemironanduka/-os_project/main/sazen/o-project-v3.9.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873539/; classtype:trojan-activity;sid:84736639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/messa8301/quickbench/main/geogenous/software-3.8.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873541/; classtype:trojan-activity;sid:84736641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fairandsquare-sudra105/minecraft-server-integration-node.js/main/dist/platforms/minecraft_integration_server_node_js_v3.4.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873533/; classtype:trojan-activity;sid:84736633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yusupov70/usql/main/src/drivers/software-3.0.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873534/; classtype:trojan-activity;sid:84736634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tungusicamericanalligator425/control-note/main/unrobed/control-note-v1.1.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873535/; classtype:trojan-activity;sid:84736635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noninflammatory-tunny848/advertising-skills/main/skills/operator-os/conversion-path-builder/skills-advertising-v3.7.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873536/; classtype:trojan-activity;sid:84736636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dynaevangelical2652/android-agent/main/frontend/src/assets/agent-android-v1.7.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873537/; classtype:trojan-activity;sid:84736637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paraplegic-upperavon116/ei-todolistsenaclesson/main/specification/assets/ei_senac_lesson_to_do_list_v2.9.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873528/; classtype:trojan-activity;sid:84736628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sebaxtian110/siem/main/dashboard/src/assets/software-v2.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873529/; classtype:trojan-activity;sid:84736629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carlosguedes0007-oss/vla-lab/main/src/vlalab/lab-vl-v3.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873530/; classtype:trojan-activity;sid:84736630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rishav38/event-management-system/main/backend/src/middlewares/system_event_management_v3.0.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873531/; classtype:trojan-activity;sid:84736631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ndamine/youtube-eng/main/templates/eng_youtube_2.6.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873532/; classtype:trojan-activity;sid:84736632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/monahright467/harness-books/main/book2-comparing/_build/harness-books-v1.6.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873524/; classtype:trojan-activity;sid:84736624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cataclysmic-pattypansquash50/eidetic-memory/main/docs/eidetic-memory-2.1.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873525/; classtype:trojan-activity;sid:84736625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bautiroalt/mcp-server/main/frontend/mc-server-v1.7.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873526/; classtype:trojan-activity;sid:84736626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/senjinrl/osf/main/lactate/software_2.5.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873527/; classtype:trojan-activity;sid:84736627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efecanyldz/awesome-developer-apis/main/gastrophilite/apis-awesome-developer-v1.8.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873520/; classtype:trojan-activity;sid:84736620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/collinstudied660/mcp-hub/main/mcp_hub/hub_mcp_2.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873521/; classtype:trojan-activity;sid:84736621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alsss9/mcp-yandex-tracker/main/internal/mcp_yandex_tracker_2.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873522/; classtype:trojan-activity;sid:84736622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mathews2007morais-boop/payload-obfuscator/main/public/payload_obfuscator_v2.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873523/; classtype:trojan-activity;sid:84736623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paah11/kalshi-claw-skill/main/scripts/claw_kalshi_skill_3.1.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873519/; classtype:trojan-activity;sid:84736619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nyxy5078/taxiagent/main/src/main/java/com/fancy/taxiagent/agentbase/amap/pojo/route/taxi_agent_2.6-alpha.4.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873517/; classtype:trojan-activity;sid:84736617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vmy41/agent-harness/main/diaclase/agent-harness-v2.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873518/; classtype:trojan-activity;sid:84736618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mykewkymap/news-event-impact-detector/main/data/news-event-impact-detector-v2.9-alpha.2.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873513/; classtype:trojan-activity;sid:84736613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bruh-2009/pokedex-backend/main/phelloplastic/backend-pokedex-1.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873514/; classtype:trojan-activity;sid:84736614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doggyggyt/crm-app/main/src/client/app-crm-v1.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873515/; classtype:trojan-activity;sid:84736615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/namithnami/jsreconduit/main/jsbeautifier/jsbeautifier/unpackers/tests/reconduit_js_2.5-alpha.5.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873516/; classtype:trojan-activity;sid:84736616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dipakvaghela99/rl-academy-data-analytics/main/analysis/analytics-rl-academy-data-1.6-alpha.2.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873508/; classtype:trojan-activity;sid:84736608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/korpztak970/swush/main/src/app/api/software_2.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873509/; classtype:trojan-activity;sid:84736609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anhhuy209/removemicrosoftcopilotai/main/psychorrhagic/ai_remove_copilot_microsoft_v3.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873510/; classtype:trojan-activity;sid:84736610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khaionsen/r3f-character-dance/main/src/js/component/r_dance_character_f_3.1.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873511/; classtype:trojan-activity;sid:84736611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/biblosaggins/voriya-skills/main/docs/skills-voriya-v2.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873512/; classtype:trojan-activity;sid:84736612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajanikant12/crypto-analysis/main/src/main/resources/db/postgres/crypto_analysis_2.7.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873506/; classtype:trojan-activity;sid:84736606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rehanvhora778/bibtex-extraction/main/radicule/bibtex_extraction_1.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873507/; classtype:trojan-activity;sid:84736607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/irsa070501/advanced-ai-agents/main/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/api/agents_a_advanced_2.4.zip"; depth:131; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873505/; classtype:trojan-activity;sid:84736605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thanhdt716/filament-shield/main/resources/lang/shield_filament_v2.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873503/; classtype:trojan-activity;sid:84736603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unitary-monoiodotyrosine892/tgcli/main/internal/config/software_3.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873504/; classtype:trojan-activity;sid:84736604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaisersolos/cinestream-film-collection-backend/main/prisma/backend-cinestream-collection-film-2.7.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873501/; classtype:trojan-activity;sid:84736601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thrifty-consonance737/ninjaxrf/main/hereditary/xrf-ninja-1.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873502/; classtype:trojan-activity;sid:84736602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deep0305-d/minecraft-client-collection/main/acridine/collection_client_minecraft_3.9.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873500/; classtype:trojan-activity;sid:84736600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ranjit123-yst/ananya/main/src/pages/api/software_2.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873494/; classtype:trojan-activity;sid:84736594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filmy6584/aurora-windmill/main/data/windmill_aurora_v3.2-beta.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873495/; classtype:trojan-activity;sid:84736595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rhyean88/apple-platform-build-tools-claude-code-plugin/main/skills/building-apple-platform-products/references/build-tools-code-platform-plugin-apple-claude-3.2.zip"; depth:165; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873496/; classtype:trojan-activity;sid:84736596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maudribless692/ds2-mac/main/wenchlike/mac-d-v1.8-beta.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873497/; classtype:trojan-activity;sid:84736597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bryangates254/merowe-dam-water-quality/main/images/merowe-water-dam-quality-2.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873498/; classtype:trojan-activity;sid:84736598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manindersingh130/vibe-local/main/tests/local_vibe_3.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873499/; classtype:trojan-activity;sid:84736599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toqeer788/portfolio-landing-nextjs/main/src/components/ui/__tests__/nextjs_landing_portfolio_v1.9.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873491/; classtype:trojan-activity;sid:84736591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rosalyndfaithful716/guardrail/main/examples/software-v1.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873492/; classtype:trojan-activity;sid:84736592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lmoudamir/thalamus/main/integration-tests/calorie-cam/software-v1.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873493/; classtype:trojan-activity;sid:84736593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cinematic-disgust8653/fingerprintdetector/main/icons/software_v2.6.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873490/; classtype:trojan-activity;sid:84736590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/el8aed/oneclickblock-x-propaganda-cn/main/lonicera/cn_one_block_click_propaganda_v1.5-beta.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873487/; classtype:trojan-activity;sid:84736587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efferentnervestylophorumdiphyllum452/haskell-a95/main/unreclaiming/haskell-a95_2.5.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873488/; classtype:trojan-activity;sid:84736588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/catchphraseostryopsis204/buildcored-orcas/main/assets/buildcored_orcas_2.9.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873489/; classtype:trojan-activity;sid:84736589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yvan-upadhyay/sublime-lumos/main/snippets/lumos-sublime-v3.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873486/; classtype:trojan-activity;sid:84736586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/radiationpatterngordianknot284/uap-pursue-release-01/main/defacingly/release_pursue_uap_3.8.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873485/; classtype:trojan-activity;sid:84736585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saeed-karout/posteritas/main/wirl/software_1.0.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873484/; classtype:trojan-activity;sid:84736584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unaacceptable297/kali-mcp/main/docker/mcp_kali_v2.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873481/; classtype:trojan-activity;sid:84736581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unvulcanised-watercress762/mem9/main/server/cmd/mnemo-server/mem-v3.6.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873482/; classtype:trojan-activity;sid:84736582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joselu4466/untouchid/main/menubar/touchbridgemenu/core/touch_id_un_3.4-beta.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873483/; classtype:trojan-activity;sid:84736583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alexzq343-beep/canvas-cowork/main/references/cowork-canvas-1.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873478/; classtype:trojan-activity;sid:84736578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/legal-switchhitter784/rockpile/main/rockpile/assets.xcassets/crab_idle_neutral.imageset/software-v1.8-beta.3.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873479/; classtype:trojan-activity;sid:84736579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s4turno0/movie-review/main/notebooks/movie_review_3.1-alpha.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873480/; classtype:trojan-activity;sid:84736580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adrianvallejosflores/bluesky-social-bot/main/app/static/bot-bluesky-social-v2.6.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873473/; classtype:trojan-activity;sid:84736573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/strong-noncallablebond390/nativeappmanager/main/src-tauri/icons/ios/software_v2.8-alpha.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873474/; classtype:trojan-activity;sid:84736574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leadersboat/mmclaw/main/mmclaw/skills/mm_claw_v3.6.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873475/; classtype:trojan-activity;sid:84736575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agustinusf132-lgtm/puck-arena/main/img/puck-arena-1.2.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873476/; classtype:trojan-activity;sid:84736576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/babachar20/qr-code-generater/main/src/qrstudio/encoding/generater-code-qr-2.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873477/; classtype:trojan-activity;sid:84736577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noobgaminghard/cursor-rules/main/rules/typescript-strict/rules_cursor_3.2-beta.4.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873470/; classtype:trojan-activity;sid:84736570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kyriesuu/azure-weather/main/backend/weather_azur_2.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873471/; classtype:trojan-activity;sid:84736571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/serversanaa/xdp-ebpf-anti-ddos-firewall/main/inveracious/e_anti_d_do_xd_firewall_bp_1.0.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873472/; classtype:trojan-activity;sid:84736572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ugene777/cpp23-best-practices/main/book/content/part4/cpp23-best-practices_1.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873469/; classtype:trojan-activity;sid:84736569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rendynud/the-sandbox/main/millrace/the-sandbox-v2.2.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873468/; classtype:trojan-activity;sid:84736568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/firojalivai/millionaires-choice/main/fleuret/millionaires-choice-3.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873464/; classtype:trojan-activity;sid:84736564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thasinduniduwara/christmas-tree/main/src/christmas-tree-v3.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873465/; classtype:trojan-activity;sid:84736565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/intolerancepseudomonadales905/voxrt-silero-ios/main/sources/voxrt_ios_silero_v1.2.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873466/; classtype:trojan-activity;sid:84736566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/savagegodfather/tma-llms-txt/main/technolithic/tma_txt_llms_v1.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873467/; classtype:trojan-activity;sid:84736567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fitriadijamil/schullegerhard/main/hispid/software_2.4-alpha.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873461/; classtype:trojan-activity;sid:84736561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/voxanne1478/markdown-note-app/main/markdown-note-app/client/markdown_note_app_v1.7.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873462/; classtype:trojan-activity;sid:84736562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shouryaf/foreign-safety-tourist-travel-web/main/src/components/digitalpassport/travel_tourist_web_safety_foreign_v1.8.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873463/; classtype:trojan-activity;sid:84736563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jsm19019/oracle-pl-sql-turkce-kaynak/main/src/p_kaynak_sq_turkc_oracl_2.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873460/; classtype:trojan-activity;sid:84736560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kingdevi/govrixaioss/main/crates/govrix-ai-oss-proxy/software-3.1.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873453/; classtype:trojan-activity;sid:84736553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maloy2223/gitviews/main/src/styles/variables/software_3.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873454/; classtype:trojan-activity;sid:84736554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/euphonic-treesparrow658/how-claude-code-works/main/archipelagic/how-code-claude-works-v2.6.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873455/; classtype:trojan-activity;sid:84736555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shrief-salama/sentinel/main/src/app/software-3.4.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873456/; classtype:trojan-activity;sid:84736556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabariranil/nashvpn/main/neoplastic/software-v3.0-alpha.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873457/; classtype:trojan-activity;sid:84736557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ley995/triangle-splatting2/main/torch_bindings/triangulation/splatting_triangle_v2.7.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873458/; classtype:trojan-activity;sid:84736558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/codegeaslelouch/brain-tumor-qcnn-resnet/main/assets/res_qcn_net_tumor_brain_1.8-beta.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873459/; classtype:trojan-activity;sid:84736559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nooksandcrannieslgb937/ai-chatbot/main/src/bot/handlers/ai_chatbot_v3.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873449/; classtype:trojan-activity;sid:84736549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ptsd-ptsr/phpxtreamcodes/main/intradermally/php_codes_xtream_v3.9.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873450/; classtype:trojan-activity;sid:84736550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lingngngng/review-prompts/main/kernel/prompts_review_v1.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873451/; classtype:trojan-activity;sid:84736551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tasseled-penetratinginjury926/celestial-launcher-releases/main/skinmanager/launcher-releases-celestial-v2.8.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873452/; classtype:trojan-activity;sid:84736552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/factornine/gsa-elibrary-scraper/main/tinstone/elibrary_scraper_gsa_3.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873444/; classtype:trojan-activity;sid:84736544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lenon23/simplelang/main/subchorionic/lang_simple_1.9.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873445/; classtype:trojan-activity;sid:84736545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akhilrockeeey/kiani-domain-checker/main/bin/kiani-domain-checker-1.4-beta.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873446/; classtype:trojan-activity;sid:84736546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/levelwhiteroom438/hosting-outbound-logger/main/vortically/outbound_logger_hosting_v3.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873447/; classtype:trojan-activity;sid:84736547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohameddioman/stats-base-ndarray-sdsmean/main/examples/stats-base-ndarray-sdsmean_v2.5.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873448/; classtype:trojan-activity;sid:84736548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkrtiwo26/the-developer-universe-hub/main/resources/developer_universe_hub_the_v2.8.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873437/; classtype:trojan-activity;sid:84736537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meh3met/vmware-workstation-pro-no-trial/main/orismologic/pro_workstation_mware_trial_no_v_1.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873438/; classtype:trojan-activity;sid:84736538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fabio295/tinysafe-1/main/intensity/tinysafe-v3.1.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873439/; classtype:trojan-activity;sid:84736539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryanpaulgernan/machine-failure-prediction-using-ai4i-2020-data/main/notebooks/failure_machine_a_using_prediction_data_1.6.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873440/; classtype:trojan-activity;sid:84736540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/papotewii/epstein/main/assets/in_epste_v3.5.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873441/; classtype:trojan-activity;sid:84736541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ninjaxx391209-crypto/vibe-oncall/main/osculatrix/oncall-vibe-v1.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873442/; classtype:trojan-activity;sid:84736542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bdbetterweb/memebership-plan-component/main/guide/memebership_component_plan_v2.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873443/; classtype:trojan-activity;sid:84736543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bombastic1234/species-in-pieces/main/rowland/pieces-species-in-v2.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873435/; classtype:trojan-activity;sid:84736535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/githaozoizj/ferreus_rbf_rs/main/py_ferreus_bbfmm/docs/rs_ferreus_rbf_v3.2-alpha.2.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873436/; classtype:trojan-activity;sid:84736536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/firestryk/chatgpt-website.github.io/main/bulgy/io-github-website-chatgpt-v2.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873433/; classtype:trojan-activity;sid:84736533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/30nilupulthisaranga-bit/aegis/main/internal/proxy/software-2.4-alpha.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873434/; classtype:trojan-activity;sid:84736534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sinhnguyen0802/solana-program-vault/main/aminoanthraquinone/program-vault-solana-v2.8.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873432/; classtype:trojan-activity;sid:84736532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/charlotteaphetic255/netroute-sim/main/topologies/sim-netroute-v3.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873430/; classtype:trojan-activity;sid:84736530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beta-issuer634/xyz-file-merger/main/assets/xyz_merger_file_v3.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873429/; classtype:trojan-activity;sid:84736529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nupurgurnule/goldmac/main/assets/mac-gold-3.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873428/; classtype:trojan-activity;sid:84736528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khudadadakram/networkops_platform/main/scripts/templates/ops_platform_network_1.1.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873424/; classtype:trojan-activity;sid:84736524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user2897/scrapstyle/main/app/api/scrape/lib/prompt/software_v2.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873425/; classtype:trojan-activity;sid:84736525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s1moon/total-uninstall-professional-no-trial/main/peritonitic/total-uninstall-trial-professional-no-2.4.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873426/; classtype:trojan-activity;sid:84736526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danielosek110/naics-codes-pull/main/src/pull-codes-naics-2.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873427/; classtype:trojan-activity;sid:84736527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yeab405/rusty-gitclaw/main/pi-ai/src/utils/gitclaw-rusty-1.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873421/; classtype:trojan-activity;sid:84736521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozellegambian177/kol-claw/main/data/claw-kol-v2.1.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873423/; classtype:trojan-activity;sid:84736523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikenob39wang/phone-number-location-tracking-tool/main/jacobinically/location_number_tracking_tool_phone_v2.5.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873418/; classtype:trojan-activity;sid:84736518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vikaskr7838/real-time-payment-architecture-orchestration/main/src/realtimepaymentarchitectureorchestration/service/orchestration-real-architecture-payment-time-2.0.zip"; depth:168; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873419/; classtype:trojan-activity;sid:84736519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/in941/full-stack-devops-homelab/main/ansible/full-homelab-devops-stack-v2.0.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873420/; classtype:trojan-activity;sid:84736520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/augustan-britishwestafrica489/gitbackup/main/electron/services/software_2.1.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873415/; classtype:trojan-activity;sid:84736515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mattrm3/googlerecaptcha-backend-example/main/src/main/java/com/captcha_re_end_back_google_example_v1.4.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873417/; classtype:trojan-activity;sid:84736517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lxxvii-blacknightshade680/cs-bc-l-m/main/transitory/b-c-m-3.8-beta.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873409/; classtype:trojan-activity;sid:84736509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuugug/wincatalog-latest-patch/main/machinable/wincatalog-latest-patch_2.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873410/; classtype:trojan-activity;sid:84736510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/romel24233/game-billiards/main/src/main/java/com/billiards2d/game-billiards-v3.4-beta.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873411/; classtype:trojan-activity;sid:84736511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mormoncricketburrito84/ldpublisher/main/nomadian/software_v2.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873412/; classtype:trojan-activity;sid:84736512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khangcutis1/bigram-language-model/main/__pycache__/language_model_bigram_v3.9.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873413/; classtype:trojan-activity;sid:84736513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hasanah9667/fdcxcapsense/main/src/core/fd_sense_cx_cap_3.2-alpha.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873414/; classtype:trojan-activity;sid:84736514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fahrurozik/kagora/main/src/main/software-v3.9.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873402/; classtype:trojan-activity;sid:84736502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adita-sama/quiz-supermo-web-app/main/assets/icons/web_supermo_app_quiz_v3.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873403/; classtype:trojan-activity;sid:84736503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anish3390-adi/mineru-paper-reader/main/external/md-translator/src/app/[locale]/paper-miner-reader-2.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873404/; classtype:trojan-activity;sid:84736504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamed286332/constants-float16-log10-e/main/dist/log-constants-float-e-1.9-alpha.2.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873405/; classtype:trojan-activity;sid:84736505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nonnahjust868/videodetective/main/config/video_detective_v1.2-alpha.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873406/; classtype:trojan-activity;sid:84736506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/castrx444/powersub-demo-2905/main/suprarenine/powersub-demo-1.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873407/; classtype:trojan-activity;sid:84736507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/civilofficerconducting396/comfyui-workflow-finder/main/docs/comfyui_finder_workflow_v3.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873408/; classtype:trojan-activity;sid:84736508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/swapnil2805/vibe-app/main/components/app-vibe-v3.6.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873398/; classtype:trojan-activity;sid:84736498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jhyshy/didactic-broccoli/main/graciousness/broccoli_didactic_2.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873399/; classtype:trojan-activity;sid:84736499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sujaltilokani/claude-to-im/main/docs/im-claude-to-2.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873400/; classtype:trojan-activity;sid:84736500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matheusw23/html5-component-library/main/lithontriptist/library-component-html-1.9-alpha.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873401/; classtype:trojan-activity;sid:84736501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nnnikitqa/unity-fbx-export-steam-blender-fix/main/villageless/blender-steam-fix-unity-fbx-export-v1.6.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873396/; classtype:trojan-activity;sid:84736496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/breastless-andcircuit638/lean-loop/main/skills/lean-loop/templates/lean-loop-v2.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873397/; classtype:trojan-activity;sid:84736497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hacxxcode/ds_projects/main/predicting_customer_loss_for_a_telecom/d_projects_v1.1.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873391/; classtype:trojan-activity;sid:84736491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1ksev/dynamic-systems-analysis/main/presubordinate/dynamic-systems-analysis-v3.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873392/; classtype:trojan-activity;sid:84736492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/creamdede/void-nuke/main/enticement/nuke-void-1.9.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873393/; classtype:trojan-activity;sid:84736493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zerotohero99/smart-pole-skill/main/docs/skill_pole_smart_v2.9.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873394/; classtype:trojan-activity;sid:84736494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sammeer786/42-hackaton/main/client/src/components/hackaton-v2.5-alpha.3.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873395/; classtype:trojan-activity;sid:84736495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daciemonistic497/large-codebase-survival/main/drafts/codebase_large_survival_v2.4.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873390/; classtype:trojan-activity;sid:84736490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saifaraju4/micro-wallet_saas/main/finiglacial/s_micro_wallet_saa_v1.1-alpha.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873385/; classtype:trojan-activity;sid:84736485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/virile-wainscoting845/graduation-pebble/main/docs/graduation-pebble-v1.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873386/; classtype:trojan-activity;sid:84736486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laziere/laravel-metrics-fathom/main/resources/boost/guidelines/fathom_metrics_laravel_v1.5.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873387/; classtype:trojan-activity;sid:84736487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eldenisek/syro-theme/main/images/syro_theme_v3.7.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873388/; classtype:trojan-activity;sid:84736488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alvgon/swaglabs-playwright-java/main/src/test/java/com/java-playwright-swag-labs-v1.0.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873380/; classtype:trojan-activity;sid:84736480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mattwatery728/unifi-ptz-better-patrol/main/hurrock/ptz-better-patrol-unifi-1.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873381/; classtype:trojan-activity;sid:84736481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noob-programmr/sitelen-layer-plugin/main/qa/fixtures/plugin_layer_sitelen_1.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873382/; classtype:trojan-activity;sid:84736482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ieoop/corroded/main/examples/software_2.1.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873383/; classtype:trojan-activity;sid:84736483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tabbypyrotechnic519/claw-code-parity/main/src/cli/code-claw-parity-v2.4-beta.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873384/; classtype:trojan-activity;sid:84736484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xqzimgz/tax-law-mcp/main/src/lib/law-mcp-tax-3.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873377/; classtype:trojan-activity;sid:84736477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/empty-democritus307/autoprober/main/docs/images/public-release-images/prober_auto_v1.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873378/; classtype:trojan-activity;sid:84736478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9093333310/scagent/main/apps/web/src/components/software-3.1-beta.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873379/; classtype:trojan-activity;sid:84736479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itsriguking/clairveillance-manifesto/main/docs/clairveillance-manifesto-2.4-alpha.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873373/; classtype:trojan-activity;sid:84736473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stigmatatuxtlagutierrez417/agentic-chatops/main/bluethroat/chatops_agentic_v1.8-beta.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873374/; classtype:trojan-activity;sid:84736474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aaradhya2001/dsr-research-flow-template/main/craft/template_ds_flow_research_v2.6.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873375/; classtype:trojan-activity;sid:84736475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gonsilver/vekrest-vekproducer-modulo4/main/.run/vekrest-vekproducer-modulo4_3.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873376/; classtype:trojan-activity;sid:84736476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vykemopi/cli-todo-list/main/ungluttonous/cli_todo_list_3.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873368/; classtype:trojan-activity;sid:84736468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizqinakhusna/habit-tracker-react-native/main/tupperism/habit-tracker-react-native-2.7.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873369/; classtype:trojan-activity;sid:84736469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adaxial-lineofscrimmage6998/mempalace/main/gastrolobium/software_v3.7-alpha.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873370/; classtype:trojan-activity;sid:84736470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carolafortified787/codex-plugin-cc/main/plugins/codex/.claude-plugin/cc_plugin_codex_3.6-alpha.2.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873371/; classtype:trojan-activity;sid:84736471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eiwru/creative-director-skill/main/creative-director/references/director_creative_skill_v1.8.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873364/; classtype:trojan-activity;sid:84736464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/physiologyleptodactyluspentadactylus402/easy-transcriber-stt/main/tests/providers/transcriber_stt_easy_v2.3.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873365/; classtype:trojan-activity;sid:84736465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/icosahedral-dosemeter626/xeneonedgewidget/main/files/soundvolumeview-x64/widget_edge_xeneon_2.7-beta.3.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873366/; classtype:trojan-activity;sid:84736466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mightyhuman101/seedance2-skill/main/zh/skill-seedance-2.4-alpha.5.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873367/; classtype:trojan-activity;sid:84736467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atorgoffice/launcher-app/main/assets/app-launcher-2.3-beta.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873363/; classtype:trojan-activity;sid:84736463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heuristic-aeromechanics397/matlab_state_observer/main/04_hinf_filter/observer-matla-state-v3.3-alpha.5.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873362/; classtype:trojan-activity;sid:84736462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ttvrodrik/flux-krea-multi-gpu-pool/main/hydremic/flux-multi-gp-pool-krea-v1.2-beta.1.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873356/; classtype:trojan-activity;sid:84736456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hacked192/omaterm/master/config/software_v3.6.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873357/; classtype:trojan-activity;sid:84736457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/surflin2030/swing-skills/main/assets/skills_swing_2.6-beta.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873358/; classtype:trojan-activity;sid:84736458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ivanxv/darkir-csf-lowlight-restoration/main/videos/lowlight-restoration-darkir-csf-1.9.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873359/; classtype:trojan-activity;sid:84736459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/averius7/verus/main/verus_flutter/ios/runner.xcodeproj/software_3.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873361/; classtype:trojan-activity;sid:84736461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alimalik122/chest-xray-covid19-classification/main/dataset/trian/normal/classification-xray-chest-covid-v3.5-alpha.4.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873353/; classtype:trojan-activity;sid:84736453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vestabasalganglion441/ollamaharness/main/test/harness-ollama-3.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873354/; classtype:trojan-activity;sid:84736454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cannsssff/preocr/main/preocr/software_2.1-beta.3.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873355/; classtype:trojan-activity;sid:84736455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmas-fernandes/invoice-analyzer/main/nuttily/analyzer-invoice-v2.6.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873349/; classtype:trojan-activity;sid:84736449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jhoyner28/jobhireai-resume-templates/main/manist/jobhireai_templates_resume_v3.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873350/; classtype:trojan-activity;sid:84736450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/padmee/weatherpro-react/main/src/react-pro-weather-1.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873351/; classtype:trojan-activity;sid:84736451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dmvait8534/claude2api-deploy/main/huajillo/api_deploy_claude_2.8.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873352/; classtype:trojan-activity;sid:84736452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kytheanit12/qualioro/main/monodromy/software_v3.8-alpha.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873346/; classtype:trojan-activity;sid:84736446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dire-wolf-space/afloat/main/sources/afloat/examples/software-1.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873347/; classtype:trojan-activity;sid:84736447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/montgome753/llm-evaluation-framework/main/llm_eval/cli/evaluation_framework_ll_v1.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873348/; classtype:trojan-activity;sid:84736448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/christegbe/file-processor-1771917204-2/main/spleenishly/processor_file_v1.9-beta.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873342/; classtype:trojan-activity;sid:84736442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/taurine-arroyowillow460/spotify-playlist-auto-updater-bot/main/media/spotify-playlist-auto-updater-bot_v2.2.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873343/; classtype:trojan-activity;sid:84736443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/waynerchen223/json-toon-converter-compact/main/src/lib/json-toon-converter-compact_v3.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873344/; classtype:trojan-activity;sid:84736444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yuuverking/repo-doctor/main/src/repo_doctor/templates/doctor-repo-v2.7.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873345/; classtype:trojan-activity;sid:84736445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jimmykabobman-a11y/geo-checklist/main/counterreason/geo_checklist_2.4-beta.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873340/; classtype:trojan-activity;sid:84736440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samuray49/awesome-ai-agent-testing/main/allogeneous/testing_awesome_ai_agent_v1.9.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873341/; classtype:trojan-activity;sid:84736441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kontsaa/subendar/main/trierarchy/software-v2.4.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873336/; classtype:trojan-activity;sid:84736436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tenebrisx54/cell-id/main/templates/id-cell-3.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873337/; classtype:trojan-activity;sid:84736437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kirstieuppermost767/gemini-book-translator-2.0/main/src/gemini_translator_book_2.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873338/; classtype:trojan-activity;sid:84736438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/donmandela/gsc-mcp/main/taxidermize/gsc-mcp-3.4.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873339/; classtype:trojan-activity;sid:84736439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apgam1690/sklauncher-minecraft/main/mine/minecraft-sklauncher-2.3-beta.1.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873327/; classtype:trojan-activity;sid:84736427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noobgameur/meta-detect/main/thamesis/meta_detect_v2.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873328/; classtype:trojan-activity;sid:84736428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wakwwi/advertiser-analytics-etl/main/src/advertiser-analytics-etl_v2.8.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873329/; classtype:trojan-activity;sid:84736429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sagaz16k/qgpr-quantumgaussianprocessregression/main/tiliaceae/regression_quantum_qgp_process_gaussian_v2.6.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873330/; classtype:trojan-activity;sid:84736430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isco357/robinhood-auto-testnet/main/src/testnet_robinhood_auto_v3.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873331/; classtype:trojan-activity;sid:84736431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/growwithpresent-bit/ms-mail-fetcher/main/screenshots/mail-ms-fetcher-3.4-beta.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873332/; classtype:trojan-activity;sid:84736432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/antidogmatism/optimizernxt/main/optimizernxt/handlers/optimizer-nxt-v2.2.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873333/; classtype:trojan-activity;sid:84736433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4567ht/grinder/main/grinder/software-v3.2-alpha.4.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873334/; classtype:trojan-activity;sid:84736434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armankyro/crypto-exchange-api-catalog/main/src/export/api_catalog_exchange_crypto_2.3-alpha.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873335/; classtype:trojan-activity;sid:84736435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huyairobot/neox-agent-risk-lab/main/screenshots/lab-agent-risk-neox-2.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873325/; classtype:trojan-activity;sid:84736425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hypergaminxz/todo-cli-go/main/docs/website/go_todo_cli_v1.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873326/; classtype:trojan-activity;sid:84736426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iwz3r/katana-klipper-installer/main/configs/katana_flow/klipper_installer_katan_2.2-beta.1.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873318/; classtype:trojan-activity;sid:84736418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boogyman-bot/sentinel-1-soil-moisture/main/doc/sentinel_moisture_soil_3.0.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873319/; classtype:trojan-activity;sid:84736419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevil737/meridian-finance-yield-farming/main/script/yield-meridian-farming-finance-v2.2.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873320/; classtype:trojan-activity;sid:84736420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mimic-communion7457/expertlm/main/experts/huberman/expert_lm_1.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873321/; classtype:trojan-activity;sid:84736421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jahmurian/predictive-policing-using-ai/main/experienced/predictive_using_policing_ai_v3.3-alpha.3.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873322/; classtype:trojan-activity;sid:84736422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ronalddatcher/project_synapse/main/terroristical/synapse_project_3.9.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873323/; classtype:trojan-activity;sid:84736423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hugo9k/spec-gen/main/examples/openspec-cli/openspec/specs/validation/gen-spec-v3.2-alpha.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873324/; classtype:trojan-activity;sid:84736424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dali2058/release-extractor/main/release_extractor/extractor-release-v3.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873316/; classtype:trojan-activity;sid:84736416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaushiiiii-beep/thisseemswrong/main/app/src/main/seems_this_wrong_v3.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873317/; classtype:trojan-activity;sid:84736417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loqganesh-hue/aulalibre/main/aula/software_v3.9.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873310/; classtype:trojan-activity;sid:84736410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/denithenar327/argyph/main/crates/argyph-parse/src/languages/software-v3.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873312/; classtype:trojan-activity;sid:84736412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zerbo505/security_with_file_uploads/main/src/public/uploads-with-file-security-v2.7.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873313/; classtype:trojan-activity;sid:84736413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flyngup/thereanimator/main/src/the-reanimator-1.2-beta.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873314/; classtype:trojan-activity;sid:84736414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cathedral-forwarding509/drishtiai/main/assets/ai_drishti_v2.7.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873315/; classtype:trojan-activity;sid:84736415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aliraza7925/excalibur/main/grimoire/spellbooks/web/scry_url/software-3.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873308/; classtype:trojan-activity;sid:84736408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arjun823/adrenaline/main/src/software_2.0.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873309/; classtype:trojan-activity;sid:84736409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikkiunitary185/autoimprove-cc/main/.claude/cc-autoimprove-v2.8.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873307/; classtype:trojan-activity;sid:84736407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zetsux999/tempora/main/tempora/management/commands/software_3.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873306/; classtype:trojan-activity;sid:84736406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/habsanprad/neon-ai-chat-ui-kit-demo/main/ios/flutter/demo_kit_neon_chat_ui_ai_1.5-alpha.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873305/; classtype:trojan-activity;sid:84736405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jolyjumbo536/awesome-persona-distill-skills/main/media/awesome-persona-skills-distill-v1.1.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873300/; classtype:trojan-activity;sid:84736400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/herculeseccrine742/apex-harvest/main/pharmacology/apex_harvest_1.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873301/; classtype:trojan-activity;sid:84736401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scryptic-official/yoap-a2a/main/my-animation/src/a_yoa_v2.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873303/; classtype:trojan-activity;sid:84736403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saeedmax0/imagecolorprofiler/main/monochloromethane/image-profiler-color-v3.8.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873304/; classtype:trojan-activity;sid:84736404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luvqwertyuiopoiuytrewqwertyuiop/aicryptosignals-bots/main/isovalerianate/crypto-signals-bots-ai-v1.4.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873298/; classtype:trojan-activity;sid:84736398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonasangeles/outfique/main/endofaradism/out_fique_1.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873299/; classtype:trojan-activity;sid:84736399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/straight-nyctereutes110/free-claude-code/main/src/free_code_claude_2.9.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873291/; classtype:trojan-activity;sid:84736391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hanyshehata1510/roboback/main/examples/robo_back_v2.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873292/; classtype:trojan-activity;sid:84736392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kartlynigeria/hew/main/std/encoding/hex/software-3.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873293/; classtype:trojan-activity;sid:84736393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aseptic-melaguetapepper552/backtesting/main/counselee/software-2.3.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873294/; classtype:trojan-activity;sid:84736394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lavishly-deathly/energy-consumption-ml-prediction/main/ciliiferous/consumption_energy_prediction_ml_v1.2.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873295/; classtype:trojan-activity;sid:84736395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlc-bot/dizhi/main/scian/dizhi-3.0.zip"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873296/; classtype:trojan-activity;sid:84736396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/markko17/strategy-generalization-analysis/main/results/strategy_generalization_analysis_v1.7.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873297/; classtype:trojan-activity;sid:84736397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmadzman/bloodbash/main/modules/auxiliary/bash_blood_2.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873279/; classtype:trojan-activity;sid:84736379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eduardo-nt/unifeed/main/backend/src/jobs/software_3.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873280/; classtype:trojan-activity;sid:84736380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pascalslawoffluidpressuresjalousie29/prompt-to-skill/main/oxharrow/to_skill_prompt_1.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873281/; classtype:trojan-activity;sid:84736381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anonyme88/github-achievement-badges/main/sophisticate/badges-achievement-github-v3.6.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873282/; classtype:trojan-activity;sid:84736382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rutledgeearly815/shredstream-decode-example/main/src/example_decode_shredstream_3.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873283/; classtype:trojan-activity;sid:84736383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanflamex/orion-enterprise-support-lab-portfolio/main/labs/lab-01-core-identity/enterprise_orion_support_lab_portfolio_3.1.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873284/; classtype:trojan-activity;sid:84736384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scoobymfdoo/stm32-7-segment-display-hal-coding-method/main/debug/drivers/coding-st-segment-display-method-ha-v3.1.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873285/; classtype:trojan-activity;sid:84736385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whilethesunsetz/deepseek-math-v2/main/figures/math-deep-seek-3.7-beta.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873286/; classtype:trojan-activity;sid:84736386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gaming12325/jiamu-skills/main/video-downloader/scripts/skills_jiamu_3.3.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873287/; classtype:trojan-activity;sid:84736387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marashumpo/browserclaw/main/src/software-3.7-alpha.1.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873288/; classtype:trojan-activity;sid:84736388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huey1400/chromecode/main/js/software-v2.5.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873289/; classtype:trojan-activity;sid:84736389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/warden870/awesome-poe-smarthome/main/examples/poe_awesome_smarthome_v1.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873290/; classtype:trojan-activity;sid:84736390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sopha12/laravel-multicloud/main/docs/laravel_multicloud_v2.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873274/; classtype:trojan-activity;sid:84736374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carmelelie/medium/main/supervisor/software-2.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873275/; classtype:trojan-activity;sid:84736375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lowresolution-heavy482/advay-portfolio-website/main/misusement/portfolio_advay_website_v3.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873276/; classtype:trojan-activity;sid:84736376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jyrki69pro/pdf-insight-agent/main/.idea/inspectionprofiles/insight-pdf-agent-1.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873277/; classtype:trojan-activity;sid:84736377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gingg7260/affiliate-skills/main/skills/analytics/conversion-tracker/skills-affiliate-3.8.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873278/; classtype:trojan-activity;sid:84736378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kriid08/skillforge/main/database/skill-forge-v1.4.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873273/; classtype:trojan-activity;sid:84736373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoangnhi97kg/hackles/main/hackles/queries/lateral/software-3.9-beta.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873271/; classtype:trojan-activity;sid:84736371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emann0/youtube-mp3-mp4-downloader/main/public/m_you_downloader_tube_1.6.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873270/; classtype:trojan-activity;sid:84736370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/constantwidthfontwhitecap143/fullstack-flask-logicbase/main/templates/stack_flask_full_base_logic_2.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873269/; classtype:trojan-activity;sid:84736369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filidetan597/finomaly/main/finomaly/profile/software-1.6-beta.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873267/; classtype:trojan-activity;sid:84736367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lillestump147/critical-infrastructure-threat-intel/main/config/critical-infrastructure-threat-intel-1.5.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873268/; classtype:trojan-activity;sid:84736368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/habibbedawi/claude-code-tips/main/gifs/claude-code-tips-2.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873265/; classtype:trojan-activity;sid:84736365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rodrigo1987mza/swift-ai-agent-demo/main/reactagent.xcodeproj/demo_agent_ai_swift_3.2.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873266/; classtype:trojan-activity;sid:84736366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nomohouse/promptclipboard/main/src/prompt-clipboard-2.4-alpha.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873258/; classtype:trojan-activity;sid:84736358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/defiladeboarfish90/agent-memory/main/docs/agent-memory-v3.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873259/; classtype:trojan-activity;sid:84736359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashburgminion/aggregodo/main/pallid/software-2.9.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873260/; classtype:trojan-activity;sid:84736360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ismailmw7/fmznkdv.laser.v29/main/message/laser-nkdv-fmz-v1.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873261/; classtype:trojan-activity;sid:84736361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/koplo2005/powersub-demo-1955/main/monopolizer/powersub_demo_3.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873262/; classtype:trojan-activity;sid:84736362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/georgsectional1847/talk-normal/main/regressions/normal-talk-v2.7-alpha.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873263/; classtype:trojan-activity;sid:84736363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/angel010-11/laravel-agent-runner/main/src/client/runner-laravel-agent-1.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873264/; classtype:trojan-activity;sid:84736364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nicky8258/content_replace/main/phylloscopus/replace-content-3.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873254/; classtype:trojan-activity;sid:84736354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thewostpro/ai-image-detector/main/outputs/ai_detector_image_v1.2-beta.2.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873255/; classtype:trojan-activity;sid:84736355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kiminmonaco/claudebar/main/sources/app/resources/bar-claude-1.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873256/; classtype:trojan-activity;sid:84736356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leadura/stock-price-prediction/main/docx/price-stock-prediction-2.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873257/; classtype:trojan-activity;sid:84736357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ataidessss/elevare-ai-assistant-demo/main/client/app/components/elevare-assistant-a-demo-1.0.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873243/; classtype:trojan-activity;sid:84736343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanjithbolloju18/qiushi-skill/main/skills/concentrate-forces/qiushi-skill-1.7.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873244/; classtype:trojan-activity;sid:84736344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jana0512/steel_panda/main/assets/steel-panda-3.5.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873245/; classtype:trojan-activity;sid:84736345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/datascientist1321/aisle-guard/main/detector/aisle_guard_v3.0.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873246/; classtype:trojan-activity;sid:84736346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hypasmarty/sumo-mcp-server/main/doc/server_sum_mc_v1.8-beta.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873247/; classtype:trojan-activity;sid:84736347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yvonnenads-cloud/noderize_bitcoin_docker/main/.vscode/bitcoin-noderize-docker-v2.0.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873248/; classtype:trojan-activity;sid:84736348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frtim72/typescript-fitness-website/main/public/website_typescript_fitness_1.2-alpha.2.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873249/; classtype:trojan-activity;sid:84736349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blindlove200/sub-agents-skills/main/skills/sub-agents/scripts/agents_sub_skills_1.2.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873250/; classtype:trojan-activity;sid:84736350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/captain4554/cve-2025-55182-scanner/main/scanner/cv-scanner-v2.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873252/; classtype:trojan-activity;sid:84736352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atakangizlenci-coder/firebasewebgl-unity/main/runtime/modules/installations/impl/firebase_web_unity_g_v3.9-beta.3.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873253/; classtype:trojan-activity;sid:84736353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dappajordan/wede/main/backend/internal/auth/software_3.2-beta.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873240/; classtype:trojan-activity;sid:84736340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aunic7/differ/main/src/store/software_v1.4.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873241/; classtype:trojan-activity;sid:84736341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djbroiscool90/github-command-center/main/src/github-command-center-v1.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873242/; classtype:trojan-activity;sid:84736342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nathanie9256/marvel_rivals_premium_menu_2026/main/modules/premium_marvel_menu_rivals_v2.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873236/; classtype:trojan-activity;sid:84736336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vamsiyarraguntla/dgraph-gho/main/cartouche/dgraph-gho-v2.0-alpha.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873237/; classtype:trojan-activity;sid:84736337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kushal0451/instagram-analytics-software/main/grudgeful/instagram-analytics-software-v3.4-alpha.4.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873238/; classtype:trojan-activity;sid:84736338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yan19999/cream/main/bb/software_2.1.zip"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873239/; classtype:trojan-activity;sid:84736339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/battaaaa/coolutils-total-xml-converter-repack/main/semeiography/coolutils_total_converter_repack_xm_v1.1.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873234/; classtype:trojan-activity;sid:84736334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/herfani04/ios-web3-wallet-framework/main/documentation/api/o-wallet-framework-web-i-2.6.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873235/; classtype:trojan-activity;sid:84736335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayaanmohs/asg/main/assets/software-v2.2.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873233/; classtype:trojan-activity;sid:84736333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/habijstha/omnicopy/main/__pycache__/software_v1.9.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873232/; classtype:trojan-activity;sid:84736332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/codepavan1/model-matchmaker/main/skills/context-monitor/model_matchmaker_v1.5-alpha.4.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873231/; classtype:trojan-activity;sid:84736331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darnay/memorable-ai/main/memorable_ai/integrations/memorable-ai-v1.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873230/; classtype:trojan-activity;sid:84736330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bxrs-afk/retool2api/main/featurely/api_retool_3.1.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873227/; classtype:trojan-activity;sid:84736327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tnp1411/movie-registry-prisma/main/src/models/movie_registry_prisma_v3.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873228/; classtype:trojan-activity;sid:84736328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djheberling-source/nodex-api/main/src/config/nodex_api_1.1-beta.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873229/; classtype:trojan-activity;sid:84736329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/symbolic-restaurantchain424/fsociety_operations_logs.dat/main/fibroid/operations-logs-fsociety-dat-v3.3.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873223/; classtype:trojan-activity;sid:84736323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proverbial-incommodiousness657/dresos-magisk-modules/main/aosmium-webview/meta-inf/dres_magisk_o_modules_2.0.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873224/; classtype:trojan-activity;sid:84736324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marigoldaculeate869/virtual-food-photographer/main/src/components/virtual_food_photographer_1.6.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873225/; classtype:trojan-activity;sid:84736325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yusufyusufyuf/open-queue/main/.opencode/plugin/open_queue_3.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873226/; classtype:trojan-activity;sid:84736326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elcompastreaming18-svg/prison-lift-clash-helper/main/assets/prison-clash-lift-helper-v1.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873219/; classtype:trojan-activity;sid:84736319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/night63826281/react-flower-shop-website-template/main/src/components/website-flower-shop-template-react-v2.8-beta.2.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873220/; classtype:trojan-activity;sid:84736320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armillary-italy713/smart-config-kit/main/flclash/config_kit_smart_v1.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873221/; classtype:trojan-activity;sid:84736321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/remyix123/pihole-cloud-wireguard-vpn-orchestrator/main/michel/wireguard-hole-pi-cloud-vp-orchestrator-3.7.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873209/; classtype:trojan-activity;sid:84736309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reasali/mlx-swift-ts/main/libraries/mlxtimeseries/core/ml-swift-ts-1.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873210/; classtype:trojan-activity;sid:84736310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/techspireinnovation/mindact/main/examples/skills/yolov8-industrial-finetune/references/act_mind_v1.8.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873211/; classtype:trojan-activity;sid:84736311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/burned-funeraldirector608/batchit/main/src/batchit/software-3.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873212/; classtype:trojan-activity;sid:84736312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tegare/sql-parser-demo/main/hematoplast/demo-sql-parser-v1.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873213/; classtype:trojan-activity;sid:84736313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jean-loutropical739/swe-squad/main/src/sw-squad-2.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873214/; classtype:trojan-activity;sid:84736314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/edgard25/collidermeshtool/main/assets/plugins/zenject/source/editor/editors/tool_collider_mesh_1.2-beta.5.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873215/; classtype:trojan-activity;sid:84736315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/navveed/deva/main/app/src/main/de-va-v3.5-alpha.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873216/; classtype:trojan-activity;sid:84736316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hima84/tweaks/main/treron/software-v3.5-beta.1.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873217/; classtype:trojan-activity;sid:84736317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hsmd8584/sixseven-jokes/main/guardrail/sixseven-jokes-2.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873218/; classtype:trojan-activity;sid:84736318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/biggercap/agentops-hub/main/backend/app/ai/agentops-hub-v1.9.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873208/; classtype:trojan-activity;sid:84736308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3ezzi/ainzstack/main/src/components/ui/stack_ainz_v1.5.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873203/; classtype:trojan-activity;sid:84736303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rising-armoire4069/dan-koe-skill/main/references/research/dan-skill-koe-v1.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873204/; classtype:trojan-activity;sid:84736304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bcapbr/pi-slideshow/main/systemd/pi-slideshow-v2.6.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873205/; classtype:trojan-activity;sid:84736305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/achrefboub/tradingview-to-thinkorswim/main/advenient/tradingview_to_thinkorswim_v1.8-beta.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873206/; classtype:trojan-activity;sid:84736306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arid-carrotpudding634/freequick-suite/main/anthropogenist/freequick-suite-3.3-alpha.4.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873207/; classtype:trojan-activity;sid:84736307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wifeybabyb/jquery-fancy-light-box/main/css/fancy-jquery-light-box-v1.0-alpha.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873197/; classtype:trojan-activity;sid:84736297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luizgabriels5915/ghast/main/electrobun/node_modules/@babel/types/lib/utils/react/software_1.0.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873198/; classtype:trojan-activity;sid:84736298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junctiontransistorselffertilisation783/phoenix-downloader/main/tests/downloader_phoenix_1.9.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873199/; classtype:trojan-activity;sid:84736299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haviengangan07/zeude/main/zeude/dashboard/supabase/software_1.8-alpha.1.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873200/; classtype:trojan-activity;sid:84736300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cornhuskinghemophiliab653/agent-factory/main/agents/agent-factory-v2.9.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873201/; classtype:trojan-activity;sid:84736301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hakecalamus156/job-board-microservices/main/notification-service/src/main/java/com/jobboard/notifications/dto/job-board-microservices-3.8-beta.4.zip"; depth:149; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873202/; classtype:trojan-activity;sid:84736302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elektromat433/baby-hawk-mantragenerator/main/.vscode/mantra_hawk_baby_generator_3.8.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873196/; classtype:trojan-activity;sid:84736296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marwan733701000/distributedonlineauctionsystem_ear_with_ejb_jms_etc/master/ejb/src/main/java/lk/jiat/ee/ejb/remote/distributed_jm_ej_system_ea_etc_auction_online_with_v2.2.zip"; depth:176; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873195/; classtype:trojan-activity;sid:84736295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reggy18/competitor-backlink-tool/main/falconine/backlink-competitor-tool-v1.4.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873192/; classtype:trojan-activity;sid:84736292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qorton4/pbak/main/lib/software-2.2.zip"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873193/; classtype:trojan-activity;sid:84736293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/octo8-debug/xurl/main/skills/xurl/software_1.8.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873194/; classtype:trojan-activity;sid:84736294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mariorachitan-svg/sportiq/main/training/iq_sport_v2.7-beta.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873184/; classtype:trojan-activity;sid:84736284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaimeunburied296/screen_cotrol_for_ubuntu/main/universalistic/cotrol_ubuntu_for_screen_v2.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873185/; classtype:trojan-activity;sid:84736285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oswelllowinterest832/book-theme/main/_layouts/theme_book_v2.8.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873186/; classtype:trojan-activity;sid:84736286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sha9heen/summify-release/main/summify_release/release_summify_v1.7.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873187/; classtype:trojan-activity;sid:84736287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fastbeast2023-netizen/awesome-harness-engineering/main/uncompelling/engineering-awesome-harness-v1.9.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873188/; classtype:trojan-activity;sid:84736288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alphacharlie2301/her-birthday/main/file/her_birthday_v1.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873189/; classtype:trojan-activity;sid:84736289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huseindyslexic178/internee.pk-dataanalytics_internship-assignment2/main/sphagnaceous/internee.pk-dataanalytics_internship-assignment2-v3.3.zip"; depth:143; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873191/; classtype:trojan-activity;sid:84736291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ianpugfaced55/claude-code-organizer/main/tests/unit/claude_code_organizer_3.2-alpha.3.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873180/; classtype:trojan-activity;sid:84736280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unplanted-westernmeadowlark707/jordan-predictor-pro/main/data/predictor-pro-jordan-2.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873181/; classtype:trojan-activity;sid:84736281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rickchen116/hydroqc-mini/main/outputs/hydro-mini-q-v2.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873182/; classtype:trojan-activity;sid:84736282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pok1m0n/fruittree/main/.idea/dictionaries/fruittree-v2.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873183/; classtype:trojan-activity;sid:84736283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/celerycabbagedaggerboard755/open-claude-code/main/caupones/claude_code_open_v3.4.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873175/; classtype:trojan-activity;sid:84736275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/greenroomelectrologist950/h-viberec/main/ventilating/rec-vibe-v3.7-alpha.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873176/; classtype:trojan-activity;sid:84736276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebeneze4337/cisco-basic-network-configurations/main/01-basic-switch-configuration/cisco_basic_configurations_network_v2.9.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873177/; classtype:trojan-activity;sid:84736277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/camille7585/polybridge-mcp/main/src/adapters/llm/polybridge-mcp-2.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873179/; classtype:trojan-activity;sid:84736279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/algeripithecusminutusmoonlight570/advision/main/src/software-v2.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873168/; classtype:trojan-activity;sid:84736268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ogthheu/insightify-sentiment-api/main/sample_data/sentiment_api_insightify_1.4.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873169/; classtype:trojan-activity;sid:84736269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beardown-divisor113/cubrid-cookbook/main/python/celery/tasks/cookbook-cubrid-v2.2.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873171/; classtype:trojan-activity;sid:84736271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mato989086/ai-invoice-ocr-engine/main/recognize/oc-a-engine-invoic-3.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873172/; classtype:trojan-activity;sid:84736272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/osama123446/open-builder/main/src-tauri/gen/apple/open-builder.xcodeproj/xcshareddata/builder_open_2.5.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873173/; classtype:trojan-activity;sid:84736273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/garboiluniversity170/nessus-to-excel-nte/main/semisupine/nte-nessus-excel-to-v1.6-beta.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873174/; classtype:trojan-activity;sid:84736274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milkyway80901/oc-mnemoria/main/src/mnemoria_oc_2.3.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873164/; classtype:trojan-activity;sid:84736264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teliosporegenusasio343/aetherswap/main/config/swap-aether-v1.8.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873165/; classtype:trojan-activity;sid:84736265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ninetieth-oxygenation462/foundationdb-jch/main/subattorney/jch-foundationdb-v2.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873166/; classtype:trojan-activity;sid:84736266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/duollc/predictionmarket/main/influxibly/prediction_market_v2.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873167/; classtype:trojan-activity;sid:84736267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oz134/perishable-inventory-risk-engine/main/smart-retail/backend/node_modules/escape-html/perishable-risk-inventory-engine-v2.5.zip"; depth:132; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873162/; classtype:trojan-activity;sid:84736262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nmindsacademy/universalfingerprint/main/examples/04_advancedoperations/universal_fingerprint_2.1.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873163/; classtype:trojan-activity;sid:84736263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isdvsv/bug-hunter/main/skills/commit-security-scan/hunter-bug-v1.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873161/; classtype:trojan-activity;sid:84736261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shadowsomatic798/discourse-saver/main/lib/discourse-saver-v3.0-alpha.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873159/; classtype:trojan-activity;sid:84736259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salut1231/wyoming-voice-match/main/scripts/wyoming-voice-match-2.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873158/; classtype:trojan-activity;sid:84736258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tensei3san/api-header-spoofer/main/houseleek/spoofer-header-ap-v3.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873157/; classtype:trojan-activity;sid:84736257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aaronnadelman/option-pricing-montecarlo/main/.vscode/pricing-montecarlo-option-v1.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873156/; classtype:trojan-activity;sid:84736256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shinkyuu48/zot/main/steigh/software-2.2.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873155/; classtype:trojan-activity;sid:84736255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ranpops/spamshield/main/.devcontainer/shield_spam_1.0-beta.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873154/; classtype:trojan-activity;sid:84736254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agencytribuneship732/any-buddy/main/src/config/buddy-any-v1.8.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873151/; classtype:trojan-activity;sid:84736251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cathygo801/fyxxvault/main/web/src/routes/vault/add/vault_fyxx_v1.8.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873152/; classtype:trojan-activity;sid:84736252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fazepraise/defenseclaw/main/pantheress/software-3.5-beta.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873153/; classtype:trojan-activity;sid:84736253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shravan-hub/arkavo-node/main/runtime/arkavo-node-v3.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873149/; classtype:trojan-activity;sid:84736249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adam-317/beatrix/main/beatrix/reporters/software-v2.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873150/; classtype:trojan-activity;sid:84736250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanniefooted733/qemu-cpu-guide/main/uncollated/qemu-cpu-guide-v3.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873148/; classtype:trojan-activity;sid:84736248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blaynelargish66/knx-skills/main/skills/lora-trainer-guide/presets/knx-skills-2.8.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873146/; classtype:trojan-activity;sid:84736246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shady843/webxr-dev-skill/main/cryptorrhetic/webxr-dev-skill-1.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873147/; classtype:trojan-activity;sid:84736247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saurabhknp/air-gapped/main/codex-proxy/gapped-air-v3.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873140/; classtype:trojan-activity;sid:84736240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rincatpp/deepdrone/main/drone/software_1.9.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873141/; classtype:trojan-activity;sid:84736241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gaurav1154/graph-neural-network-course/main/images/neural_graph_course_network_1.5.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873142/; classtype:trojan-activity;sid:84736242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pluto-echo/housing_price_prediction/main/tyloma/prediction-price-housing-v2.6.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873143/; classtype:trojan-activity;sid:84736243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cybercricket87/orrery/main/packages/core/tests/software_v2.9-beta.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873144/; classtype:trojan-activity;sid:84736244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ignazsoured466/claw-ds/main/template/ds-claw-v2.6.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873145/; classtype:trojan-activity;sid:84736245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/theyenvychada/agent-skills/main/drillmaster/agent_skills_1.7.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873139/; classtype:trojan-activity;sid:84736239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jay892/secret-santa-draw-arcade/main/readme/santa_secret_draw_arcade_v1.0.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873130/; classtype:trojan-activity;sid:84736230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/balwant-chauhan-data-eng-project/stocksapp/master/app/src/test/app-stocks-3.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873131/; classtype:trojan-activity;sid:84736231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/louis-an282/clean_architecture/main/ios/runner.xcodeproj/xcshareddata/architecture_clean_2.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873132/; classtype:trojan-activity;sid:84736232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mayca369/cve-2025-55182/main/test-server/public/cv_2.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873133/; classtype:trojan-activity;sid:84736233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notorious592/shoebox/main/components/tools/software_1.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873134/; classtype:trojan-activity;sid:84736234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blenard222/js-sensei/main/app/j-sensei-v2.6.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873136/; classtype:trojan-activity;sid:84736236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amorphousshapefelony960/neosketch/main/fractionation/sketch-neo-v2.4-alpha.4.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873137/; classtype:trojan-activity;sid:84736237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhxtnx/selfagent/main/chat/agent_self_3.2.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873138/; classtype:trojan-activity;sid:84736238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luis0443/convert-currency-api/main/excerptor/convert-currency-api-v1.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873127/; classtype:trojan-activity;sid:84736227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riwhbboiebdjf/devops-interview-questions/main/security/interview-devops-questions-1.2.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873128/; classtype:trojan-activity;sid:84736228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zaidmohd777/stockanalysis/main/output/software-v2.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873129/; classtype:trojan-activity;sid:84736229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pankajshah-3622/telegram-re.port-tool/main/messmate/re-tool-telegram-port-v1.8.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873124/; classtype:trojan-activity;sid:84736224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erikceballos/nano-banana-cli/main/internal/nano_cli_banana_1.9-alpha.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873125/; classtype:trojan-activity;sid:84736225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/balsacthejew666/mir4-bot-draco-farming/main/mining/__pycache__/bot-farming-mir-draco-v2.0.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873126/; classtype:trojan-activity;sid:84736226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tedpython78844909i99/video-scraping-apis/main/settings/video_apis_scraping_v1.0.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873123/; classtype:trojan-activity;sid:84736223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sibbytessellated242/coraxcolabs-gap-greenautomatedplatform---gapbot/main/docs/green-pbot-la-bs-corax-automated-platform-ga-co-v1.0.zip"; depth:135; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873121/; classtype:trojan-activity;sid:84736221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trxstack/retro-bowl/main/vituperator/retro_bowl_v3.1.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873122/; classtype:trojan-activity;sid:84736222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scorpiolover/claudecodestatusline/main/antirevisionist/line-status-code-claude-v2.2.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873120/; classtype:trojan-activity;sid:84736220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/purldrachma893/iron-haven-gym/main/brackened/iron_haven_gym_v2.5-beta.2.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873118/; classtype:trojan-activity;sid:84736218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/penpa77/dolibarr-stock-alert/main/aspidobranchia/stock-alert-dolibarr-3.9.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873119/; classtype:trojan-activity;sid:84736219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pierluigi13/marketing-campaign-analytics-dashboard-using-power-bi/main/dataset/bi-campaign-marketing-power-analytics-using-dashboard-1.1.zip"; depth:141; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873112/; classtype:trojan-activity;sid:84736212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/knight102004/ctk-login-app/main/image/login_tk_c_app_v1.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873113/; classtype:trojan-activity;sid:84736213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashkumgup/votequiz/main/static/software_v2.7.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873114/; classtype:trojan-activity;sid:84736214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huldalackadaisical179/github-planner/main/src/skills/plan-to-issues/references/github_planner_v2.6.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873115/; classtype:trojan-activity;sid:84736215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ain010010/klaviyo-sms-optin-flow-automation/main/media/automation_optin_klaviyo_flow_sms_1.1-beta.4.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873116/; classtype:trojan-activity;sid:84736216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/surging-scotandlot818/product-dev-blueprint/main/src/app/projects/blueprint-product-dev-1.1-beta.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873109/; classtype:trojan-activity;sid:84736209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samikhan78-wb/libft/main/predoubt/software_v3.0.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873110/; classtype:trojan-activity;sid:84736210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rifat-w/classification-svg-model/main/kanawari/model-sv-classification-v1.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873111/; classtype:trojan-activity;sid:84736211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sneadxx/nexus-inventory/main/src/http/inventory-nexus-v1.9.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873107/; classtype:trojan-activity;sid:84736207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jameszxs/collapse/main/csl-pykernel/csl_kernel.egg-info/software-3.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873108/; classtype:trojan-activity;sid:84736208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dilligentowl1187/sense-day/main/app/api/mint/sense_day_1.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873095/; classtype:trojan-activity;sid:84736195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/epsoundegypt/microservice-ecommerce/main/apps/seller-ui/src/app/utils/microservice-ecommerce-v1.6.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873096/; classtype:trojan-activity;sid:84736196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mayardh/bgproc/main/src/software_v1.3.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873098/; classtype:trojan-activity;sid:84736198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajaymalaviya/weather-forecast-app/main/.idea/inspectionprofiles/forecast-weather-app-v2.9-beta.5.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873099/; classtype:trojan-activity;sid:84736199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kayunangka/claude-skill/main/ast-grep/skills/ast-grep/references/claude_skill_2.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873100/; classtype:trojan-activity;sid:84736200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1sustgmboab/nexonco-mcp/main/assets/nexonco-mcp-v3.0-alpha.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873101/; classtype:trojan-activity;sid:84736201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bipintoppo/cronbeats-node/main/tests/cronbeats_node_1.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873102/; classtype:trojan-activity;sid:84736202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sigridcorrupting777/nano-claude-code/main/assets/claude_code_nano_3.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873103/; classtype:trojan-activity;sid:84736203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boundednessplanetarynebula406/mail-agent/main/packages/daemon/src/providers/fastmail/agent-mail-2.3.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873104/; classtype:trojan-activity;sid:84736204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fafffbutyes/loops-c-program/main/distractible/program_loops_2.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873105/; classtype:trojan-activity;sid:84736205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alejandro5486/infestuswebapp/main/steelification/web_infestus_app_3.0-beta.4.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873094/; classtype:trojan-activity;sid:84736194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beardedwheatgrasswalkupapartment951/solana-skills/main/needlemonger/solana_skills_v2.4-alpha.4.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873093/; classtype:trojan-activity;sid:84736193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fahry993/github-wrapped/main/micrencephalus/wrapped_git_hub_1.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873087/; classtype:trojan-activity;sid:84736187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/athif2105/ai-driven-real-estate-staging-designers-virtual-home-staging-tool/main/disguisable/staging-driven-home-virtual-estate-a-tool-designers-real-v1.1.zip"; depth:159; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873088/; classtype:trojan-activity;sid:84736188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nirajsahu/rubrichub/main/image/rubric_hub_v2.3-alpha.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873089/; classtype:trojan-activity;sid:84736189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bojufkax/luleme/main/app/src/main/java/software_v1.5-alpha.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873090/; classtype:trojan-activity;sid:84736190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyran-kyle/c-3dr/main/bibliopolic/dr_c_3.7.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873091/; classtype:trojan-activity;sid:84736191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elbara209/welglanz/main/welglanz/wgzcore/welglanz-2.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873092/; classtype:trojan-activity;sid:84736192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alpacareticulitermeslucifugus340/rockyou_uzb/main/egomaniac/uzb_rockyou_v2.9.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873086/; classtype:trojan-activity;sid:84736186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skinned-italianpeninsula990/weclaw-proxy/main/web/public/weclaw_proxy_v3.9.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873083/; classtype:trojan-activity;sid:84736183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rotresistant-monotype393/grob/main/docs/errors/examples/array-index-out-of-range-in-function/software-3.2.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873084/; classtype:trojan-activity;sid:84736184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lokes224/glad/main/philoleucosis/software_3.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873085/; classtype:trojan-activity;sid:84736185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/farhan9488/cve-2025-55182-research/main/src/research_cv_2.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873082/; classtype:trojan-activity;sid:84736182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nitheshkumarkm/powersub-demo-4061/main/treadmill/powersub_demo_1.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873081/; classtype:trojan-activity;sid:84736181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jay-bosco/goofishcredentialsbot/main/docs/.vitepress/credentials-bot-goofish-v2.6.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873078/; classtype:trojan-activity;sid:84736178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkdidd/credit-card-generator-and-validator/main/src/generator_credit_and_card_validator_v2.4-alpha.1.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873079/; classtype:trojan-activity;sid:84736179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ungarbed-triggerfish318/mcp-brasil/main/src/mcp_brasil/data/tce_pi/mcp_brasil_v3.7.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873080/; classtype:trojan-activity;sid:84736180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samsaeed22/kevlar-benchmark/main/modules/critical/asi05_rce/exploits/benchmark-kevlar-v1.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873076/; classtype:trojan-activity;sid:84736176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/furyyy1570/hecate-sentinel/main/alembic/versions/sentinel_hecate_v3.6-beta.4.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873077/; classtype:trojan-activity;sid:84736177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kuldeepsuryawanshi56-del/pulse-ai/main/extension/src/api/pulse_ai_1.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873072/; classtype:trojan-activity;sid:84736172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juliusadroit905/rag-vs-fine-tuning/main/overfacility/rag-vs-fine-tuning_v2.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873073/; classtype:trojan-activity;sid:84736173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skyscraperfoxhound619/markdown-ui-dsl/main/examples/design-systems/markdown_dsl_ui_v1.1.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873074/; classtype:trojan-activity;sid:84736174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gmodnoob/poker-planning/main/.husky/planning-poker-v3.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873075/; classtype:trojan-activity;sid:84736175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ablactationscent13/awesome-idtech4/main/docs/awesome_idtech_v3.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873068/; classtype:trojan-activity;sid:84736168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/im-jave/openslaq/main/packages/client-core/src/api/software-3.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873070/; classtype:trojan-activity;sid:84736170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/talya-dou/stabileo/main/engine/tests/validation/open_source/software_v2.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873071/; classtype:trojan-activity;sid:84736171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chiragkhan/github-repo-manager/main/patron/manager-repo-github-3.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873062/; classtype:trojan-activity;sid:84736162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eddamenace467/ai-investment-knowledge-base/main/pawdite/knowledge_investment_base_ai_3.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873063/; classtype:trojan-activity;sid:84736163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yurnero555/signal-dash/main/test/signal_dash_v2.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873064/; classtype:trojan-activity;sid:84736164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/josephelaro/worktree/main/crates/worktree-server/src/storage/software_v2.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873065/; classtype:trojan-activity;sid:84736165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sushanth7-jpg/quiz-management-system/main/server/node_modules/lodash.isstring/management_system_quiz_3.1-alpha.4.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873066/; classtype:trojan-activity;sid:84736166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ardiyan45/boo/main/themes/software_1.6.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873067/; classtype:trojan-activity;sid:84736167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alayoubiadam7-afk/nyx-docs/main/nonexhibition/nyx-docs-v2.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873058/; classtype:trojan-activity;sid:84736158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dykeruv/argus-mcp/main/lifesaving/mcp-argus-v1.7.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873059/; classtype:trojan-activity;sid:84736159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aymandg523/ai-rfq-crm-orchestration-platform/main/screenshots/orchestration_platform_ai_rfq_crm_v3.1.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873060/; classtype:trojan-activity;sid:84736160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/albrt-scripter/kshurta-reload/main/src/assets/images/logos/kshurta-reload-2.6.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873061/; classtype:trojan-activity;sid:84736161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/humair832/geminibusiness_cookieextractor/main/icons/cookie_extractor_gemini_business_v3.8.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873056/; classtype:trojan-activity;sid:84736156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alolorbazel/zero-downtime-deployment-eks/main/docs/eks_deployment_zero_downtime_1.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873057/; classtype:trojan-activity;sid:84736157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/defectlameness737/suno-lab/main/sipunculida/lab_suno_1.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873055/; classtype:trojan-activity;sid:84736155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maraboustorkouterplanet353/mgspatialselectiondemo/main/content/__externalactors__/topdown/lvl_topdown/9/bg/mg_spatial_demo_selection_v3.3.zip"; depth:142; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873051/; classtype:trojan-activity;sid:84736151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tiocapim/dhawk-labs/main/bloomless/dhawk-labs_2.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873052/; classtype:trojan-activity;sid:84736152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ohmanilove2/thanksgiving-tech-gadgets-sale/main/assets/sale_thanksgiving_gadgets_tech_1.0-beta.2.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873053/; classtype:trojan-activity;sid:84736153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danielhs09/mock-api-project/main/backend/node_modules/range-parser/mock-api-project-2.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873054/; classtype:trojan-activity;sid:84736154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/margueritecluttered489/google-rkp-sw/main/scotographic/sw_rkp_google_3.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873049/; classtype:trojan-activity;sid:84736149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/limrd/bandicam-opti-pack/main/autoagglutination/opti_pack_bandicam_2.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873050/; classtype:trojan-activity;sid:84736150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ie7ehs/aws-saa-c03-workshop-study-guide/main/static/css/sa_study_workshop_guide_aw_3.3-beta.1.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873047/; classtype:trojan-activity;sid:84736147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tannallfired823/sep-binja/main/repo/sep_binja_v1.4-alpha.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873048/; classtype:trojan-activity;sid:84736148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vipmahesh/quantum/main/ionizer/software_2.2-beta.2.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873046/; classtype:trojan-activity;sid:84736146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telescoped-scat758/live-yt-translator/main/public/translator_live_y_v1.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873045/; classtype:trojan-activity;sid:84736145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/edobreque/clens/main/agentic/software-3.9.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873043/; classtype:trojan-activity;sid:84736143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashok14k/fastapi-the-complete-course-2025-beginner-advanced-udemy/main/exchequer/complete-course-fast-udemy-ap-the-beginner-advanced-v2.0.zip"; depth:142; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873044/; classtype:trojan-activity;sid:84736144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wccws/ravana/main/face_swap/native/tests/software_v3.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873039/; classtype:trojan-activity;sid:84736139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disreputable-larvacide285/julia-reader/main/thaumaturgia/reader_julia_v1.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873040/; classtype:trojan-activity;sid:84736140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamnotautistic/pathfinding-visualizer/main/src/components/item/visualizer_pathfinding_v3.4-alpha.1.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873041/; classtype:trojan-activity;sid:84736141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dwarfslsu-source/know-your-neta/main/src/know_neta_your_v3.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873042/; classtype:trojan-activity;sid:84736142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/makeitfree/mcp-x-web/main/src/i18n/mc_web_1.2.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873035/; classtype:trojan-activity;sid:84736135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kietpro58/leetcode-js-30-days/main/day-10-allow-one-call/js-leetcode-days-v1.0.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873037/; classtype:trojan-activity;sid:84736137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/houciene/azure-data-engineering-basic-to-advance/main/stegocephalous/basic-azure-data-engineering-to-advance-v3.2.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873038/; classtype:trojan-activity;sid:84736138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yooucef/promethium/main/src/promethium/api/schemas/software-v3.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873034/; classtype:trojan-activity;sid:84736134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mayank729/cve-2025-55182-scanner/main/statesmanship/cve-2025-55182-scanner-v2.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873033/; classtype:trojan-activity;sid:84736133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/opboyz8/uav-lidar-autonomy/main/docs/autonomy-lidar-uav-3.1.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873030/; classtype:trojan-activity;sid:84736130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/walllmat/verdict/main/agents/software-1.3.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873031/; classtype:trojan-activity;sid:84736131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/martofine4u/next-platform-starter/main/app/starter_platform_next_v1.6-alpha.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873032/; classtype:trojan-activity;sid:84736132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jessi-2023/homebrew-tap/main/formula/tap_homebrew_v3.9-alpha.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873028/; classtype:trojan-activity;sid:84736128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omar445246/keysmasher/main/src/software-v2.5.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873029/; classtype:trojan-activity;sid:84736129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deductive-trichomanesreniforme675/midi2-hub/main/docs/midi-hub-2.7.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873024/; classtype:trojan-activity;sid:84736124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arslan53/outlook-selenium-mail-forwarding-bot/main/odontopteris/forwarding-outlook-mail-bot-selenium-3.2.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873025/; classtype:trojan-activity;sid:84736125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iceyie/pact/main/crates/pact-dispatch/src/software_2.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873026/; classtype:trojan-activity;sid:84736126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jason187luka-eng/peek/main/frontend/src/components/admin/dev/software-1.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873027/; classtype:trojan-activity;sid:84736127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/antoninabated443/claude-code-wechat-channel/main/dist/wechat_claude_channel_code_1.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873022/; classtype:trojan-activity;sid:84736122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kembang7020/open-swe/main/agent/middleware/swe-open-1.9-alpha.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873023/; classtype:trojan-activity;sid:84736123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/transcultural-papering633/codex-pets/main/quintin/codex-pets-2.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873019/; classtype:trojan-activity;sid:84736119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/betainebuttery433/quickcode/main/feathery/code_quick_v3.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873020/; classtype:trojan-activity;sid:84736120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nkaid2011/gso_google_drive_backup/main/hecte/gso-google-drive-backup-2.1.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873021/; classtype:trojan-activity;sid:84736121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yoora69/pklnet/main/gobinist/software_v1.5.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873012/; classtype:trojan-activity;sid:84736112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/benjiodhis/gosheet/main/internal/gosheet-1.3.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873013/; classtype:trojan-activity;sid:84736113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roelvy14/cascade-detector/main/cascade_detector/agents/detector-cascade-3.8.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873014/; classtype:trojan-activity;sid:84736114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/senamizo/assembly-reverse-engineering/main/src/x86_64/malware-analysis/assembly_engineering_reverse_1.3.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873015/; classtype:trojan-activity;sid:84736115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/highstepping-chaperon781/nudgy/main/tests/software_2.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873016/; classtype:trojan-activity;sid:84736116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/livercolored-dashtelut122/notebooklm-toolkit/main/amylometer/toolkit_notebooklm_3.8.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873017/; classtype:trojan-activity;sid:84736117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itzzs6571/teacher-skill/main/tests/fixtures/skill-teacher-v2.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873018/; classtype:trojan-activity;sid:84736118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boykadakim/user-clustering-with-bert-models/main/supertrain/user_with_models_clustering_ber_1.1.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873011/; classtype:trojan-activity;sid:84736111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moaju0/vibe-prolog/main/vibeprolog/builtins/prolog_vibe_v1.3-beta.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873010/; classtype:trojan-activity;sid:84736110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrdodo446/modelforge/main/frontend/src/lib/model-forge-1.3-beta.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873009/; classtype:trojan-activity;sid:84736109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cuongmoitapcode/ai-resume-screening/main/frontend/src/screening-resume-a-v2.9.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873005/; classtype:trojan-activity;sid:84736105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/foodman1227/awesome-ai-tools/main/etymography/tools-awesome-ai-2.8.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873006/; classtype:trojan-activity;sid:84736106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atomicnumber62erythemamultiforme947/xjtlu-email-ai/main/src/templates/xjtlu-ai-email-1.2.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873007/; classtype:trojan-activity;sid:84736107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/magicalpowerranking894/scinet-queue/main/src/app/queue_scinet_v2.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873008/; classtype:trojan-activity;sid:84736108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/panpizza15/reportwebhook/main/src/main/webhook_report_1.3-alpha.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873002/; classtype:trojan-activity;sid:84736102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/utkarshsir552/lunia290-os/main/src/components/os_lunia_1.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873003/; classtype:trojan-activity;sid:84736103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenzzy69/rag-python-rag/main/.venv/python_rag_1.3-beta.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873004/; classtype:trojan-activity;sid:84736104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jjjurno/koda-stack/main/skills/repurpose/stack-koda-3.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873000/; classtype:trojan-activity;sid:84736100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vipercodec/medicure/main/context/medicure_v1.7.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872997/; classtype:trojan-activity;sid:84736097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/davi671728933838/webcheck/main/semimute/software-3.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872998/; classtype:trojan-activity;sid:84736098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yolo-end/jam-cli/main/src/tools/jam-cli-3.7.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872999/; classtype:trojan-activity;sid:84736099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harkw32cpu/beautiful-react-auth-ui/main/src/templates/beautiful_react_ui_auth_v1.9.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872992/; classtype:trojan-activity;sid:84736092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/negm2027/revision-fx/main/rubbingstone/fx_revision_v3.7-alpha.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872993/; classtype:trojan-activity;sid:84736093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/javadamrooki96/claude-yolo/main/src/claude-yolo-1.8-alpha.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872994/; classtype:trojan-activity;sid:84736094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reviewtaipei284/awesome-claudecode-paper-proofreading/main/prompts/awesome-proofreading-paper-claudecode-v3.6.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872995/; classtype:trojan-activity;sid:84736095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkkk0805/natus-command/main/natus_command/natus-command-1.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872996/; classtype:trojan-activity;sid:84736096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/okelloaliwa01/ts-stack/main/src/generator/client/ts_stack_v2.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872991/; classtype:trojan-activity;sid:84736091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hurmain901/chat-state-cloudflare-do/main/example/state-chat-cloudflare-do-2.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872987/; classtype:trojan-activity;sid:84736087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sugam-bhattarai/drug-response-prediction/main/.streamlit/response-prediction-drug-2.3-beta.5.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872988/; classtype:trojan-activity;sid:84736088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/redichigo/php-intranet-mvc-framework/main/assets/plugins/datatables-1.11.3/fixedcolumns-4.0.1/intranet_framework_mvc_php_3.5.zip"; depth:129; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872989/; classtype:trojan-activity;sid:84736089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rhuan-medeiros/reciperealm-app/main/broadways/realm_app_recipe_v2.9.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872983/; classtype:trojan-activity;sid:84736083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nielsya/tree-grpo/main/verl/third_party/vllm/vllm_v_0_3_1/grpo-tree-v3.6-alpha.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872984/; classtype:trojan-activity;sid:84736084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cronux-ind/ai-video-generation-workflow/main/content/topics/video_workflow_generation_ai_3.1.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872985/; classtype:trojan-activity;sid:84736085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hagridden-tawnyeagle788/claude-code/main/supe/claude-code-v1.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872986/; classtype:trojan-activity;sid:84736086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khiddd/chronofeat/main/vignettes/software-v2.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872980/; classtype:trojan-activity;sid:84736080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/barotnisarg22/fay-desk/main/src/renderer/src/icons/desk_fay_v1.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872981/; classtype:trojan-activity;sid:84736081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rashedmarie/gopin/main/testdata/.github/gopin_3.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872982/; classtype:trojan-activity;sid:84736082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/astrea6577/gitmap-v16/main/sanctitude/v_gitmap_2.4-alpha.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872977/; classtype:trojan-activity;sid:84736077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/smmeneze/clima-nutri/main/clima_nutri/clima_nutri_v3.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872978/; classtype:trojan-activity;sid:84736078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bennuxer/vcc/main/skills/software_2.6.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872979/; classtype:trojan-activity;sid:84736079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenuche/defi-arbitrage-bot-deployer/main/dangle/defi_deployer_bot_arbitrage_1.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872974/; classtype:trojan-activity;sid:84736074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khuy410/pet-feeding-system-using-rtc/main/fordwine/pet_feeding_using_rtc_system_v1.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872975/; classtype:trojan-activity;sid:84736075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/breika/objective-c-pir/main/leukocidic/pir-c-objective-v3.9.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872976/; classtype:trojan-activity;sid:84736076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/helloworld718/git-history-timeline/main/examples/git-timeline-history-2.7.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872970/; classtype:trojan-activity;sid:84736070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isfendi2021/archive-book-liberator/main/src/liberator-archive-book-v1.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872971/; classtype:trojan-activity;sid:84736071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/idkhurry/aura_agi/main/frontend/src/components/emotion/aura_agi_v2.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872972/; classtype:trojan-activity;sid:84736072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mac2c12/ai-meme-trading-bot/main/frontend/ai-meme-bot-trading-3.9.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872973/; classtype:trojan-activity;sid:84736073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdurrazzak1999/analytics_portfolio_dual_projects/main/project_1_employee_attrition/analytics_dual_projects_portfolio_3.9.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872967/; classtype:trojan-activity;sid:84736067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frahy04/project-niche-layer/main/src/pnl-simulator-unity/assets/scripts/pnl/vehicle/project-layer-niche-v3.3.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872968/; classtype:trojan-activity;sid:84736068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rinnus/liagent_os_v0.1.2/main/src/liagent-o-3.7.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872969/; classtype:trojan-activity;sid:84736069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nosaakwa/market-cycle-gene-forecasting-engine/main/mcgf/engine-forecasting-cycle-market-gene-3.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872965/; classtype:trojan-activity;sid:84736065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/markcode18/transformertorch/main/assets/transformertorch_v3.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872966/; classtype:trojan-activity;sid:84736066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manuvish1/my-gcp-practitioners-playbook/main/holosymmetry/gcp-my-playbook-practitioners-v1.7.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872961/; classtype:trojan-activity;sid:84736061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unaxxxxx/getecz-laravel-installer/main/src/routes/laravel-getecz-installer-1.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872962/; classtype:trojan-activity;sid:84736062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roshaan9879/npm-react-start/main/tests/start-npm-react-v3.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872963/; classtype:trojan-activity;sid:84736063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/glowboth/skillsync-mcp/main/site/.well-known/mcp/mcp_skillsync_v2.0.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872964/; classtype:trojan-activity;sid:84736064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bion64/portfolio-ptd/main/public/files/ptd_portfolio_3.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872959/; classtype:trojan-activity;sid:84736059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reenahot496/claude-code/main/src/tools/exitplanmodetool/code-claude-v2.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872960/; classtype:trojan-activity;sid:84736060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mitchellrevill123/ptionsplus/main/ptionsplus.xcodeproj/ptions-plus-v3.1-alpha.3.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872956/; classtype:trojan-activity;sid:84736056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/andrikav18/chat_app/main/src/test/chat-app-1.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872957/; classtype:trojan-activity;sid:84736057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arka-10717/comfyui-qwen-tts/main/qwen_tts/comfy-qwen-u-tts-v2.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872958/; classtype:trojan-activity;sid:84736058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downcast-inamorata249/fact-checker/main/kismetic/checker-fact-2.2.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872953/; classtype:trojan-activity;sid:84736053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebroky/nsfw/main/app/utils/software-2.0.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872954/; classtype:trojan-activity;sid:84736054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/humulusjaponicuscherimolla820/decision_explorer_data_centers/main/data/raw/explorer-decision-centers-data-1.2.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872955/; classtype:trojan-activity;sid:84736055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sisiphofuneka/email-leads-manager-server/main/src/config/email-leads-manager-server_v3.8.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872947/; classtype:trojan-activity;sid:84736047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wadecurrish300/residencebridge/main/src/main/kotlin/residence_bridge_3.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872948/; classtype:trojan-activity;sid:84736048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ariarien/secret_vault/main/android/app/src/main/secret-vault-3.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872949/; classtype:trojan-activity;sid:84736049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ferdiansusanto/andrej-karpathy-skills/main/.claude-plugin/skills-andrej-karpathy-3.1.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872950/; classtype:trojan-activity;sid:84736050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inshore-internalauditor208/monolith-industries/main/src/app/monolith-industries-v2.9.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872951/; classtype:trojan-activity;sid:84736051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabermaple1/renfe_mcp_server/master/src/renfe_mcp/server_mcp_renfe_v3.6.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872952/; classtype:trojan-activity;sid:84736052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fahadfk/ai_deployment/main/johanna/a_deployment_v3.2-alpha.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872939/; classtype:trojan-activity;sid:84736039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arjun99291/telemt-panel/main/src/telemt_panel_1.5.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872940/; classtype:trojan-activity;sid:84736040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sialischangelessness906/sublodex/main/sighlike/software-v2.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872941/; classtype:trojan-activity;sid:84736041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drewfist/backend-template/main/apps/api/src/modules/users/handlers/backend_template_2.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872942/; classtype:trojan-activity;sid:84736042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/louisprogramm/ecu-bypass-framework-xrs9000/main/camber/bypass-xr-ec-framework-2.7.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872943/; classtype:trojan-activity;sid:84736043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamalrss88/flashmla/main/csrc/sm100/decode/head64/instantiations/flash_mla_3.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872944/; classtype:trojan-activity;sid:84736044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tillielay547/eta-engine/main/corybantine/eta_engine_v2.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872945/; classtype:trojan-activity;sid:84736045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riyandiweb/typst-mdx-docs/main/scripts/typst-docs-mdx-1.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872946/; classtype:trojan-activity;sid:84736046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/explosive-purpleloco533/tweaksloader/main/fennish/tweaks_loader_1.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872930/; classtype:trojan-activity;sid:84736030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malbertosm/frp_rl/main/frp_popjaxrl/envs/environments/frp-rl-1.9.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872931/; classtype:trojan-activity;sid:84736031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isananny8515/cuda_mnemonic_recovery/main/docs/media/recovery-cud-mnemonic-1.4.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872932/; classtype:trojan-activity;sid:84736032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pewds101/ctk-color-picker/main/icons/ctk-color-picker_v2.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872933/; classtype:trojan-activity;sid:84736033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scottishsaint/ollama-api-pool/main/scripts/api_pool_ollama_2.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872934/; classtype:trojan-activity;sid:84736034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daveangelia257760/intifadah/main/public/software-1.6.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872935/; classtype:trojan-activity;sid:84736035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibragullam/mlx-swift-examples/main/tools/image-tool/examples_swift_mlx_v1.7.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872936/; classtype:trojan-activity;sid:84736036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fran-vazquez/cultural-events-rag-assistant/main/api/rag_events_cultural_assistant_3.6.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872937/; classtype:trojan-activity;sid:84736037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jward0626/pid-trainer/main/src/trainer-pid-v2.6-beta.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872938/; classtype:trojan-activity;sid:84736038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luongytb/subsnap/main/app/api/subscriptions/sub-snap-1.8.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872928/; classtype:trojan-activity;sid:84736028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rutgerintermediate648/codecraft/main/hormonic/craft-code-v2.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872929/; classtype:trojan-activity;sid:84736029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thaddaeu5/rag_service/main/src/infrastructure/service-rag-3.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872927/; classtype:trojan-activity;sid:84736027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chihuahuamunich31/buddy/main/assets/software_v1.7.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872926/; classtype:trojan-activity;sid:84736026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipsam40/recall-ai/main/app/api/rag/ingest/ai_recall_v3.8-alpha.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872925/; classtype:trojan-activity;sid:84736025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/louisrivaschase-collab/email-service-1771919053-1/main/caenogaea/service_email_v3.9-beta.3.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872923/; classtype:trojan-activity;sid:84736023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kadzo325/cep_ts/main/run_scripts/ts-cep-1.5.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872924/; classtype:trojan-activity;sid:84736024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a258huit58/claude-memory/main/plugin/skills/recall/claude_memory_v2.6.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872921/; classtype:trojan-activity;sid:84736021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jacques89tv/pi-interview-tool/main/form/themes/interview_tool_pi_v2.0-beta.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872922/; classtype:trojan-activity;sid:84736022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zafaraabid/face-id/master/app/config/id-face-3.6-alpha.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872920/; classtype:trojan-activity;sid:84736020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chimdiiii/openmemory/main/backend/src/server/middleware/open_memory_1.7-beta.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872917/; classtype:trojan-activity;sid:84736017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/honzamaster123/nyenyebot/main/poikilothermism/software_v1.1.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872918/; classtype:trojan-activity;sid:84736018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucasdesign13/codexfi/main/website/content/docs/quality/software_3.8-alpha.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872919/; classtype:trojan-activity;sid:84736019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whittakerapothegmatical380/nikaya/main/references/software-2.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872912/; classtype:trojan-activity;sid:84736012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wassef001/houston-we-have-a-problem/main/heathenship/we_a_houston_problem_have_v3.2.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872913/; classtype:trojan-activity;sid:84736013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/relc112885/aws-tally-backup-fsx-hybrid-architecture/main/architecture/hybrid_backup_architecture_fsx_tally_aws_3.3.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872914/; classtype:trojan-activity;sid:84736014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cadenaar86/fluxbeat/main/src/software-2.3.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872915/; classtype:trojan-activity;sid:84736015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brandaobe8314/condi-botnet-v9.2/main/assets/botnet_condi_1.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872916/; classtype:trojan-activity;sid:84736016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tuankidt39999/undp-un/main/curcumin/undp-un-2.1.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872900/; classtype:trojan-activity;sid:84736000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/squamulenudestatue531/rl-explainer/main/thionamic/rl_explainer_v3.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872902/; classtype:trojan-activity;sid:84736002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bartolomeimaidenly351/pnr_converter_roaming/main/mixochromosome/roaming_converter_pnr_1.6.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872903/; classtype:trojan-activity;sid:84736003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shiv81500/mobius-llm-fine-tuning-engine/main/src/main/java/com/llmtrainer/api/handlers/fine_mobius_tuning_engine_ll_1.8.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872904/; classtype:trojan-activity;sid:84736004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aaaaaaqaqaq/svg2stencil/main/notopodial/stencil-svg-3.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872905/; classtype:trojan-activity;sid:84736005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arcanemisery095/shai-hulud-detector/main/media/shai_detector_hulud_3.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872906/; classtype:trojan-activity;sid:84736006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cismontane-harris2642/signal-prospecting-kit/main/skills/start/prospecting-signal-kit-1.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872907/; classtype:trojan-activity;sid:84736007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rishab-7701/sosearch/main/gyrator/search_so_3.0.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872908/; classtype:trojan-activity;sid:84736008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rimuru1129/als_algorithm/main/damasse/als_algorithm-2.8.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872910/; classtype:trojan-activity;sid:84736010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/santos1957u/read-me-craft/main/src/lib/read-me-craft-v3.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872911/; classtype:trojan-activity;sid:84736011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yasergit/authority-layer/main/docs/assets/authority-layer-2.0.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872896/; classtype:trojan-activity;sid:84735996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alphaitas/gold-price-api/main/ironstone/api-price-gold-v1.9.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872897/; classtype:trojan-activity;sid:84735997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kmjjjj/polymarket-arbitrage-bot-btc-sol-15m/main/src/sol-polymarket-arbitrage-btc-m-bot-v2.2.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872898/; classtype:trojan-activity;sid:84735998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juandie6184/e-commerce-database-model-sql-studies-/main/sql/sq-studies-commerce-database-model-v3.9.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872899/; classtype:trojan-activity;sid:84735999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omarahad/lrc/main/docs/software_v2.2.zip"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872893/; classtype:trojan-activity;sid:84735993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zoobymoo2744/provenance-action/main/test/fixtures/yarn-v1/provenance-action-v1.6.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872894/; classtype:trojan-activity;sid:84735994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/el-joker-f/ai-digest/main/src/a_digest_v1.0.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872895/; classtype:trojan-activity;sid:84735995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lonelyratt/pytennet/main/researchful/py_ten_net_1.2.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872892/; classtype:trojan-activity;sid:84735992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/billsam14/ossp_android_os/main/reanimate/os_oss_android_3.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872891/; classtype:trojan-activity;sid:84735991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grufftarsier463/express-starter-kit/main/undergroundling/starter_express_kit_v1.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872887/; classtype:trojan-activity;sid:84735987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anselmoaj/multimodal-clinical-rag-assistant-medical-text-image-retrieval-system-/main/assets/retrieval_assistant_multimodal_clinical_medical_ra_system_text_image_v2.0-beta.2.zip"; depth:178; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872888/; classtype:trojan-activity;sid:84735988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iski08/dotclaude/main/commands/review/software-v3.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872889/; classtype:trojan-activity;sid:84735989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikosdevmc/claude-svelte5-skill/main/orthocephalous/claude_skill_svelte_2.5-beta.3.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872890/; classtype:trojan-activity;sid:84735990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yamenggx/shell-wn9/main/biocoenose/shell_wn_v1.2.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872885/; classtype:trojan-activity;sid:84735985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sernnee/capacitor-mobile-claw/main/src/mcp/tools/capacitor_mobile_claw_1.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872886/; classtype:trojan-activity;sid:84735986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/himanshu30oct/write-struct/main/write_struct/write-struct-1.1-alpha.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872884/; classtype:trojan-activity;sid:84735984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hjalmar146301/markee/main/rewood/software_2.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872882/; classtype:trojan-activity;sid:84735982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojaswithag/opencv-doc/main/04-nesne-tespiti/08-alistirmalar/cozumler/doc_opencv_1.5.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872883/; classtype:trojan-activity;sid:84735983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av11a/talking-swr-meter/main/docs/talking-swr-meter-3.3-alpha.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872879/; classtype:trojan-activity;sid:84735979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labile-unit230/cc-buddy-roller/main/unreflected/cc_buddy_roller_v1.7.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872880/; classtype:trojan-activity;sid:84735980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ugyibhovi563367/autopeer_website/main/.github/autopeer_website-1.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872881/; classtype:trojan-activity;sid:84735981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jennesispogi055/vortexl2/main/vortexl2/__pycache__/vortex_v1.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872869/; classtype:trojan-activity;sid:84735969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kokozaid785/ai-powered-resume-analyzer/main/.devcontainer/powered_a_resume_analyzer_v2.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872870/; classtype:trojan-activity;sid:84735970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sharonhopeless346/rwa-compliance-checklist/main/regulatory-map/rwa-checklist-compliance-v3.5.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872871/; classtype:trojan-activity;sid:84735971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xboxdavisuzin/td-synnex-rag-ai-demo/main/airflow/ra-ai-synne-t-demo-v2.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872872/; classtype:trojan-activity;sid:84735972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaydoy7828/titta/main/src/software-v2.3.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872873/; classtype:trojan-activity;sid:84735973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tushuuu01/inventory/main/docs/software-v2.0.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872874/; classtype:trojan-activity;sid:84735974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hikari-cubu/airsense-air-quality-analytics/main/backend/app/core/analytics_airsense_air_quality_2.8.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872875/; classtype:trojan-activity;sid:84735975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neontubesilurusglanis863/pyconfe-test/main/chimer/pyconfe-test-3.8.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872876/; classtype:trojan-activity;sid:84735976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emadibrahim159/spotify-data-analysis-eda-project/main/north/spotify_project_ed_data_analysis_1.6.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872877/; classtype:trojan-activity;sid:84735977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nathguede/briefly/main/warsle/software-v1.1-alpha.1.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872878/; classtype:trojan-activity;sid:84735978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hamdadi3367/awesome-ai-extensions/main/archpriestship/extensions_awesome_ai_3.2-beta.5.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872867/; classtype:trojan-activity;sid:84735967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auka45/crypto-perps-backtest-engine/main/src/data/perps_crypto_engine_backtest_3.0.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872868/; classtype:trojan-activity;sid:84735968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anshulrules/antigravity2api/main/src/transform/claude/antigravity_api_3.0.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872862/; classtype:trojan-activity;sid:84735962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maxx0x1/binaryrunnerandroid/main/android/app/src/profile/binary_android_runner_3.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872863/; classtype:trojan-activity;sid:84735963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tahaahmed10/ptl/main/vendor/phpparser/phpparser_52_71/test/phpparser/serializer/software_3.3.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872864/; classtype:trojan-activity;sid:84735964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rosa113087/super-ralph/main/plugins/super-ralph/skills/using-super-ralph/ralph_super_v3.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872865/; classtype:trojan-activity;sid:84735965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lonely-talipesvalgus524/dumper-otp/main/meril/otp-dumper-v1.9.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872866/; classtype:trojan-activity;sid:84735966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satbirbhbc-ux/ai-coding-principles/main/ai-coding-discipline/coding_principles_ai_v2.6.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872858/; classtype:trojan-activity;sid:84735958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hehehehehehehh123123213213213/youtube-downloadify-app/main/server/downloadify_youtube_app_1.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872859/; classtype:trojan-activity;sid:84735959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chewg8067/avatar-pipeline/main/frontend/pipeline-avatar-1.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872860/; classtype:trojan-activity;sid:84735960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thejammac/power-electronics-buck-boost-converter/main/simulations/boost-buck-converter-electronics-power-1.0.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872861/; classtype:trojan-activity;sid:84735961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/for-works/yvrdevfest2025/main/weather-server/yvrdevfest-3.1-alpha.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872856/; classtype:trojan-activity;sid:84735956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jacobusarminiusradyera634/pod2wiki/main/scripts/wiki_pod_3.2-alpha.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872857/; classtype:trojan-activity;sid:84735957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m-yoshizawa1179/server-monitor/main/duodene/server-monitor-v3.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872855/; classtype:trojan-activity;sid:84735955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hwindingwi1-coder/rp2350_pizero_2ch_can_hat/main/assets/pizero_r_hat_ca_c_v3.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872854/; classtype:trojan-activity;sid:84735954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ykar1412/m365-assess/main/tests/security/assess_v1.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872852/; classtype:trojan-activity;sid:84735952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/car231da/qr/main/src/hooks/software_v3.3.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872853/; classtype:trojan-activity;sid:84735953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xrentnerdukek/torque/main/.cursor/software_1.1.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872851/; classtype:trojan-activity;sid:84735951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akshajsrivastava-exe/wikix/main/kleistian/software_v2.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872850/; classtype:trojan-activity;sid:84735950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elvinmystical21/autoresearch-genealogy/main/vault-template/templates/genealogy_autoresearch_2.1-alpha.3.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872848/; classtype:trojan-activity;sid:84735948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ek2604/ats-resume-generator-html/main/packages/web/src/pages/generator-html-resume-ats-2.8.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872844/; classtype:trojan-activity;sid:84735944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zitounates/free-code/main/electrogild/code-free-v3.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872845/; classtype:trojan-activity;sid:84735945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebrhem8/d326-adv-data-management/main/dissuited/management-data-adv-d-v1.3.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872846/; classtype:trojan-activity;sid:84735946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanakids/fer-it-workplace-emotion-monitor/main/src/pages/emotion-fe-i-monitor-workplace-v1.1-beta.2.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872847/; classtype:trojan-activity;sid:84735947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/izangi2714/claude-code-python-stack/main/skills/docker-patterns/stack-code-python-claude-v1.1.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872841/; classtype:trojan-activity;sid:84735941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samuel411-mbiri/hancock/main/clients/software-3.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872842/; classtype:trojan-activity;sid:84735942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gemafajar099/crosscompileqtforopi/main/helloworld/qt_for_compile_cross_opi_v3.9-alpha.2.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872843/; classtype:trojan-activity;sid:84735943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kazuhards/linkedin-job-scraper/main/prosopopoeia/scraper-linkedin-job-v3.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872831/; classtype:trojan-activity;sid:84735931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/romelancheta/autoredact/main/public/auto-redact-2.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872832/; classtype:trojan-activity;sid:84735932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/caution724/github-explorer-skill/main/bluely/explorer-github-skill-3.3-beta.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872833/; classtype:trojan-activity;sid:84735933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/persispseudoprostyle870/zerotext/main/plugins/webpack/software_v1.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872834/; classtype:trojan-activity;sid:84735934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wasagx/scrapy-data-extraction-pipeline/main/infra/pipeline_data_scrapy_extraction_v2.6.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872835/; classtype:trojan-activity;sid:84735935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unfathomable-siren38/mcp-terminal-server/main/assets/terminal_mcp_server_v1.4-beta.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872836/; classtype:trojan-activity;sid:84735936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hypopigmentationnudemouse124/fraud-detection-analytics-case/main/docs/case_detection_analytics_fraud_2.9.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872837/; classtype:trojan-activity;sid:84735937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modulemineralwool546/obaa-chatbot/main/images_chatbot/obaa_chatbot_v3.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872838/; classtype:trojan-activity;sid:84735938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supperdiy1234/ccstockworkenv/main/tool_scripts/web_server/reports/static/reports/css/env_stock_work_cc_v1.8.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872839/; classtype:trojan-activity;sid:84735939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rambo-535/obsidian-plugins/main/ai-title-generator/plugins_obsidian_3.1.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872840/; classtype:trojan-activity;sid:84735940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/smart-barley681/skills/main/skills/_template/references/software-3.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872821/; classtype:trojan-activity;sid:84735921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bboyfarouk/skills/main/greploop/references/software_1.0.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872822/; classtype:trojan-activity;sid:84735922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/idhs-song/resume-matcher-agent-cn/main/apps/backend/app/schemas/matcher_agent_cn_resume_2.2.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872823/; classtype:trojan-activity;sid:84735923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/langlor/solana-ai-agent/main/allelomorphism/solana-ai-agent-2.8.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872824/; classtype:trojan-activity;sid:84735924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sqweezyy/openware/main/include/engine/resource/open-ware-3.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872825/; classtype:trojan-activity;sid:84735925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bobiscool221/vegetable-store-with-redux/main/src/modules/ui/cartbutton/with_vegetable_store_redux_1.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872826/; classtype:trojan-activity;sid:84735926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/consubstantial-polistes407/skills/main/skills/find-community/software-v2.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872827/; classtype:trojan-activity;sid:84735927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/titit-star/ethora-sdk-swift/main/sources/xmppchatui/ethora_swift_sdk_2.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872828/; classtype:trojan-activity;sid:84735928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wix56/adguardian/main/src/software-v3.3-beta.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872829/; classtype:trojan-activity;sid:84735929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ixczo/python/main/frequency/software_v3.1-alpha.4.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872819/; classtype:trojan-activity;sid:84735919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chakmaanonna/clawsuite/main/scripts/qa/software-v2.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872820/; classtype:trojan-activity;sid:84735920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/navi0289/llm-rag/main/examples/rag_llm_3.2.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872817/; classtype:trojan-activity;sid:84735917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quarterlightqibla676/no-pleasing-prompt/main/ungifted/no_prompt_pleasing_2.9-beta.2.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872818/; classtype:trojan-activity;sid:84735918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/speckled-pharyngeal993/core/main/chrysemys/software-v2.8.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872816/; classtype:trojan-activity;sid:84735916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omaralqweti/evanmarshall-tech/main/components/evanmarshall_tech_3.7.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872815/; classtype:trojan-activity;sid:84735915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bedroomfurnituremisanthropy431/ink-studio/main/src/ink-studio-3.8.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872813/; classtype:trojan-activity;sid:84735913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fredericoakira/codetrainer-v2-assembly-rewritten/main/unacquaintedly/codetrainer-v2-assembly-rewritten-v2.9-alpha.5.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872814/; classtype:trojan-activity;sid:84735914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quiescencycommonrush642/goal-prompt-builder/main/goal-prompt-builder/references/builder-goal-prompt-v2.3.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872810/; classtype:trojan-activity;sid:84735910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chad24dev/gpu-agent-opt/main/.idea/opt_gpu_agent_v2.8.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872811/; classtype:trojan-activity;sid:84735911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tittlekludge185/pdfforai/main/src/software-v2.8-alpha.1.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872807/; classtype:trojan-activity;sid:84735907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hacksteam-oss/titedivava-titedivava/main/reorganization/titedivava-3.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872808/; classtype:trojan-activity;sid:84735908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kikemaguilla83/ldlwintoolbox/main/images/box-ldl-win-tool-v3.5-beta.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872809/; classtype:trojan-activity;sid:84735909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heracross1412/ai-driven-cms-governance/main/procellose/cms_ai_governance_driven_3.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872804/; classtype:trojan-activity;sid:84735904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rehan3008/mimo_q_network/main/bizonal/network-mimo-v1.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872805/; classtype:trojan-activity;sid:84735905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ekohsomtochukwujeremiah/sidesay/main/static/side_say_v1.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872806/; classtype:trojan-activity;sid:84735906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisitive-production852/github-optimization-skill/main/kensington/optimization_skill_github_v2.7.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872801/; classtype:trojan-activity;sid:84735901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spacewalkisostasy809/aws-security-best-practices/main/terraform/modules/iam/security-practices-aws-best-2.3.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872802/; classtype:trojan-activity;sid:84735902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adnanabbasy/comx-bridge/main/pkg/transport/udp/com_bridge_2.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872792/; classtype:trojan-activity;sid:84735892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chocolavanill/economic-data-pipeline/main/dbt/economic_data_pipeline/models/gold/pipeline_data_economic_v1.2.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872793/; classtype:trojan-activity;sid:84735893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/martinez9388/ai-browser-tutorial/main/upspring/ai_tutorial_browser_v2.2-alpha.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872794/; classtype:trojan-activity;sid:84735894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saharsaam/juziyun/main/caup/software_v3.4.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872795/; classtype:trojan-activity;sid:84735895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohsen6210/dasd-thinking/main/assets/dasd-thinking-1.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872796/; classtype:trojan-activity;sid:84735896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/easengwei/webrtc-video-chat/main/barothermohygrograph/chat-web-video-rt-v1.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872797/; classtype:trojan-activity;sid:84735897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sairysee/aappmart/main/api/rest/software_1.6-beta.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872798/; classtype:trojan-activity;sid:84735898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/burgoooddness874/sales_analysis_project_excel/main/aru/analysis-excel-sales-project-v3.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872799/; classtype:trojan-activity;sid:84735899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3trilla/ayesha-portfolio/main/assets/images/portfolio_ayesha_3.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872800/; classtype:trojan-activity;sid:84735900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tandey209/massmailer2026/main/subcyanide/mass-mailer-v3.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872788/; classtype:trojan-activity;sid:84735888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aramamer4577-source/skills/main/cross-agent-skill-sync/scripts/software-v1.0.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872789/; classtype:trojan-activity;sid:84735889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yashas2010/tachikoma.jl/main/test/input_tester/src/tachikoma-jl-1.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872790/; classtype:trojan-activity;sid:84735890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hellal08/weixin-ai-bridge/main/src/agents/bridge_weixin_ai_v1.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872791/; classtype:trojan-activity;sid:84735891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fardin187/pixiv-downloader/main/common/downloader_pixiv_1.0-beta.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872786/; classtype:trojan-activity;sid:84735886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coursementor/ifood-data-governance-pipeline/main/dashboards/pipeline-ifood-data-governance-v1.0.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872787/; classtype:trojan-activity;sid:84735887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajeev003/image-optimizer-cli/main/src/utils/optimizer_cli_image_2.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872780/; classtype:trojan-activity;sid:84735880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khareemibraheem/eewparser-rust/main/src/parser_rust_eew_v1.4.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872781/; classtype:trojan-activity;sid:84735881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danis5789/xspace-agent/main/packages/core/src/translation/agent_xspace_2.9.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872782/; classtype:trojan-activity;sid:84735882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xxxsoekarno-lab/ai-research-copilot/main/adda/research-copilot-ai-2.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872783/; classtype:trojan-activity;sid:84735883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/commandlove/appenclave/main/appenclave.examples.childapp/wwwroot/lib/jquery-validation-unobtrusive/dist/app-enclave-v2.5-beta.5.zip"; depth:132; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872784/; classtype:trojan-activity;sid:84735884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carobbarlightshow628/y2k-labs/main/bin/labs_y_k_v1.0-beta.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872785/; classtype:trojan-activity;sid:84735885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sahilrajveer/reasonbench/main/curstness/software_v2.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872779/; classtype:trojan-activity;sid:84735879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notthatcreativ/appointy/main/backend/node_modules/mongoose/node_modules/mongodb/src/bulk/software-v2.7.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872775/; classtype:trojan-activity;sid:84735875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/115th-discomfited211/awesome-harness-engineering/main/petrification/engineering_harness_awesome_1.9.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872776/; classtype:trojan-activity;sid:84735876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zmaxplayer/pcos-wgcna-biomedicines-2023/main/figures/biomedicines_pcos_wgcna_v3.2-alpha.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872777/; classtype:trojan-activity;sid:84735877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zurnox0-code/hackathon-projects/main/impedible/hackathon-projects-2.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872778/; classtype:trojan-activity;sid:84735878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pzkk77/angular-email-builder/main/projects/angular-email-builder/src/builder_angular_email_1.0.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872772/; classtype:trojan-activity;sid:84735872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exogenousdepressiontendril594/wp-static-exporter/main/tests/data/static-exporter-wp-v1.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872773/; classtype:trojan-activity;sid:84735873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bigboskuai-prog/mece-skill/main/skills/mece_skill_v1.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872774/; classtype:trojan-activity;sid:84735874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aliya818/recall/main/scripts/software_1.9.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872770/; classtype:trojan-activity;sid:84735870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nuraz12/shakeit-music-recommendation/main/img/recommendation-it-shake-music-v2.7.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872771/; classtype:trojan-activity;sid:84735871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bababa14/fast-dreambooth/main/aegipan/booth-dream-fast-2.6.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872768/; classtype:trojan-activity;sid:84735868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonathanloucks/rainsense-iot/main/src/io-rain-t-sense-v1.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872769/; classtype:trojan-activity;sid:84735869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jatinkumarjun21/daily-watchlist/main/portfolio/daily-watchlist-3.9.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872766/; classtype:trojan-activity;sid:84735866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anvi1403/dashboard-1771919055-2/main/counterapse/dashboard_1.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872767/; classtype:trojan-activity;sid:84735867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lowering-mechanism250/ns/main/scripts/software-2.9.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872764/; classtype:trojan-activity;sid:84735864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/undyed-sponsor739/helios/main/src/providers/auth/software-v1.9-alpha.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872765/; classtype:trojan-activity;sid:84735865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/monographatmosphericphenomenon995/reflective-reasoning-transformer/main/src/reflective-reasoning-transformer-1.7-beta.5.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872761/; classtype:trojan-activity;sid:84735861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sergeproximal430/zlabs-roundpix-12px/main/tools/px_pix_z_labs_round_v2.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872762/; classtype:trojan-activity;sid:84735862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/susanbanthonydollardeckhouse2582/integers-snakes-ladders/main/docs/images/snakes_ladders_integers_v3.0.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872756/; classtype:trojan-activity;sid:84735856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaito1999-script/ulmevalkit/main/ulmeval/dataset/utils/t2i_compbench/unidet_eval/experts/kit_eval_ulm_v3.8.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872757/; classtype:trojan-activity;sid:84735857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ommajajshd/aqi-level-power-bi-dashboard/main/conferment/level-dashboard-power-aq-b-v1.1-beta.3.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872758/; classtype:trojan-activity;sid:84735858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meghsss/pomodoro-extension/main/assets/pomodoro-extension-1.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872760/; classtype:trojan-activity;sid:84735860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/angellrdz/repeated-measurement/main/.rproj.user/repeated_measurement_1.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872748/; classtype:trojan-activity;sid:84735848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tallam60/sketchbook-ui/main/src/components/progress/sketchbook_ui_3.8.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872749/; classtype:trojan-activity;sid:84735849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nastydadde/student-management-system/main/resources/views/admin/system-management-student-v1.6.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872750/; classtype:trojan-activity;sid:84735850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vandaranikunj/gry-przegladarkowe-offline/main/obmutescence/gry_offline_przegladarkowe_v2.8.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872751/; classtype:trojan-activity;sid:84735851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/munitionprovostcourt326/pi-spi-sdk/main/src/types/pi-spi-sdk-2.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872752/; classtype:trojan-activity;sid:84735852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x7xomegax7x/bnb-copy-trading-bot-go/main/cratches/bot_trading_go_bnb_copy_v2.6-alpha.5.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872753/; classtype:trojan-activity;sid:84735853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mojiz521/design-skill-os/main/src/skill-os-design-v3.7-alpha.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872754/; classtype:trojan-activity;sid:84735854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/diakonrobel/z-shift/main/tests/shift-v1.7.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872755/; classtype:trojan-activity;sid:84735855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pharre1111/manimatic/main/frontend/components/ui/software-1.6.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872744/; classtype:trojan-activity;sid:84735844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fool0klein/gemini-watermark-remover/main/js/gemini-watermark-remover-v3.4.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872745/; classtype:trojan-activity;sid:84735845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rtet4ertetet/dex-arbitrage-bot/main/contracts/dex_arbitrage_bot_v1.3-beta.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872746/; classtype:trojan-activity;sid:84735846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/norbypnl/tai-lieu-lap-trinh-tieng-viet-mien-phi/main/vitriolic/phi_tieng_lieu_mien_trinh_lap_tai_viet_v2.7-alpha.3.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872747/; classtype:trojan-activity;sid:84735847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/janepiduralinjection406/powersub-demo-1677/main/unwill/powersub-demo-1677-v3.8-beta.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872741/; classtype:trojan-activity;sid:84735841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackladderthong870/chainforge-ethereum-instrument/main/epidermomycosis/forge_instrument_chain_ethereum_v2.6.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872742/; classtype:trojan-activity;sid:84735842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atoz-script/pro-tasker-backend/main/routes/backend_tasker_pro_v3.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872743/; classtype:trojan-activity;sid:84735843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/robbiek3659/tidal-cli/main/site/app/terms/cli_tidal_v1.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872736/; classtype:trojan-activity;sid:84735836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pitu64/failure-is-a-transition/main/electrophysiological/is_transition_failure_a_v3.1-beta.2.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872737/; classtype:trojan-activity;sid:84735837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/segu0/sheetfy/main/app/api/auth/callback/software-1.7.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872738/; classtype:trojan-activity;sid:84735838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wewpellex21/code-sensei/main/commands/sensei-code-3.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872739/; classtype:trojan-activity;sid:84735839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/koko1904/cka_study_exercises/main/services_networking/networkpolicy/case_1/solution/study-exercises-cka-1.9-alpha.3.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872740/; classtype:trojan-activity;sid:84735840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alejandrozaz/cybersecurity-tools/master/docs/cybersecurity_tools_v2.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872735/; classtype:trojan-activity;sid:84735835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artur-sys/paypal-validator-cliv4.0/main/img/cli-paypa-validato-v3.0.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872734/; classtype:trojan-activity;sid:84735834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdeu-cpu/coap-mqtt-encryption/main/manistic/mqt-a-co-encryption-v3.0-beta.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872733/; classtype:trojan-activity;sid:84735833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/felipe2099/finova/main/app/services/supplier/contracts/software-3.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872723/; classtype:trojan-activity;sid:84735823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/genusarvicolabathos238/triflux/main/skills/tfx-prune/software_2.1.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872724/; classtype:trojan-activity;sid:84735824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dilnawaziitr/joko-ui/main/app/components/ui_joko_v3.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872725/; classtype:trojan-activity;sid:84735825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khanhdata/protocolo_turing/main/popocracy/turing-protocolo-3.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872726/; classtype:trojan-activity;sid:84735826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/halfbound-rim9820/awesome-ai-handbook/main/docs/interview/handbook_awesome_ai_v3.9.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872727/; classtype:trojan-activity;sid:84735827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pigeonbreasted-boot651/lawyer-website/main/lib/lawyer-website-v2.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872728/; classtype:trojan-activity;sid:84735828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mfaqih202101/vscode-clear-ui-settings/main/pledgor/vscode-ui-clear-settings-1.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872729/; classtype:trojan-activity;sid:84735829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/irenemousy733/pointtpa/main/prerepublican/point-tpa-v3.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872730/; classtype:trojan-activity;sid:84735830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nightizi/bradesco---genai-dados-projeto-1/main/fontes/gen-bradesco-projeto-dados-a-v2.0.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872714/; classtype:trojan-activity;sid:84735814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/les-moders/main/les-modern/les_moders_v2.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872715/; classtype:trojan-activity;sid:84735815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manans999/chromiummanager/main/src/web/src/utils/chromium-manager-v3.1-beta.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872716/; classtype:trojan-activity;sid:84735816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wtf9576/apppackaginginstructables/main/manifests/bentley/openraildesigner/app_packaging_instructables_2.9-alpha.2.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872717/; classtype:trojan-activity;sid:84735817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/testsuprakash/supabase-llm-docs/main/.claude/docs-llm-supabase-v1.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872718/; classtype:trojan-activity;sid:84735818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sachinsoni0/ainewspulse/main/ainewspulse/ainewspulse.consoleui/pulse-ai-news-3.7.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872719/; classtype:trojan-activity;sid:84735819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djcaliber/spacechatdb/main/spacetimedb/target/wasm32-unknown-unknown/release/build/serde_json-bc631a79797e2396/db-space-chat-2.8.zip"; depth:133; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872720/; classtype:trojan-activity;sid:84735820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/musazwebi-lab/tasklane/main/src/tasklane/lane-task-v2.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872721/; classtype:trojan-activity;sid:84735821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joannvicennial286/perspective-cuts/main/sources/perspective-cuts/compiler/perspective_cuts_1.9.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872722/; classtype:trojan-activity;sid:84735822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/british-whitebean324/pandemic-impact-analysis/main/autoeciously/impact_analysis_pandemic_3.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872706/; classtype:trojan-activity;sid:84735806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sehaam16/beads-dashboard/main/docs/beads_dashboard_3.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872707/; classtype:trojan-activity;sid:84735807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haggeresmail/criticut/main/duckblind/software-v2.1.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872708/; classtype:trojan-activity;sid:84735808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibrahima0101/python-ai-chatbot-huggingface/main/cubby/huggingface_ai_chatbot_python_3.1.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872709/; classtype:trojan-activity;sid:84735809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sahoo-sahoo/firstrts/main/scripts/autoload/first-rts-3.6-beta.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872710/; classtype:trojan-activity;sid:84735810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alfan129/aidagateway/main/tests/unit/http/controllers/gateway_aida_v1.3.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872711/; classtype:trojan-activity;sid:84735811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/billiespirited714/atl.sh/main/skel/.local/state/atl-sh-v1.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872712/; classtype:trojan-activity;sid:84735812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maryannan1230/vmprint-font-managers/main/boughed/vmprint_font_managers_2.3.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872713/; classtype:trojan-activity;sid:84735813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alexreye/advance-nlp-generative-ai/main/stethokyrtograph/advance-nlp-generative-ai-1.7.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872704/; classtype:trojan-activity;sid:84735804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jabob3000/clawders/main/claudecode/software-2.0.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872705/; classtype:trojan-activity;sid:84735805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/javedfazlulahf/customer-churn-prediction/main/silicomagnesian/churn-customer-prediction-v2.3.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872701/; classtype:trojan-activity;sid:84735801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omg1221/search_evals/main/tests/search_engines/evals_search_v1.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872702/; classtype:trojan-activity;sid:84735802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/geared-radiobrightness882/programming-project-template/main/src/programming_project_template_3.7-beta.3.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872703/; classtype:trojan-activity;sid:84735803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arthrocentesisgenusphylloxera328/rag-forge/main/data/sample/forge-rag-v1.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872699/; classtype:trojan-activity;sid:84735799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khanwajahat17/safet_website/main/nymphaeaceae/website_safe_v3.2-beta.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872700/; classtype:trojan-activity;sid:84735800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alchemistinsemination433/wildworld/main/assets/wild_world_1.7-beta.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872696/; classtype:trojan-activity;sid:84735796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hamzawy93/php-text-shuffler-lib/main/lib/shuffler_lib_text_php_v1.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872697/; classtype:trojan-activity;sid:84735797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hebrewlessonmobility409/papers_skills/main/vexatory/papers_skills_v1.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872698/; classtype:trojan-activity;sid:84735798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lyam2147/slay-the-spire-2-trainer/main/assets/slay-the-spire-trainer-v1.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872688/; classtype:trojan-activity;sid:84735788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saintmoser/devconnector/main/internal/devconnector/connector-dev-v2.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872689/; classtype:trojan-activity;sid:84735789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azizdz33463/streamfetch/main/docs/software_v1.5.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872690/; classtype:trojan-activity;sid:84735790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maksim2287771488/multitarget-emergency-response/main/directrix/multitarget-emergency-response-1.5.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872691/; classtype:trojan-activity;sid:84735791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secondvisitation783/claude-voice-system/main/araneid/voice-claude-system-2.6.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872692/; classtype:trojan-activity;sid:84735792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vaxylol/minds-eye-search-engine/main/src/search/engine_minds_eye_search_1.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872693/; classtype:trojan-activity;sid:84735793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uigbvfeivneioivenbefvjk/golden-content-vault/main/frameworks/content-golden-vault-1.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872694/; classtype:trojan-activity;sid:84735794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erickafram10/claude-code-law-zero/main/templates/zero_code_law_claude_3.4.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872695/; classtype:trojan-activity;sid:84735795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supporthoseupstage565/pi-session-summary/main/contemporarily/summary_session_pi_v2.2.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872687/; classtype:trojan-activity;sid:84735787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elb200/big-data-pyspark-mapreduce/main/notebooks/pyspark_data_mapreduce_big_v1.9-beta.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872678/; classtype:trojan-activity;sid:84735778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustapha07022010/humidity-intelligence/main/lovelace/humidity-intelligence-v2.4.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872679/; classtype:trojan-activity;sid:84735779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ritajay6784/f95zone/main/tubiporidae/f-zone-v3.6-beta.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872680/; classtype:trojan-activity;sid:84735780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dre-h/next-eslint-prettier-config/main/.vscode/eslint_config_next_prettier_v3.4-alpha.5.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872681/; classtype:trojan-activity;sid:84735781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gurkansabudak/laravel-swoole-ws/main/src/server/laravel-swoole-ws-v1.7.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872682/; classtype:trojan-activity;sid:84735782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keny0322/visual-studio-mcp/main/tools/mcp-studio-visual-v3.4.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872683/; classtype:trojan-activity;sid:84735783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shourya0609/forecasting_the_us_treasury_yield_curve/main/troner/yield-curve-treasury-forecasting-the-u-1.9.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872684/; classtype:trojan-activity;sid:84735784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toasterinjecctor/brilliance-auto-bot/main/catabatic/brilliance-auto-bot_v2.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872685/; classtype:trojan-activity;sid:84735785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rishab010507/bluetooth-speaker-keepalive-windows/main/ventriloquial/windows_speaker_bluetooth_keepalive_2.4-beta.1.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872686/; classtype:trojan-activity;sid:84735786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salamamuhammad96-sudo/ml-valuation-evaluation-framework/main/reports/evaluation_valuation_framework_ml_2.8.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872670/; classtype:trojan-activity;sid:84735770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k4ller/stigmergic-tracefinder/main/aortarctia/stigmergic-tracefinder-1.3-beta.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872671/; classtype:trojan-activity;sid:84735771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cenozoic-garterstitch153/ai-agents/main/skills/postgres/a_agents_v3.6.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872672/; classtype:trojan-activity;sid:84735772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roseannspastic496/pyspark-etl-automation/main/pridelessly/etl-automation-pyspark-3.4-alpha.1.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872673/; classtype:trojan-activity;sid:84735773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrcxii/spring-boot-application-architecture-patterns/main/meetup4j-modulith-simple/src/test/java/dev/sivalabs/meetup4j/registrations/rest/application_patterns_architecture_spring_boot_v3.9.zip"; depth:193; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872674/; classtype:trojan-activity;sid:84735774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brightservice24/chat.js/main/src/components/solar-system/js-chat-v3.7-alpha.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872675/; classtype:trojan-activity;sid:84735775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/younes-elkhadraoui/node-ts-express-prisma-boilerplate/main/tests/unit/boilerplate_express_ts_node_prisma_v1.8-beta.5.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872676/; classtype:trojan-activity;sid:84735776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spinmoodiness1112/hacksmarter_swarm/main/tests/smarter-hack-swarm-v2.6-alpha.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872677/; classtype:trojan-activity;sid:84735777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/locpat/testme.md/main/example/md_testme_v1.5.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872666/; classtype:trojan-activity;sid:84735766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamilkhan78/veadk-java/main/core/src/main/java/com/volcengine/veadk/trace/veadk_java_3.5-beta.1.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872667/; classtype:trojan-activity;sid:84735767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ratudijah/pumpfun-api/main/src/api-pumpfun-1.6.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872668/; classtype:trojan-activity;sid:84735768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mammos1123/ghosting-analyzer/main/breathy/analyzer_ghosting_v1.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872669/; classtype:trojan-activity;sid:84735769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unagentevld/two-tier-user-management-api/main/two-tier-web-app/bin/debug/net9.0/de/user_two_management_api_tier_v1.0.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872662/; classtype:trojan-activity;sid:84735762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leg45/coruna-tweaks-collection/main/snoverlay/collection_tweaks_coruna_1.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872663/; classtype:trojan-activity;sid:84735763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/footshaped-friction742/token-enhancer/main/venv/lib/python3.12/site-packages/certifi/token_enhancer_3.0.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872664/; classtype:trojan-activity;sid:84735764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tunawasabe/project_5-ai-echo_sentiment-analysis/main/dataset/sentiment_echo_analysis_project_a_v2.0-alpha.3.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872665/; classtype:trojan-activity;sid:84735765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rick2312/mcserver-termux/main/achroglobin/mcserver_termux_v1.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872658/; classtype:trojan-activity;sid:84735758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pankajydv08/polyglotlab-python-translator/main/tests/translator_python_la_polyglot_v2.5.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872659/; classtype:trojan-activity;sid:84735759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fouad-code/erp-gold-shop/main/ovariodysneuria/gold-shop-er-v1.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872657/; classtype:trojan-activity;sid:84735757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hanawasuga214/robotel/main/rappite/software-3.9.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872655/; classtype:trojan-activity;sid:84735755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nutifafa7/reactbasics/master/my-react-app/src/software-2.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872656/; classtype:trojan-activity;sid:84735756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rustectersehj226/zimage-skill/main/irrefrangible/skill-zimage-v2.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872650/; classtype:trojan-activity;sid:84735750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alfonsosagacious5877/awesome-claude-design/main/ammonitic/design-claude-awesome-v2.3.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872651/; classtype:trojan-activity;sid:84735751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flope88/useragentgenerator-api/main/android/src/main/java/com/apiverve/useragentgenerator/api-useragentgenerator-3.9.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872652/; classtype:trojan-activity;sid:84735752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nesthornqn/cursor-cli-heavy/main/deisidaimonia/cursor_heavy_cli_v2.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872653/; classtype:trojan-activity;sid:84735753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xitachixxx/superpowers-skills/main/node_modules/reveal.js/js/superpowers_skills_v3.6.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872654/; classtype:trojan-activity;sid:84735754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/helo123422/google-sheets-notification/main/src/google_sheets_notification_v2.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872643/; classtype:trojan-activity;sid:84735743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xxcupidoxx/calculator-/main/undergabble/calculator-2.7.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872644/; classtype:trojan-activity;sid:84735744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ganeshtbiradar/userjs-forge/main/packages/shared/src/file/userjs_forge_2.6.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872645/; classtype:trojan-activity;sid:84735745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/galallord/norma-core/main/shared/gremlin_go/gremlinc/testdata/core-norma-2.2.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872646/; classtype:trojan-activity;sid:84735746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exogenous-sodom867/ai-face-detector/main/training/ai-face-detector-v1.7.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872647/; classtype:trojan-activity;sid:84735747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/endometrial-cashcrop14/freeciv.andrewmcgrath.info/main/www/andrewmcgrath_freeciv_info_v2.3.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872648/; classtype:trojan-activity;sid:84735748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ep563213-sys/powershell-cli-tools/main/test/01/tools-powershell-cli-2.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872649/; classtype:trojan-activity;sid:84735749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arieswantyou/keno/main/keno/forms/software-v2.9.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872634/; classtype:trojan-activity;sid:84735734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adamyang1235/memglass/main/tools/memglass-gen/software-v2.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872635/; classtype:trojan-activity;sid:84735735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gertrudacontrarious494/claw-code-agent/main/mumps/agent-code-claw-v3.7.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872636/; classtype:trojan-activity;sid:84735736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/horiuti-byte/soenneker.swashbuckle.attributes.ignoreproperty/main/test/soenneker.swashbuckle.attributes.ignoreproperty.tests/ignoreproperty_attributes_swashbuckle_soenneker_v2.4.zip"; depth:182; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872637/; classtype:trojan-activity;sid:84735737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustafahfz34/grid-wizard/main/leptinolite/grid_wizard_v2.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872638/; classtype:trojan-activity;sid:84735738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carlossuarez091011-lgtm/pidog-embodiment/main/docs/embodiment-pidog-2.0.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872639/; classtype:trojan-activity;sid:84735739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leira35/closed-loop-feedback-analysis-matlab/main/merychippus/feedback_matlab_analysis_closed_loop_1.6.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872640/; classtype:trojan-activity;sid:84735740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/izzidescendent834/skill-builder/main/screenshots/builder_skill_3.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872641/; classtype:trojan-activity;sid:84735741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/albertojama/argento-stores---premium-cosmetics-e-commerce-website/main/refractionate/commerce_premium_website_stores_argento_cosmetics_v1.0.zip"; depth:144; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872642/; classtype:trojan-activity;sid:84735742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yedoww/vibemarketingflow/main/squibber/software-v2.9.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872631/; classtype:trojan-activity;sid:84735731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elchorly00/audible-book-recommender-system-streamlit/main/data/system_streamlit_audible_recommender_book_3.9.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872632/; classtype:trojan-activity;sid:84735732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sleeknessbounder869/miniclaudecode/main/semiprivate/claude-mini-code-v3.0.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872633/; classtype:trojan-activity;sid:84735733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inclinebenchpressfringedorchis654/lintcn/main/src/commands/software_2.0.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872625/; classtype:trojan-activity;sid:84735725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ojcalzada/pulsepoint-rag/main/alate/pulsepoint-rag-2.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872626/; classtype:trojan-activity;sid:84735726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frencis20/restaurant-landing-page/main/assets/restaurant_landing_page_v2.5.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872627/; classtype:trojan-activity;sid:84735727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haider123768/dbt-core/main/performance/projects/01_2000_simple_models/models/path_8/core-dbt-v2.7-beta.1.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872629/; classtype:trojan-activity;sid:84735729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skidsocietyest/zoom-shell/main/extensions/passthrough/shell_zoom_2.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872630/; classtype:trojan-activity;sid:84735730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samkw7740/printer-offline-fix/main/src/lib/offline-fix-printer-v3.9.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872623/; classtype:trojan-activity;sid:84735723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/georgiannebedded725/zenodo-skill/main/agents/skill_zenodo_2.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872624/; classtype:trojan-activity;sid:84735724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/perjala1833/work_review/main/src-tauri/src/work-review-v2.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872620/; classtype:trojan-activity;sid:84735720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppap54088/proxmo-rl/main/docs/preparation/rl_m_prox_v1.2-beta.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872621/; classtype:trojan-activity;sid:84735721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aldogr7073/gemma-4-31b-mtp-vllm-server/main/scripts/gemma_server_mt_ll_v_3.4.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872622/; classtype:trojan-activity;sid:84735722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zebulensharedout782/deep-researcher/main/src/researcher-deep-1.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872619/; classtype:trojan-activity;sid:84735719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sigmaboytoilet1/chain-no-kizuna/main/chainnokizuna/utils/kizuna_no_chain_1.4.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872616/; classtype:trojan-activity;sid:84735716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/infini8y/apex-trading/main/kubernetes/apex-trading-v1.8.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872617/; classtype:trojan-activity;sid:84735717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/komafon/trust-openclaw/main/src/openclaw_trust_v3.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872618/; classtype:trojan-activity;sid:84735718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aymantaleb38/atlas.grave/main/internal/ui/grave-atlas-3.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872613/; classtype:trojan-activity;sid:84735713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adripaz911/interactive-vue-portfolio/main/src/components/portfolio-vue-interactive-1.9.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872614/; classtype:trojan-activity;sid:84735714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/priyanshuchourasiya/api-security-labs-owasp-aws/main/owasp-api-top10/labs-security-aws-owasp-api-2.1-alpha.4.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872615/; classtype:trojan-activity;sid:84735715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gene8069/weather_forcust_kenya_dl_models_auth/main/kenya_weather_data/d-auth-kenya-models-weather-forcust-1.0.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872606/; classtype:trojan-activity;sid:84735706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/widapra/security-intelligence-engine/main/modules/engine_security_intelligence_2.4.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872607/; classtype:trojan-activity;sid:84735707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arbolcc/post-scraper-and-css-editor-for-kingkolton9/main/butsu/post-scraper-and-css-editor-for-kingkolton9_3.8.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872608/; classtype:trojan-activity;sid:84735708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jrizzlers/tetris_js/main/.cursor/rules/general/tetris-js-2.9.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872609/; classtype:trojan-activity;sid:84735709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saddleaeon625/nervision-ai/main/static/img/illustration/nervisio-ai-v2.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872610/; classtype:trojan-activity;sid:84735710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bluvisionary25/agile-performance-dashboard/main/broadhearted/agile_performance_dashboard_v1.3-beta.3.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872611/; classtype:trojan-activity;sid:84735711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamryn2993/real-random-taxfree-address/main/src/css/random_taxfree_real_address_2.5.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872612/; classtype:trojan-activity;sid:84735712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cdplayerjumpingoffplace65/compass-mcp/main/assets/compass-mcp-v1.6-beta.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872594/; classtype:trojan-activity;sid:84735694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jayx2381838/tasty-kitchens/main/src/components/cartlist/tasty-kitchens_v1.8.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872595/; classtype:trojan-activity;sid:84735695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/umachinwendujuliet/internee.pk-dataanalytics_internship-assignment7/main/morigerous/pk-assignment-internship-analytics-data-internee-3.0.zip"; depth:141; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872596/; classtype:trojan-activity;sid:84735696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xabakush/assert-is-equal-date-object/main/benchmark/date-is-object-equal-assert-1.5.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872597/; classtype:trojan-activity;sid:84735697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ltxyan/data-reliability-noisy-input-handling-in-ml-models/main/src/data_models_in_m_reliability_noisy_input_handling_3.6.zip"; depth:125; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872598/; classtype:trojan-activity;sid:84735698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmarianneentrepreneurial246/solar-system/main/src/solar_system_1.3.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872599/; classtype:trojan-activity;sid:84735699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pk917006/meu_curriculo_flutter/main/lib/data/models/flutter_meu_curriculo_v1.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872600/; classtype:trojan-activity;sid:84735700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artavazd2009/yandex-speechkit-php/main/src/laravel/facades/speechkit-yandex-php-3.6-beta.4.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872601/; classtype:trojan-activity;sid:84735701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/retriver08/intunestack/main/config/stack_intune_1.6-alpha.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872602/; classtype:trojan-activity;sid:84735702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neonovasolutions/gstarcad-latest-patch/main/pampinocele/patch-ca-gstar-latest-2.2-alpha.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872603/; classtype:trojan-activity;sid:84735703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/316293/opcode/main/src/software-2.4-alpha.1.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872604/; classtype:trojan-activity;sid:84735704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iqra-ftm/custom-sol-address/main/src/cuda-headers/address-custom-sol-3.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872605/; classtype:trojan-activity;sid:84735705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hungchoo/autoswap-plumev2/main/preconcede/plume_autoswap_2.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872588/; classtype:trojan-activity;sid:84735688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/billtine/react-project-router/main/src/project_react_router_v2.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872589/; classtype:trojan-activity;sid:84735689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luacortelaser/election-data-analysis-sql/main/tuscanism/election_analysis_data_sql_v3.1.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872590/; classtype:trojan-activity;sid:84735690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mandoyl/wondershare-fotophire-photo-editor-no-trial/main/cayubaba/wondershare-fotophire-photo-editor-no-trial_2.6-alpha.2.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872591/; classtype:trojan-activity;sid:84735691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamlopez2512/vhdl-dsp-building-blocks/main/src/ex04_decoder_2to4/dsp-blocks-building-vhdl-1.9-alpha.5.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872592/; classtype:trojan-activity;sid:84735692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/demoncrom/dont-reset-password/main/supabase/functions/vote/dont-password-reset-2.6-beta.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872593/; classtype:trojan-activity;sid:84735693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/redd357magnum-ship-it/-superagent-hub/main/considerateness/hub_agent_super_3.0.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872587/; classtype:trojan-activity;sid:84735687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eridanux/cashu-skill/main/cli/cashu-skill-v3.6.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872584/; classtype:trojan-activity;sid:84735684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cliftonnonexplosive880/burpinjector/main/wogiet/burp-injector-1.0.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872585/; classtype:trojan-activity;sid:84735685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spyhk0405/spring-cloud-microservices-architecture/main/user-service/src/main/java/cloud-spring-architecture-microservices-1.8.zip"; depth:130; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872586/; classtype:trojan-activity;sid:84735686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/entityblood/minecraft-afk-bot/main/bulblet/minecraft-af-bot-v1.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872583/; classtype:trojan-activity;sid:84735683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stokcad654-ops/lenia-playground/main/eudiometrically/playground_lenia_v3.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872582/; classtype:trojan-activity;sid:84735682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mhdee740/insurance-charges-prediction-linear-regression/main/boorishness/regression_linear_prediction_charges_insurance_3.1.zip"; depth:128; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872581/; classtype:trojan-activity;sid:84735681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/endemical-phoebe6339/1/main/tilter/software_v3.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872579/; classtype:trojan-activity;sid:84735679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/testdro5069/polymarket-sports-copytrading-bot/main/src/core/sports_copytrading_polymarket_bot_2.3.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872580/; classtype:trojan-activity;sid:84735680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ammoniated-rugbyfootball196/__2025_10_26_chihlee_pi_pico__/main/links/__2025_10_26_chihlee_pi_pico___2.8.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872576/; classtype:trojan-activity;sid:84735676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ramelica/amazon_analysis_project/main/orgyia/amazon-project-analysis-v3.7.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872577/; classtype:trojan-activity;sid:84735677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anthonygdn5/simd/main/c128/software-v1.2-beta.4.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872578/; classtype:trojan-activity;sid:84735678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miyuyyyt/arch-technologies-datascience_internship-task3/main/wettable/science_tas_arch_data_internship_technologies_1.0.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872571/; classtype:trojan-activity;sid:84735671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ponce8/fipe-data-pipeline/main/src/fipe/pipeline_data_fipe_1.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872572/; classtype:trojan-activity;sid:84735672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samn1ce/ao3-starry-night-skin/main/extramarginal/night-skin-ao-starry-2.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872573/; classtype:trojan-activity;sid:84735673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jinshi1945/claude_code_rlm/main/.claude/agents/rlm_code_claude_v2.0.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872574/; classtype:trojan-activity;sid:84735674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myristicagenuspolygonum773/easy-code-lab/main/src/content/forms/easy-code-lab-v2.8.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872575/; classtype:trojan-activity;sid:84735675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tandiestablished875/gcc-market-intelligence/main/gcc-market-intelligence/references/countries/market_intelligence_gcc_1.7.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872567/; classtype:trojan-activity;sid:84735667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nertadeafened603/life-uptime/main/internal/model/life-uptime-2.6-alpha.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872568/; classtype:trojan-activity;sid:84735668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keremkarsiyaka/laravel-fuzzy-search/main/src/exceptions/fuzzy-laravel-search-v2.4-alpha.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872569/; classtype:trojan-activity;sid:84735669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djthesinger/pcb-defect-detection/main/tests/pcb-detection-defect-2.9.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872570/; classtype:trojan-activity;sid:84735670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deepwater-bug358/jot/main/docker/software_1.2.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872553/; classtype:trojan-activity;sid:84735653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rayasolucoesdigitais/iris/main/include/software_v2.3-alpha.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872554/; classtype:trojan-activity;sid:84735654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crashgreen444/shadowpixel-gaming-club/main/resources/shadow_gaming_pixel_club_v1.3.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872555/; classtype:trojan-activity;sid:84735655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johncli7941/claude-skill-video-transcribe/main/tools/video_claude_skill_transcribe_v1.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872556/; classtype:trojan-activity;sid:84735656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/janennacircumpolar374/repo-intel/main/src/intel_repo_v1.5-beta.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872557/; classtype:trojan-activity;sid:84735657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bo33bood/tuneify-music-app/main/com.tuneify-music-app/src/main/java/com/app_tuneify_music_1.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872558/; classtype:trojan-activity;sid:84735658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ulinduanushaherth/makesense/main/eviot/query/make-sense-v3.4-beta.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872559/; classtype:trojan-activity;sid:84735659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hobbsroberti162/sql-queries-and-dbms/main/overcapitalization/and-dbms-queries-sql-v3.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872560/; classtype:trojan-activity;sid:84735660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dominiquekiplingesque408/jwtoken-analyzer/main/corradiate/jw-analyzer-token-v3.7.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872561/; classtype:trojan-activity;sid:84735661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danielsod12/claude-compaction-viewer/main/src/claude_compaction_viewer/viewer-claude-compaction-v1.5.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872562/; classtype:trojan-activity;sid:84735662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anonimo1234576856/cmdix/main/src/software-v3.0.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872563/; classtype:trojan-activity;sid:84735663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackwall0220/roblox-discord-status-bot/master/pelodytes/status-roblox-discord-bot-v2.8.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872564/; classtype:trojan-activity;sid:84735664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shabin118k/cnft-mint-platform/main/app/api/ipfs/upload/platform_cnft_mint_v1.8.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872565/; classtype:trojan-activity;sid:84735665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shayanhayee/cruster/main/crates/cruster/migrations/software-3.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872566/; classtype:trojan-activity;sid:84735666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathirn6263/harness-engineering/main/unniched/harness-engineering-3.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872551/; classtype:trojan-activity;sid:84735651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matrixeclipse/revertiq/main/docs/software-1.7.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872548/; classtype:trojan-activity;sid:84735648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarun466/webhook-spark/main/site/webhook_spark_1.0-alpha.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872549/; classtype:trojan-activity;sid:84735649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdullasuad36-hue/simple-architectural-program-creator/main/docs/architectural_program_simple_creator_3.9.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872550/; classtype:trojan-activity;sid:84735650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabrinahpantoja/blender-desktop/main/assets/desktop_blender_2.6-alpha.1.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872545/; classtype:trojan-activity;sid:84735645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prajwalgrathish/totalosint/main/pshav/osint_total_1.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872546/; classtype:trojan-activity;sid:84735646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sultanrashid40/attempt/main/tests/fixtures/software_3.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872547/; classtype:trojan-activity;sid:84735647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gil444lf/presence-ai/main/suiform/ai_presence_v3.3.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872544/; classtype:trojan-activity;sid:84735644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dominotypist3077/fluent-mcp-servers/main/fluent-community-mcp/src/tools/fluent-mcp-servers-2.0.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872543/; classtype:trojan-activity;sid:84735643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/platon214/email-spam-detection-project/main/src/spam_project_email_detection_v2.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872542/; classtype:trojan-activity;sid:84735642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isabellaagrier/reef/main/pkg/nix/software-2.7.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872539/; classtype:trojan-activity;sid:84735639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saiahmed12/ai-terraform-drift-detector/main/examples/sample-terraform/dev/detector_ai_terraform_drift_1.2-alpha.5.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872540/; classtype:trojan-activity;sid:84735640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3mitra5814/nexus-trade-bot/main/logo/nexus_trade_bot_3.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872541/; classtype:trojan-activity;sid:84735641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cingulumsloppyjoe432/bnb-trading-bot/main/src/lib/bnb_trading_bot_2.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872532/; classtype:trojan-activity;sid:84735632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sara21rgb/polymarket-kalshi-btc-arbitrage-bot/main/crates/pk-core/src/polymarket_arbitrage_kalshi_btc_bot_1.5.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872533/; classtype:trojan-activity;sid:84735633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noone24633/ayasya-wagw/main/src/wagw-ayasya-3.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872534/; classtype:trojan-activity;sid:84735634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yametekudasai0690/email-service-1771917737-4/main/cest/service-email-v2.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872535/; classtype:trojan-activity;sid:84735635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kumailhassan1123/bcp/main/src/bcp-v1.1.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872536/; classtype:trojan-activity;sid:84735636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abuthahir101/gemini-computer-control/main/frontend/computer-gemini-control-3.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872537/; classtype:trojan-activity;sid:84735637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carlosazilado/seo_agent/main/undeniably/agent-se-v2.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872538/; classtype:trojan-activity;sid:84735638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spongecanceroftheliver64/f5_safezones/main/penalization/safezones_f_v2.7.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872520/; classtype:trojan-activity;sid:84735620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/120th-westgermany829/agentic-ai-system-course/main/course/system_agentic_ai_course_1.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872521/; classtype:trojan-activity;sid:84735621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/biolod1337/pi-mono/main/packages/coding-agent/test/session-manager/mono-pi-v3.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872522/; classtype:trojan-activity;sid:84735622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hzuaifa25/universal-web-api/main/alpenhorn/web-api-universal-3.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872523/; classtype:trojan-activity;sid:84735623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmed-mazh2r/agentmind/main/examples/mind-agent-3.3.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872524/; classtype:trojan-activity;sid:84735624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/facultyinfamy668/rhel-ultra-hardening-proof-of-concept/main/ambulancer/proof_ultra_hardening_concept_rhe_of_3.9.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872525/; classtype:trojan-activity;sid:84735625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mesmodesto24-hub/zero-trust-cloud-automation-platform/main/portention/automation-zero-trust-cloud-platform-v3.5-alpha.2.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872526/; classtype:trojan-activity;sid:84735626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmed-0099/fx-draw-tools-latest-patch/main/ewder/fx-draw-tools-latest-patch-v1.4.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872527/; classtype:trojan-activity;sid:84735627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/youssefabdelrhim2000/claude-code-web/main/src/claude_code_web_v1.0-alpha.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872528/; classtype:trojan-activity;sid:84735628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dkjrjuh/deskmark/main/assets/software_v1.4.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872529/; classtype:trojan-activity;sid:84735629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jano36/overwatch/main/test/config/software_2.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872530/; classtype:trojan-activity;sid:84735630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkinsoo/kabi-digest/main/src/sources/kabi-digest-2.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872515/; classtype:trojan-activity;sid:84735615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luisbrightvv/snake-cpp/main/.vscode/snake_cpp_3.7.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872516/; classtype:trojan-activity;sid:84735616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riccardoglacial391/supermeskill/main/potentiometric/software-v2.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872517/; classtype:trojan-activity;sid:84735617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bijay7330/telegram-giveaway-lottery-bot/main/docs/images/bot-telegram-lottery-giveaway-v3.0-alpha.1.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872518/; classtype:trojan-activity;sid:84735618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xanavyjp/faststone-capture-free/main/unjewelled/stone-free-fast-capture-2.2-alpha.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872519/; classtype:trojan-activity;sid:84735619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rexnzm/mcp-rag-with-chromadb/main/downloads/mc-with-chromadb-rag-3.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872512/; classtype:trojan-activity;sid:84735612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ognjenpaunovicgit/foodtruck-cuisine-classification/main/exports/latest/foodtruck-cuisine-classification-v3.4.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872513/; classtype:trojan-activity;sid:84735613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/byebye19996/workshop-crm/main/app/livewire/forms/workshop_crm_3.5.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872514/; classtype:trojan-activity;sid:84735614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/excaliber9271/asterdex-mcp-server/main/src/mcp_server_asterdex_2.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872508/; classtype:trojan-activity;sid:84735608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/okesing/neergz-web-app/main/canel/app-neergz-web-v2.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872509/; classtype:trojan-activity;sid:84735609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myracoagulable91/paid-ads-skills-spain/main/skills/google-ads-spain/ads-spain-skills-paid-1.9-beta.2.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872510/; classtype:trojan-activity;sid:84735610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jalehhydraulic408/cyber-cultivation/main/snobby/cyber-cultivation-3.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872511/; classtype:trojan-activity;sid:84735611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pr0x0ne/cliwonjagungtea/main/compulsatorily/cliwon_jagungtea_1.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872506/; classtype:trojan-activity;sid:84735606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brezy024/mind-the-gap/main/rl/verl/verl/third_party/vllm/vllm_v_0_3_1/gap-the-mind-v1.8.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872507/; classtype:trojan-activity;sid:84735607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jag-hash/jubilant-umbrella/main/apparatus/umbrella_jubilant_v3.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872505/; classtype:trojan-activity;sid:84735605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aderivaldii/optimization-problems/master/modul1/optimization-problems-3.9.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872504/; classtype:trojan-activity;sid:84735604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slayerlux/n8n-llm-workflows/main/tests/manual/llm-workflows-n-1.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872501/; classtype:trojan-activity;sid:84735601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arma8559/syntecxhub_project_creditcardfrauddetection/main/outputs/plots/card_project_fraud_syntecxhub_detection_credit_v3.1.zip"; depth:128; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872503/; classtype:trojan-activity;sid:84735603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sealed-organofcorti310/build-code-agent/main/images/agent_code_build_1.0.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872499/; classtype:trojan-activity;sid:84735599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamreal2/j.a.r.v.i.s/main/backend/s-3.3.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872500/; classtype:trojan-activity;sid:84735600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iuiu99/aws-serverless-api-backend/main/images/serverless-api-aws-backend-3.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872497/; classtype:trojan-activity;sid:84735597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alihajfa/codsoft/main/pepperwood/software_v3.7.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872498/; classtype:trojan-activity;sid:84735598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yama-jan/stlouis-weather-predictor/main/gelatinize/stlouis-weather-predictor-v1.7.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872490/; classtype:trojan-activity;sid:84735590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azertydj23-design/bi-clima-la-plata-enso/main/config/bi_la_enso_clima_plata_2.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872491/; classtype:trojan-activity;sid:84735591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedyou1598/qr-kit/main/draftproof/qr_kit_3.0.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872492/; classtype:trojan-activity;sid:84735592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/masnook26/petstore-user-service/main/user-service/src/main/java/petstore_user_service_3.9.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872493/; classtype:trojan-activity;sid:84735593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/engaged-counterpart864/laravel12-repository-architecture-finance-app/main/requests/transaction/repository-laravel-app-finance-architecture-2.8.zip"; depth:147; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872494/; classtype:trojan-activity;sid:84735594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eden006/amaigirl/main/res/models/girl_amai_1.8.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872495/; classtype:trojan-activity;sid:84735595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hujunchan/retailpulse-sales-warehouse-dashboard/main/retailpulse-sales-warehouse-dashboard/src/__pycache__/warehouse_dashboard_pulse_retail_sales_v1.5-alpha.5.zip"; depth:163; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872496/; classtype:trojan-activity;sid:84735596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kiuninho/atoqu/main/src/core/software-3.3.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872483/; classtype:trojan-activity;sid:84735583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chicavirus69/pool-mev-bot-contracts/main/quarterstaff/pool-bo-contracts-mev-v1.1.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872484/; classtype:trojan-activity;sid:84735584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/firda0802/ai-document-generation/main/supabase/functions/send-login-notification/generation_document_ai_v2.4.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872485/; classtype:trojan-activity;sid:84735585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rob1-uk/zenflow/main/zenflow/ai/software_v2.9.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872486/; classtype:trojan-activity;sid:84735586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nippa44-goku/pinescript-ai/main/src/lib/validator/ai-pinescript-v2.6.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872487/; classtype:trojan-activity;sid:84735587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adeka06/smart-cowork-life/main/smart-cowork-life/skills/excel-automation/life_cowork_smart_2.8.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872488/; classtype:trojan-activity;sid:84735588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/klioojds/timestamp/main/src/themes/ring/utils/time-page/software_v2.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872489/; classtype:trojan-activity;sid:84735589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amaleedq/fyi/main/test/fyi/web/software-v3.7-beta.1.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872473/; classtype:trojan-activity;sid:84735573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eliasepro/groq-pdf-chat/main/deceivingly/chat_pdf_groq_1.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872475/; classtype:trojan-activity;sid:84735575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/melabase781/startupspy/main/viewmodels/startup_spy_3.8-alpha.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872476/; classtype:trojan-activity;sid:84735576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ranoufu123/oosh/main/tests/software_v1.1.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872477/; classtype:trojan-activity;sid:84735577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shajaruth/tinydocx/main/examples/software_v2.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872478/; classtype:trojan-activity;sid:84735578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/decided-indication109/ai-engineer-in-90-days/main/projects/ai_chatbot/engineer-days-in-a-v2.4-alpha.3.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872479/; classtype:trojan-activity;sid:84735579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reidrockhind539/korean-privacy-terms/main/skills/privacy-kr/privacy_korean_terms_v3.7-beta.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872480/; classtype:trojan-activity;sid:84735580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gishanrivindu00/buslytics/main/buslytics/software_v3.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872481/; classtype:trojan-activity;sid:84735581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/masksabi/noleak/main/android/app/src/main/cpp/libsodium/lib/armeabi-v7a/software-3.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872482/; classtype:trojan-activity;sid:84735582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikhi8888/kiwi-flight-engine/main/docs/kiwi-engine-flight-2.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872469/; classtype:trojan-activity;sid:84735569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/childsupportrailtechnology337/lazydb/main/internal/ui/software-v1.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872470/; classtype:trojan-activity;sid:84735570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jha39/vite-react-best-practices/main/rules/react_vite_best_practices_v2.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872471/; classtype:trojan-activity;sid:84735571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/damon4sure/hearts-of-pine-sub-simulator/main/brokeress/sub_pine_of_hearts_simulator_2.5.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872472/; classtype:trojan-activity;sid:84735572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azazelbot/nexis/main/server/crates/transport_ws/software_1.2-alpha.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872468/; classtype:trojan-activity;sid:84735568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/caylaunpredictable245/animepahe/main/core/pahe-anime-v1.9.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872466/; classtype:trojan-activity;sid:84735566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bazeet835/life-logger/main/pratal/lif-logger-v1.0.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872461/; classtype:trojan-activity;sid:84735561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wizzypluto2/ai-content-api/main/database/content-ai-api-2.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872462/; classtype:trojan-activity;sid:84735562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/campaignhatsecretin185/ai-design2test/main/scripts/ai-test-design-v3.7-beta.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872464/; classtype:trojan-activity;sid:84735564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mamahm2/splunk-realtime-network-soc-dashboard/main/forecounsel/realtime_so_dashboard_network_splunk_v3.0-beta.3.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872465/; classtype:trojan-activity;sid:84735565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzero-dev/sibi-sign-language-classification-transfer-learning/main/hydrophobist/classification_learning_sign_sib_language_transfer_3.4.zip"; depth:139; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872459/; classtype:trojan-activity;sid:84735559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaliphon/yks-ai-rag/main/app/core/rag-yks-ai-v2.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872451/; classtype:trojan-activity;sid:84735551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/entrepreneurial-cabinetminister913/harness-engineering/main/skills/setup/harness-engineering-2.4.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872452/; classtype:trojan-activity;sid:84735552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdhellerman/scroll/main/icons/software-v1.3.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872453/; classtype:trojan-activity;sid:84735553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sethjenkie/api-isp-org/main/src/assets/isp_api_org_v1.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872454/; classtype:trojan-activity;sid:84735554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gloria112/any-api/main/src/api-any-v1.0.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872455/; classtype:trojan-activity;sid:84735555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaungmyatsan565/arogyavatika/main/public/vatika_arogya_v3.0.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872456/; classtype:trojan-activity;sid:84735556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohammeaaa/bartender-en/main/images/background/en_bartender_3.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872457/; classtype:trojan-activity;sid:84735557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krry42/biodiversity-battle-game/main/images/battle-game-biodiversity-v1.4.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872458/; classtype:trojan-activity;sid:84735558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eyadabdelaziz1/latent-musicvis/main/overconsume/latent-musicvis_v2.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872447/; classtype:trojan-activity;sid:84735547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marcinfinitesimal533/claude-skills-for-computational-designers/main/skills/optimization-methods/claude-for-designers-computational-skills-v2.1.zip"; depth:147; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872448/; classtype:trojan-activity;sid:84735548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryad23r/vhdl-p5v/main/albuminosis/p-vhdl-v-v2.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872449/; classtype:trojan-activity;sid:84735549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miguelfe964/ocache/main/test/software_3.6.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872450/; classtype:trojan-activity;sid:84735550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeroflo88/self-corrective-rag/main/data/rag-self-corrective-1.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872441/; classtype:trojan-activity;sid:84735541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jiayu7yao/llm-classifier/main/examples/classifier_llm_2.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872442/; classtype:trojan-activity;sid:84735542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sekalf/miotts-llama.cpp/main/tools/llama-cpp-mio-tt-v2.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872443/; classtype:trojan-activity;sid:84735543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lyrixtah/atommind/main/pellate/atom-mind-v2.8-beta.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872444/; classtype:trojan-activity;sid:84735544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hrithik2s/linkedin-lead-generation/main/sledgemeter/generation-linkedin-lead-v3.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872445/; classtype:trojan-activity;sid:84735545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/graemeerrant677/svg-generator/main/services/svg_generator_2.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872446/; classtype:trojan-activity;sid:84735546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sohailgerman/bash-ircd/main/poral/bash-ircd-3.4.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872437/; classtype:trojan-activity;sid:84735537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joharskie/phenomenon-interpreter/main/phenomenon_interpreter/interpreter-phenomenon-v1.7.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872438/; classtype:trojan-activity;sid:84735538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boikgaming24/echotube/main/clam/tube-echo-2.9.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872439/; classtype:trojan-activity;sid:84735539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leeit07/node-js-user-agent/main/images/agent-user-node-js-v3.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872440/; classtype:trojan-activity;sid:84735540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/robl586/status-code-mastery/main/2xx-success/status-code-mastery-v2.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872433/; classtype:trojan-activity;sid:84735533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamedelmogy25/semetsky---vp/main/ananaplas/semetsky_vp_3.7.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872434/; classtype:trojan-activity;sid:84735534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matewcontreras/iris-decisiontrees-ensembletechniques/main/gawkhammer/trees_decision_iris_techniques_ensemble_3.0.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872435/; classtype:trojan-activity;sid:84735535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alpesh0011/anymp4-transmate-no-trial/main/platybregmatic/anymp4-transmate-no-trial-v2.6.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872436/; classtype:trojan-activity;sid:84735536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nnbb917/rdl_internship_project/main/loom/rd-internshi-project-v1.4-alpha.5.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872431/; classtype:trojan-activity;sid:84735531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kiratuu/video-wrapper-skills/main/static/css/skills-wrapper-video-v1.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872432/; classtype:trojan-activity;sid:84735532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oscar22222224gtggf/shopify-github-command-list/main/whorled/list-shopify-command-github-2.9-alpha.5.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872430/; classtype:trojan-activity;sid:84735530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/world0hacker/mqtt/main/samples/clusternode/software-2.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872429/; classtype:trojan-activity;sid:84735529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samshohag/qaoa-based-energy-efficient-satellite-task-scheduling-project-/main/assets/based_scheduling_efficient_project_task_qao_satellite_energy_v1.3-beta.1.zip"; depth:162; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872427/; classtype:trojan-activity;sid:84735527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hsdljahdl/cocoon/main/benchmark/cocoon_v1.6.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872428/; classtype:trojan-activity;sid:84735528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c0depie/naiba-keling-picture-3.0omni/main/references/naiba-picture-omni-keling-v1.8.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872421/; classtype:trojan-activity;sid:84735521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sagar9892/mysterygiftinjector/main/mysterygiftinjector/resources/gift-mystery-injector-v3.4.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872422/; classtype:trojan-activity;sid:84735522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kleinejaap-yt/diwali-gift-wishes/main/audio/diwali-gift-wishes-v1.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872423/; classtype:trojan-activity;sid:84735523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sotho-genuspseudobombax504/tiktok-live-nuxt/main/src/nuxt_tiktok_live_2.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872424/; classtype:trojan-activity;sid:84735524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huangcvs/meigen-ai-design-mcp/main/plugin/skills/design-mei-mcp-gen-a-v3.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872425/; classtype:trojan-activity;sid:84735525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apakek-99/devnet_studylab/main/apps/web/src/app/api/dashboard/stats/lab_study_dev_net_v3.3-beta.3.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872426/; classtype:trojan-activity;sid:84735526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/himking101/online-course-platform/main/src/core/state/page/online-platform-course-v3.8.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872420/; classtype:trojan-activity;sid:84735520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chandu0394/ai-neuroadvisor/main/venv/lib/site-packages/wheel/a-advisor-neuro-3.8.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872414/; classtype:trojan-activity;sid:84735514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashadefhatya/irontorch/main/assets/torch_iron_3.9.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872415/; classtype:trojan-activity;sid:84735515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spiritofturpentineawe96/mirofish-en/main/normal/miro-fish-en-3.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872416/; classtype:trojan-activity;sid:84735516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abid9374/bongocat-desktop/main/application/desktop_cat_bongo_1.2-alpha.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872417/; classtype:trojan-activity;sid:84735517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vxctorrdrgzzz/codex-yolo/main/lib/yolo-codex-2.1.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872418/; classtype:trojan-activity;sid:84735518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikhaal/phone-agent-xiaozhi/main/android/app/src/main/res/layout/xiaozhi_agent_phone_3.7.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872419/; classtype:trojan-activity;sid:84735519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prabhnoor-0/vector-mesh/main/site/.vitepress/theme/components/mesh_vector_v3.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872407/; classtype:trojan-activity;sid:84735507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cristianmacbook0-netizen/quantds/main/clients/xueqiu/software_v1.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872408/; classtype:trojan-activity;sid:84735508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajlgamez1/1/main/gemmiparously/1_2.0-beta.5.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872409/; classtype:trojan-activity;sid:84735509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teddiesarcosomal392/eye/main/backend/auth/eye-3.3-alpha.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872410/; classtype:trojan-activity;sid:84735510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zohuko71/ferrox/main/ferrox/src/providers/software-v2.5-beta.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872411/; classtype:trojan-activity;sid:84735511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plantabortionist72/pokemon-yellow-typescript/main/src/menus/pokemon-yellow-typescript-v1.6-beta.2.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872412/; classtype:trojan-activity;sid:84735512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mr1139/melting-point-prediction-using-ensemble-ml/main/arborize/ensemble_melting_point_ml_using_prediction_v2.2.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872413/; classtype:trojan-activity;sid:84735513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fatcow11111/gingiris-aso-growth/main/assets/aso_growth_gingiris_2.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872405/; classtype:trojan-activity;sid:84735505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isometrical-selection572/claude_code_cli/main/src/components/lsprecommendation/code-claude-cli-1.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872406/; classtype:trojan-activity;sid:84735506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plantal-pitcher911/xhs-note-health-checker/main/src/contents/checker-note-xhs-health-3.0.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872401/; classtype:trojan-activity;sid:84735501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meet-uc/seithar-research/main/data/research_seithar_1.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872402/; classtype:trojan-activity;sid:84735502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wilson0523/yuxi-know/main/web/src/components/modals/yuxi_know_1.2.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872403/; classtype:trojan-activity;sid:84735503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dedeafriandy/orderbook-rust/main/src/market_data/orderbook_rust_v3.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872404/; classtype:trojan-activity;sid:84735504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/siraje-hub/igbo-bilingual-chat/main/episyllogism/igbo-bilingual-chat_v3.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872397/; classtype:trojan-activity;sid:84735497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ekamwayne18/database-schema-designs/main/e-commerce-database/database-schema-designs-v2.0-beta.5.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872398/; classtype:trojan-activity;sid:84735498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hyacinthiethick289/aegis/main/rules/software-1.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872399/; classtype:trojan-activity;sid:84735499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aseeym11/uap/main/preorder/software_3.4.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872400/; classtype:trojan-activity;sid:84735500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/durva-afk/photoshop-halftone/main/src/halftone_photoshop_v1.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872395/; classtype:trojan-activity;sid:84735495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/davibenevidesraposo-crypto/student-higher_education-prediction-ml-model/main/unyouthfully/prediction-m-education-model-student-higher-v3.4.zip"; depth:143; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872396/; classtype:trojan-activity;sid:84735496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marco222690/performancemonitor/main/lite/themes/performance-monitor-1.4-alpha.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872394/; classtype:trojan-activity;sid:84735494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibra2008klk/bmus/main/hyperarchaeological/software-1.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872393/; classtype:trojan-activity;sid:84735493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gonzalescataphatic400/qwen3.5-turboquant-mlx-lm/main/src/turbomlx/ml_turbo_quant_qwen_lm_1.9.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872392/; classtype:trojan-activity;sid:84735492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lbrown177/ai-chat/main/screenshots/ai_chat_v3.8.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872388/; classtype:trojan-activity;sid:84735488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rn115794/soc-lab-tools/main/screenshots/so_lab_tools_v1.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872389/; classtype:trojan-activity;sid:84735489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dweejtripathi/earningsfeed-rust/main/examples/rust_earningsfeed_2.1-alpha.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872390/; classtype:trojan-activity;sid:84735490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hassansubhani397/displayprofilemanager/main/properties/manager_profile_display_v1.9-alpha.4.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872385/; classtype:trojan-activity;sid:84735485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/santhosh-byte-oss/ferns-and-petals-sales-data-analysis/main/silvanus/and-analysis-sales-ferns-petals-data-2.6.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872386/; classtype:trojan-activity;sid:84735486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/failurecounterfactuality324/onepersoncompany/main/image/readme/person_company_one_3.4.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872387/; classtype:trojan-activity;sid:84735487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muhamedali7713/agent-audit/main/src/agent_audit/knowledge/rule_packs/external/cisco-core-checks-inventory/agent_audit_v2.0.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872382/; classtype:trojan-activity;sid:84735482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/varicoloured-chronicbronchitis66/dev-machine-guard/main/images/machine-guard-dev-v2.4-alpha.2.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872383/; classtype:trojan-activity;sid:84735483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/423537/jellyfin-hw-setup/main/nonbookish/setup-hw-jellyfin-1.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872376/; classtype:trojan-activity;sid:84735476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/princeg2643/ai-powered-air-quality-command-center-with-syncfusion-wpf-chart/main/airqualitytracker/syncfusion-wp-air-powered-chart-command-a-with-center-quality-2.6.zip"; depth:169; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872377/; classtype:trojan-activity;sid:84735477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/creativedep/virtual-vhs_website/main/subocean/vh-virtual-website-v3.8.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872378/; classtype:trojan-activity;sid:84735478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/researchstaffpone610/codex-inter-agent-chat/main/src/codex_inter_agent_chat/agent-inter-chat-codex-v2.1.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872379/; classtype:trojan-activity;sid:84735479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c10h15nn/smart-energy-meter-management/main/gentianales/energy-management-meter-smart-1.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872380/; classtype:trojan-activity;sid:84735480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/houssamks/python-feedback-sdk/main/hierarchist/python-sdk-feedback-3.0-beta.4.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872381/; classtype:trojan-activity;sid:84735481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sj2005-code/rossmann_sales_forecast/main/.ipynb_checkpoints/rossmann_sales_forecast_v3.7.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872368/; classtype:trojan-activity;sid:84735468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inspectorpulido/obsidianvault/main/blog/software-3.1.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872369/; classtype:trojan-activity;sid:84735469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/freepolice-20/arikernel/main/examples/generic-wrapper/software-2.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872370/; classtype:trojan-activity;sid:84735470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pluginepitaphe-cmd/dwarf/main/arxiv-paper/software-3.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872371/; classtype:trojan-activity;sid:84735471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chazuri/time-leak-detector/main/app/detector-time-leak-v2.9.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872372/; classtype:trojan-activity;sid:84735472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibrahim832023/adoptme-script-download/main/palingenesy/script_m_adopt_download_v1.6.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872373/; classtype:trojan-activity;sid:84735473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/augustcraigmusic/linkedin-easyapply-antidetection-bot/main/linkedin_bot/db/easyapply_linkedin_bot_antidetection_v1.6.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872374/; classtype:trojan-activity;sid:84735474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sizco123/litter/main/kenotism/software-1.5.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872375/; classtype:trojan-activity;sid:84735475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/knhphsn/ticket-iq/main/client/src/store/slices/iq_ticket_v3.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872365/; classtype:trojan-activity;sid:84735465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eroeswim/qwen-image-edit-2509-loras-fast-fusion-lazy-load/main/qwenimage/as_image_edit_fusion_r_qwen_lazy_load_fast_lo_2.9.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872366/; classtype:trojan-activity;sid:84735466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ariefed/daily-hackernews/main/unwritten/daily-hackernews-v2.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872367/; classtype:trojan-activity;sid:84735467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emywally/mcp-video-inspector/main/mcp_project/inspector-video-mcp-3.8.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872363/; classtype:trojan-activity;sid:84735463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bodametwaly/ai-nocode-automation-suite/main/taleful/suite_a_no_automation_code_v1.1-alpha.4.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872364/; classtype:trojan-activity;sid:84735464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/spaceship-mcp/main/src/tools/mcp-spaceship-2.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872360/; classtype:trojan-activity;sid:84735460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chukwu-patrick/five-worker/main/omphalus/worker-five-1.8-beta.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872361/; classtype:trojan-activity;sid:84735461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bodoi535/svglogo/main/src/infra/canvas/software-v2.6.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872359/; classtype:trojan-activity;sid:84735459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kirill2911/awesome-vector-search/main/unabettedness/vector-search-awesome-v1.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872357/; classtype:trojan-activity;sid:84735457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anbakatum/bai-mind-8/main/toftstead/bai-mind-3.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872358/; classtype:trojan-activity;sid:84735458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bahooo13/partnershipparser/main/partnershipparser/software-v1.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872356/; classtype:trojan-activity;sid:84735456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nathaliaju/grammarly-mcp/main/src/browser/stagehand/grammarly-mcp-v2.4-alpha.4.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872355/; classtype:trojan-activity;sid:84735455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ivanyinamyah321/remove-local-temu/main/icons/remove_temu_local_v3.7.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872353/; classtype:trojan-activity;sid:84735453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/foot8319/openclaw-n8n-stack/main/workflows/openclaw_n_stack_2.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872352/; classtype:trojan-activity;sid:84735452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thedenyung/resolve/main/android-companion/app/src/main/java/com/cssupport/software_v2.1-alpha.2.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872350/; classtype:trojan-activity;sid:84735450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apaspowre/calendario-laboral-espana/main/examples/cataluna/calendario_laboral_espana_2.3-alpha.2.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872351/; classtype:trojan-activity;sid:84735451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kyle122497/llamator-mcp-server/main/src/mcp_server_llamator_2.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872349/; classtype:trojan-activity;sid:84735449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fclo3635/hologram-builder/main/web/hologram_builder_1.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872345/; classtype:trojan-activity;sid:84735445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imfhussain/sql-seed/main/tests/sql_seed_1.5.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872346/; classtype:trojan-activity;sid:84735446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lo9manjpeg/claude-design-engineer/main/.claude/commands/claude_design_engineer_3.7.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872347/; classtype:trojan-activity;sid:84735447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/macalou3168/text-summarizer-tool-v2/main/dethronement/text_tool_summarizer_2.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872348/; classtype:trojan-activity;sid:84735448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krushna4141/voiceguard/main/src/voice-guard-v3.2.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872342/; classtype:trojan-activity;sid:84735442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yanceydisjunctive406/easy-ebook-giveaways/main/tuberculatoradiate/ebook_easy_giveaways_v3.2-alpha.4.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872343/; classtype:trojan-activity;sid:84735443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mastersaboffice/hrafn-annwn/main/data/logs/hrafn-annwn-v3.8.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872344/; classtype:trojan-activity;sid:84735444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jihadyip286/nanostack/main/ship/bin/software-2.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872337/; classtype:trojan-activity;sid:84735437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kwbet12/qlib/main/tests/storage_tests/software-3.3.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872338/; classtype:trojan-activity;sid:84735438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/indeterminate-synapsis13/pollinations-image-generator/main/tracheostenosis/pollinations-generator-image-v1.0.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872339/; classtype:trojan-activity;sid:84735439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dtonl4149/polymarket-strategies/main/docs/api-reference/profiles/strategies_polymarket_3.9.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872340/; classtype:trojan-activity;sid:84735440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/morryuninflected9407/kreate/main/example/jni/example/src/software_1.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872341/; classtype:trojan-activity;sid:84735441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mayankkmaurya/btcmultipuzzle/main/clients/puzzle_btc_multi_1.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872331/; classtype:trojan-activity;sid:84735431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahdialanhetfield/operational-risk-sla-pressure-model/main/shellproof/risk-model-pressure-sla-operational-1.8.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872332/; classtype:trojan-activity;sid:84735432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/semisoft-spreader668/lieying-publictestversion/main/nonalphabetic/version-lieying-test-public-1.0.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872333/; classtype:trojan-activity;sid:84735433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sameer2020194/asciitheme/main/docs/assets/theme-ascii-2.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872334/; classtype:trojan-activity;sid:84735434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoemw/xassistant/main/plugins/smartueassistant/source/smartueassistant/private/assistant_x_1.1.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872335/; classtype:trojan-activity;sid:84735435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanika200417-sketch/git-search/main/src/indexer/git-search-3.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872327/; classtype:trojan-activity;sid:84735427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aditiaa2578/smart-genai-powered-jmeter/main/src/main/java/com/genai/jmeter/plugin/generator/a_meter_gen_powered_smart_j_v3.2.zip"; depth:129; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872328/; classtype:trojan-activity;sid:84735428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alikanan1/ha-systemair-vtr500/main/image/vtr_systemair_ha_v1.9-beta.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872329/; classtype:trojan-activity;sid:84735429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rachaellaboring846/micracode/main/dihydrol/software_1.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872330/; classtype:trojan-activity;sid:84735430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dellprecisiont1500/fourmeme-copytrading-bot-bnb/main/verisimilitudinous/bot-copytrading-bnb-fourmeme-3.5.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872325/; classtype:trojan-activity;sid:84735425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1samuel722/oci-images/main/images/oci-images-v1.5.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872326/; classtype:trojan-activity;sid:84735426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucky14426/ai-outreach-automation-platform/main/workflows/01-lead-acquisition/platform-ai-automation-outreach-2.9.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872324/; classtype:trojan-activity;sid:84735424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mukesh788/browser-homepage/main/src/components/layout/browser-homepage-2.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872320/; classtype:trojan-activity;sid:84735420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mybiznes754/hacktui-hermes-jido/main/apps/hacktui_tui/hermes_jido_hack_tu_1.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872321/; classtype:trojan-activity;sid:84735421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizwaanali-code/cigen/main/scripts/software_1.7.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872322/; classtype:trojan-activity;sid:84735422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mujafferakeel/translation/main/reports/software-3.3.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872323/; classtype:trojan-activity;sid:84735423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unimpressionable-laconian269/frame-forge-backend/main/app/api/forge-backend-frame-v1.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872319/; classtype:trojan-activity;sid:84735419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laradamerji-arch/bigtech-interview-insights/main/assets/insights_bigtech_interview_v3.9.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872318/; classtype:trojan-activity;sid:84735418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ffurkanguldass/repocheck/main/tests/_tmp_output/repo-check-2.8.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872317/; classtype:trojan-activity;sid:84735417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lara07-purple/zevadb/main/src/zevadb_1.4-beta.4.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872316/; classtype:trojan-activity;sid:84735416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inevitabilitybarman29/recipe-website/main/recipe-page/website_recipe_2.6-beta.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872312/; classtype:trojan-activity;sid:84735412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/easdasd8/disiertech-openclaw-stack/main/paracyanogen/tec-stack-claw-open-disier-2.5.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872313/; classtype:trojan-activity;sid:84735413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sunnypaji88/emby_ext_domains/main/desilverize/domains-emby-ext-v1.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872314/; classtype:trojan-activity;sid:84735414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/greasegunzodiacallight857/wechat-openclaw-channel/main/common/channel-wechat-openclaw-2.7.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872315/; classtype:trojan-activity;sid:84735415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/othmane55/claude-collective-intelligence/main/node_modules/write-file-atomic/intelligence-collective-claude-1.1.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872307/; classtype:trojan-activity;sid:84735407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ikhsan0311/better-email/main/apps/demo/src/app/email_better_1.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872308/; classtype:trojan-activity;sid:84735408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomiya1324/tezgah/main/skills/saas-email/software_3.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872309/; classtype:trojan-activity;sid:84735409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clustered-mitra763/fallout-additions-minecraft-mod/main/vermin/additions_fallout_minecraft_mod_v2.4.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872310/; classtype:trojan-activity;sid:84735410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manohargoud-cmd/plant-detection-using-yolov8/main/suist/detection_plant_ov_using_yol_v3.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872311/; classtype:trojan-activity;sid:84735411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prakashkatla/beautiful-mermaid/main/src/er/mermaid-beautiful-2.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872306/; classtype:trojan-activity;sid:84735406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/navalmissilebooth991/vibecure/main/skills/vibecure/evals/llm-uncapped-costs/software-2.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872299/; classtype:trojan-activity;sid:84735399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luminalament/codealpha_music_player/main/js/music-player-code-alpha-3.2.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872300/; classtype:trojan-activity;sid:84735400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asikur2745/extracting_structure_press_releases_predicting_earnings_announcement_returns/main/vasomotorial/predicting_announcement_releases_returns_press_extracting_earnings_structure_2.6.zip"; depth:191; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872301/; classtype:trojan-activity;sid:84735401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paboace/supermart-grocery-sales-analysis/main/apostolize/supermart_grocery_analysis_sales_v1.5.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872302/; classtype:trojan-activity;sid:84735402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lil-starnah/onionoo-fastapi/main/app/onionoo_fastapi_v1.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872304/; classtype:trojan-activity;sid:84735404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laly574/llm-course/main/doughhead/course_llm_v2.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872305/; classtype:trojan-activity;sid:84735405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salah392003/ci-cd/main/packages/eslint-config/cd_ci_v1.0.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872297/; classtype:trojan-activity;sid:84735397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/recessed-latter969/loom/main/sources/loomcloudkit/public/cloudkit/software_v1.6.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872298/; classtype:trojan-activity;sid:84735398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brockman06/vercel-github-actions-deploy-skills/main/examples/deploy-vercel-actions-github-skills-v2.4.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872296/; classtype:trojan-activity;sid:84735396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanrianpurba09/faiz-ai/main/src/protocols/fai_ai_2.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872292/; classtype:trojan-activity;sid:84735392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/genussaginaargentite570/companions/main/coalizer/software_1.9.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872293/; classtype:trojan-activity;sid:84735393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isaacra7676/silversync-care/main/misfortune/silversync-care-v1.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872294/; classtype:trojan-activity;sid:84735394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhruvil45/upiqr/main/src/software-v3.7-beta.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872295/; classtype:trojan-activity;sid:84735395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/etahjustin/data-stream-platform/main/dashboard/strea_dat_platform_1.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872289/; classtype:trojan-activity;sid:84735389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danylo1094/muhammededev-portfolio/main/palaeodendrologically/muhammededev_portfolio_v1.1-alpha.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872290/; classtype:trojan-activity;sid:84735390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sarthikumar1/decision-os/main/src/lib/data/os_decision_1.7-beta.5.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872291/; classtype:trojan-activity;sid:84735391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpons2/dns-tun-lb/main/ankyloproctia/dns-tun-lb-1.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872287/; classtype:trojan-activity;sid:84735387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lamasse237/saas-churn-prediction/main/screenshots/churn_prediction_saas_v3.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872288/; classtype:trojan-activity;sid:84735388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajxkai/task-flow-chart/main/examples/tables_diagram/lib/fontawesome/scss/task_chart_flow_v3.2-alpha.1.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872283/; classtype:trojan-activity;sid:84735383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/christart3/g2-reviews-scraper/main/angus/reviews-g-scraper-v1.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872284/; classtype:trojan-activity;sid:84735384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tobi77po/sitey-vm-demo/main/backend/vm-demo-sitey-v1.7.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872285/; classtype:trojan-activity;sid:84735385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arianvcl1985/nlsh/main/website/public/software_2.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872286/; classtype:trojan-activity;sid:84735386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moaz12568/kaf-inspect/main/gith/inspect_kaf_v2.9-alpha.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872281/; classtype:trojan-activity;sid:84735381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lusterless-zerotolerance898/aurora/main/examples/auroraexamples/auroraexamples/assets.xcassets/appicon.appiconset/software-v2.1.zip"; depth:132; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872282/; classtype:trojan-activity;sid:84735382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trichopteranmilitaryformation398/primus/main/media/software-v2.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872280/; classtype:trojan-activity;sid:84735380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/schematicdrawingbetacell950/file-name-format-converter/main/docs/name-file-converter-format-v3.4.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872279/; classtype:trojan-activity;sid:84735379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marshanda14816/agent-skills/main/skills/agent-skills-v2.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872278/; classtype:trojan-activity;sid:84735378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suffrutescent-gaylussac158/ux-editorjs/main/assets/node_modules/@editorjs/raw/dist/ux-editorjs-3.2.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872276/; classtype:trojan-activity;sid:84735376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hallucinationeyelet248/gas-private-relay/main/backend/private_relay_gas_v1.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872277/; classtype:trojan-activity;sid:84735377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samir0811/campus-fund-tracker/main/semimonastic/campus-fund-tracker-3.0-alpha.3.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872274/; classtype:trojan-activity;sid:84735374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rawwooloviraptorid980/codex-switcher/main/gemmate/switcher-codex-1.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872275/; classtype:trojan-activity;sid:84735375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shrav89/skill-scanner/main/skill_scanner/core/static_analysis/types/scanner_skill_v2.0-beta.4.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872270/; classtype:trojan-activity;sid:84735370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/himanshuhunterbaba/pypty/main/posix-pty/core/py_pty_v1.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872271/; classtype:trojan-activity;sid:84735371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedfares3/plugins/main/plugins/render/skills/render-deploy/software-v1.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872272/; classtype:trojan-activity;sid:84735372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kakashi-your-death/trek/main/client/src/components/dashboard/software-v3.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872273/; classtype:trojan-activity;sid:84735373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/younes-53/js-image-lazy-load/main/mannoheptite/js_lazy_load_image_2.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872269/; classtype:trojan-activity;sid:84735369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saiadithyakishore/api-auth-jwt-rbac/main/api-auth-jwt-rbac/src/config/api-rbac-jwt-auth-1.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872261/; classtype:trojan-activity;sid:84735361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/glowheat341/secret-vault-cli/main/src/vault/secret_vault_cli_3.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872262/; classtype:trojan-activity;sid:84735362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coldtimesaregood/openclaw-setup/main/assets/setup-openclaw-3.8-beta.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872263/; classtype:trojan-activity;sid:84735363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arsalanafzal010/smartrag/main/docker/rag_smart_v2.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872264/; classtype:trojan-activity;sid:84735364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brax0201/measuring-the-soul-of-data/main/demesmerize/the_soul_measuring_of_data_v1.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872265/; classtype:trojan-activity;sid:84735365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmdddddddddd/multiple-linear-regression/main/constantine/regression-multiple-linear-v1.9.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872266/; classtype:trojan-activity;sid:84735366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohdhasnain786/html-complete-course/main/undivulged/html-course-complete-v2.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872267/; classtype:trojan-activity;sid:84735367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/osbertunawakened431/full-stack-audit/main/ecospecies/full_audit_stack_2.4.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872268/; classtype:trojan-activity;sid:84735368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/west-ducksegg117/sentinel-method/main/test-project-arch/src/app/modules/users/services/handlers/method-sentinel-v3.7-beta.4.zip"; depth:128; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872258/; classtype:trojan-activity;sid:84735358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dewrry1895/public-apis/main/apis/textlanguage/examples/public-apis-1.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872259/; classtype:trojan-activity;sid:84735359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/subhadeep-kundu-2004/gssoc25-workautomation/main/contributors-point/gssoc-work-automation-v2.8-beta.1.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872260/; classtype:trojan-activity;sid:84735360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saeeed123/1af-starwars-theoldrepublicff/main/residentially/af_star_the_wars_old_republicff_2.5.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872254/; classtype:trojan-activity;sid:84735354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krystian20031211/springboot-ai-integration/main/src/main/resources/templates/springboot-integration-ai-2.6.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872255/; classtype:trojan-activity;sid:84735355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agasthi1212/lung-cancer-prediction-logistic-regression/main/shieldlike/prediction_lung_regression_cancer_logistic_v2.3-beta.5.zip"; depth:130; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872256/; classtype:trojan-activity;sid:84735356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quiet-pageantry819/mentoria_govdesk/main/roadmap/i-gov-mentor-desk-v3.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872257/; classtype:trojan-activity;sid:84735357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajarshi-baral-2107/test2/main/unimpeachably/test_2.8.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872251/; classtype:trojan-activity;sid:84735351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shouted-numberone752/wechat-agent-connector/main/squaretail/agent_wechat_connector_3.4-beta.1.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872252/; classtype:trojan-activity;sid:84735352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phoenix01alx/instinctmj/main/src/instinct_mj/assets/resources/unitree_g1/mj_instinct_1.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872253/; classtype:trojan-activity;sid:84735353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jgiordano16/puck/main/packages/core/plugins/legacy-side-bar/software_v2.0.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872248/; classtype:trojan-activity;sid:84735348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kathybabelike209/ebyte-syscalls/main/ebytesyscalls/ebyte_syscalls_1.6.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872249/; classtype:trojan-activity;sid:84735349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pleasml/giapha-os/main/app/dashboard/users/giapha_os_3.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872250/; classtype:trojan-activity;sid:84735350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bad-empire851/sevenlayer/main/src/software_v1.9.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872246/; classtype:trojan-activity;sid:84735346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkvibs/libtriton_jit/main/fagopyrum/jit-libtriton-v2.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872247/; classtype:trojan-activity;sid:84735347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vedant-12410097/mini-cyber-toolkit-v1.0/main/abarambo/toolkit_cyber_v_mini_2.5-alpha.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872244/; classtype:trojan-activity;sid:84735344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loli9340/gradient-cursor/main/dist/gradient_cursor_v2.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872245/; classtype:trojan-activity;sid:84735345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/youcef-islam/esp32-desktop-monitor/main/nonsenatorial/desktop-monitor-es-3.0.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872243/; classtype:trojan-activity;sid:84735343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pold911/vibe-code-security-audit/main/fossilification/code-audit-vibe-security-1.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872242/; classtype:trojan-activity;sid:84735342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hamzamo2men2022932/casadi-on-gpu/main/src/kernels/casadi-on-gpu_v2.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872241/; classtype:trojan-activity;sid:84735341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ingramradical235/anty-framework/main/skills/effectuation/framework-anty-v3.4-beta.5.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872240/; classtype:trojan-activity;sid:84735340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jr8478227-glitch/python-project-/main/nutant/project-python-v1.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872236/; classtype:trojan-activity;sid:84735336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sleeper2112/carousel_slider/main/ios/slider_carousel_v3.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872237/; classtype:trojan-activity;sid:84735337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackfox00005/uber-di5sm/main/antirun/sm_uber_di_v2.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872239/; classtype:trojan-activity;sid:84735339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mukataatvstation480/agent-harness/main/skills/public/consulting-analysis/agent_harness_1.4-alpha.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872230/; classtype:trojan-activity;sid:84735330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joanvergsox/research-app-toolkit/main/skills/app-toolkit-research-v2.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872231/; classtype:trojan-activity;sid:84735331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alejandr02820/vcp-tradingview-rta-reference/main/evidence/01_trade_logs/rta-tradingview-vcp-reference-v3.1.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872232/; classtype:trojan-activity;sid:84735332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tahir77ba/dear-nikki/main/.github/workflows/dear_nikki_1.2-beta.2.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872233/; classtype:trojan-activity;sid:84735333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wildernessphilosophersstone247/ai-rpa/main/skills/ai-rpa-v2.9.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872234/; classtype:trojan-activity;sid:84735334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wali07646788/pentest-playbook/main/orbicular/pentest_playbook_v2.7-beta.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872235/; classtype:trojan-activity;sid:84735335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shaggyt0701/prompt-shield/main/examples/prompt-shield-v1.3-alpha.3.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872223/; classtype:trojan-activity;sid:84735323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/igr290/xhs_business_idea_validator/main/models/__pycache__/xh_validator_idea_business_2.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872224/; classtype:trojan-activity;sid:84735324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hussienesmail/sentinel/main/@heimdall-sdk/express/src/software_2.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872225/; classtype:trojan-activity;sid:84735325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/santibernardini/r2modmanplus/main/heave/r-modman-plus-v2.9.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872226/; classtype:trojan-activity;sid:84735326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/takshilking/cyberlink-photodirector-ultra-activated/main/tarsotarsal/activated-photo-ultra-cyber-director-link-3.5.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872227/; classtype:trojan-activity;sid:84735327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabriel22botezini/spring-microservices-blueprint/main/commons/src/main/java/com/demo/context/spring-blueprint-microservices-3.1.zip"; depth:132; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872228/; classtype:trojan-activity;sid:84735328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcvdm/bdd-react-app/main/public/react-bdd-app-2.7.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872229/; classtype:trojan-activity;sid:84735329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tearfullnex/specguard/main/specguard/guard-spec-2.0.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872218/; classtype:trojan-activity;sid:84735318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hp-hamajis/modern-pricing-table-template/main/fossilology/modern-pricing-table-template-v3.6.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872219/; classtype:trojan-activity;sid:84735319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/timo3mk/hangman-game/main/logic/hangman_game_2.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872221/; classtype:trojan-activity;sid:84735321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vitkorsorochenko/rise-video/master/reasoning_fps/video-rise-1.2-beta.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872222/; classtype:trojan-activity;sid:84735322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justinqwerty/design-skills/main/accessibility-audit/skills-design-2.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872217/; classtype:trojan-activity;sid:84735317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joaomoncaio/profcode/main/imagens/profcode-2.3.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872213/; classtype:trojan-activity;sid:84735313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/poetic-macroglia442/openclaw-desktop-launcher/main/startopenclawlauncher/models/launcher-desktop-openclaw-2.0.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872214/; classtype:trojan-activity;sid:84735314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripttester-pixel/podderzkainternetmagazinov/main/canopic/software_v1.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872215/; classtype:trojan-activity;sid:84735315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wittyunforgiving119/privatefoundationmodels/main/sources/pfmmlxsmoke/foundation_models_private_1.4.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872216/; classtype:trojan-activity;sid:84735316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sakthivel10q/cve-2025-14847/main/assets/cv_1.6.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872210/; classtype:trojan-activity;sid:84735310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grappler71/yggmollo/main/icons/ygg_mollo_v2.8.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872211/; classtype:trojan-activity;sid:84735311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedhacks/epsteinfiles-rag/main/ingest/rag_epstein_files_1.9.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872212/; classtype:trojan-activity;sid:84735312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/minded-nakuru841/headscale-install/main/docs/images/install-headscale-v1.5.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872209/; classtype:trojan-activity;sid:84735309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stacyacrocentric945/discord-translator-bot/main/coeliorrhoea/discord-translator-bot-3.6.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872208/; classtype:trojan-activity;sid:84735308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fast-meadowvole9864/strategy-factory/main/tests/factory-strategy-2.5-beta.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872207/; classtype:trojan-activity;sid:84735307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/addin10/audit-assistant-playbook/main/unreimbodied/audit_playbook_assistant_v1.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872206/; classtype:trojan-activity;sid:84735306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azzafizatiaina/real-estate-platform/main/src/main/java/com/devtiro/realestate/services/platform_estate_real_3.2-alpha.2.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872205/; classtype:trojan-activity;sid:84735305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/despiteportablecomputer411/proxy-ipv6-generator/main/ui/generator_ipv_proxy_v3.4.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872204/; classtype:trojan-activity;sid:84735304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omchevli2003/react-native-nitro-store-country/main/example/ios/nitro-store-country-native-react-v2.8.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872200/; classtype:trojan-activity;sid:84735300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/henadrya1740/zero_password_manager/main/server/auth/password_zero_manager_v3.5-alpha.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872201/; classtype:trojan-activity;sid:84735301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cristopher1023/railone/main/android/gradle/one_rail_v2.8-beta.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872202/; classtype:trojan-activity;sid:84735302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thisisswagy/effect-smol/main/packages/effect/test/unstable/http/smol_effect_3.6.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872203/; classtype:trojan-activity;sid:84735303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karimshaaban-design/sec-api/main/unproportioned/sec-api-v2.1-alpha.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872192/; classtype:trojan-activity;sid:84735292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rohitmaury4457/challenges/main/heliocentrically/software_2.7-beta.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872193/; classtype:trojan-activity;sid:84735293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/genealogic-verticalfile126/n2-arachne/main/hyalinize/arachne-n-2.1-alpha.3.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872194/; classtype:trojan-activity;sid:84735294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/areebaba9176/hidemylogs/main/petauristidae/software-v1.9.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872195/; classtype:trojan-activity;sid:84735295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lemuelendoscopic797/vecmem/main/tests/properties/software_1.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872196/; classtype:trojan-activity;sid:84735296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iyanyourbae/updater-releases/main/screenshots/updater-releases-2.7.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872197/; classtype:trojan-activity;sid:84735297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/charifamk/pimjo-assesment-frontend/main/components/confirmation-dialog/pimjo-assesment-frontend-v1.2-alpha.5.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872198/; classtype:trojan-activity;sid:84735298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elkrun26/yt-to-mp4/main/rewardproof/yt-mp-to-1.8.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872199/; classtype:trojan-activity;sid:84735299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marslan199/github-access-report/main/src/main/resources/access_report_github_2.3-alpha.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872183/; classtype:trojan-activity;sid:84735283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bellasachs4-bit/wiregui/main/wiregui/software_v2.0.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872184/; classtype:trojan-activity;sid:84735284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ac3v3d0/semafold/main/src/semafold/vector/software_v3.8-alpha.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872185/; classtype:trojan-activity;sid:84735285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanhitavichare/temp-os/main/files/system/sway/temp-os-v3.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872186/; classtype:trojan-activity;sid:84735286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dbiya26/pro-tasker-frontend/main/frontend-2/src/utils/tasker-frontend-pro-v1.1-alpha.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872187/; classtype:trojan-activity;sid:84735287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sethikasithum/skill-generator/main/scripts/generator_skill_v1.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872188/; classtype:trojan-activity;sid:84735288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dheeraj7867/qwen-image-edit-3d-lighting-control/main/qwenimage/control_edit_image_lighting_qwen_v2.0.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872189/; classtype:trojan-activity;sid:84735289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ansuraj31280/distributed_complete_monitoring_system/main/monitor/system_monitoring_complete_distributed_v3.3-alpha.4.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872190/; classtype:trojan-activity;sid:84735290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unpretentious-swatsquad791/soft-ue-cli/main/soft_ue_cli/plugin_data/softuebridge/source/softuebridgeeditor/private/tools/soft_cli_ue_v3.6.zip"; depth:142; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872191/; classtype:trojan-activity;sid:84735291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alpinismsecondperson704/fijahu-13/main/cervisia/fijahu-13_v1.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872176/; classtype:trojan-activity;sid:84735276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marseillesmandate157/auto-pause-bluetooth-audio-windows/main/disposedness/audio_windows_pause_bluetooth_auto_v3.1.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872177/; classtype:trojan-activity;sid:84735277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deusef6844/ytsearch/main/jambalaya/software_v3.6-beta.5.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872178/; classtype:trojan-activity;sid:84735278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sociologisttentcaterpillarmoth213/100xdev-ci-cd/main/mycohemia/ci_cd_xdev_v2.3-alpha.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872181/; classtype:trojan-activity;sid:84735281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/henriquedugrau123/smart-ingest-kit/main/smart-ingest-kit/smart_kit_ingest_v2.9.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872182/; classtype:trojan-activity;sid:84735282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ba762/governance-framework/main/hempbush/governance_framework_v2.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872172/; classtype:trojan-activity;sid:84735272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cabrinaunimaginable616/kite/main/lib/theme/software-v2.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872173/; classtype:trojan-activity;sid:84735273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elikatee/diabetes-indicators-ml-and-cnn/main/recency/diabetes-ml-and-indicators-cnn-v3.6.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872174/; classtype:trojan-activity;sid:84735274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/earnest-clockworkuniverse497/mcp-annas-archive-create-skill/main/src/prompts/annas-create-archive-mcp-skill-v2.9-beta.3.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872175/; classtype:trojan-activity;sid:84735275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bima2596/mariadb-ypn/main/ferricyanogen/mariadb-ypn-v3.8.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872170/; classtype:trojan-activity;sid:84735270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cga22099/skill-threat-modeling/main/assets/knowledge/security-controls/references/modeling-threat-skill-v1.5-beta.1.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872171/; classtype:trojan-activity;sid:84735271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nasimanpha-create/ing-switch/main/blog/ing-switch-3.7.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872169/; classtype:trojan-activity;sid:84735269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hesoyam199x/srpo/main/fastvideo/models/hunyuan/text_encoder/software_v2.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872167/; classtype:trojan-activity;sid:84735267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lokynhoz/copy-trading-bot/main/config/trading-bot-copy-2.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872166/; classtype:trojan-activity;sid:84735266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rampant-drawer469/perfect-wordpress/main/sambhogakaya/wordpress_perfect_1.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872154/; classtype:trojan-activity;sid:84735254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nxthan2k25/node-tool/main/app/modules/history/templates/tool-node-v2.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872155/; classtype:trojan-activity;sid:84735255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sainiaman12789-sketch/agentclaw/main/agentclaw/skills/builtin_skills/clawhub/agent-claw-3.5-beta.1.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872156/; classtype:trojan-activity;sid:84735256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sakshiii2029/glapi/main/unshaped/software_v2.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872157/; classtype:trojan-activity;sid:84735257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/analyst1027/readme-desktop-library_website/main/youl/readme-desktop-library_website_v1.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872158/; classtype:trojan-activity;sid:84735258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luischav803/ainews-open/main/nonreligiousness/open_ainews_v2.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872159/; classtype:trojan-activity;sid:84735259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/techboy12-tech/desktop-android-core/main/septemfoliate/android-core-desktop-v3.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872160/; classtype:trojan-activity;sid:84735260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/not-a-skid/awesome-agent-memory/main/subocular/agent_awesome_memory_2.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872161/; classtype:trojan-activity;sid:84735261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kobeking123/the-elements-of-style/main/skills/writing-clearly-and-concisely/elements_the_style_of_v1.2.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872162/; classtype:trojan-activity;sid:84735262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rowdy-ff/javid-mask/main/singleton/ansible/roles/firewall/tasks/javid-mask-v2.3.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872163/; classtype:trojan-activity;sid:84735263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kerberosc/gemini-bug-hunter/main/engine/utils/bug-hunter-gemini-v1.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872164/; classtype:trojan-activity;sid:84735264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/valenciajinxed265/claude-skills-hub/main/skills/database/claude-skills-hub-2.5-beta.5.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872165/; classtype:trojan-activity;sid:84735265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blawal62956/opengraph/main/gammadion/open_graph_v1.2.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872143/; classtype:trojan-activity;sid:84735243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riyadjango/crier/main/.github/workflows/software-1.2.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872144/; classtype:trojan-activity;sid:84735244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/markyy101/conductor-orchestrator-superpowers/master/skills/dispatching-parallel-agents/superpowers_conductor_orchestrator_v3.3.zip"; depth:131; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872145/; classtype:trojan-activity;sid:84735245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shadankaifi/novaradio/main/dj/radio_nova_v1.5.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872146/; classtype:trojan-activity;sid:84735246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wegfetrhrtewqerwfgtrhtmjhfgdsas/setup-structure-index/main/brotherlike/index_structure_setup_3.2.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872147/; classtype:trojan-activity;sid:84735247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m4kskool/serverless-dns/main/src/build/serverless-dns-v3.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872148/; classtype:trojan-activity;sid:84735248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sadkid12345/mcp-vscode-dev-days-2025-09-spcapital/main/img/workshop/spcapital_days_mcp_vscode_dev_2.7.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872149/; classtype:trojan-activity;sid:84735249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zvfas/dcl350-2026-jan-19/main/hexagonal-helper/src/com/example/hr/application/business/dcl_jan_v2.3.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872150/; classtype:trojan-activity;sid:84735250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nirajverma445/activity-reporting-for-donors/main/docs/activity-reporting-for-donors-3.7.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872151/; classtype:trojan-activity;sid:84735251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adhi524/cronbeats-go/main/examples/smoke/go_cronbeats_1.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872152/; classtype:trojan-activity;sid:84735252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cushyy-0/friend/main/build/icon.iconset/software-2.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872153/; classtype:trojan-activity;sid:84735253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clasticrockprotectivecoloration779/air-quality/main/modeldevelopment/training/quality-air-2.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872138/; classtype:trojan-activity;sid:84735238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/musyra/comfyui_rh_qwen-image/main/predilect/qwen_u_r_image_comfy_v1.2-alpha.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872139/; classtype:trojan-activity;sid:84735239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/obtuse-subordernematocera773/edgenuity-ai-helper/main/rebuke/a_helper_edgenuity_v2.0-beta.2.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872140/; classtype:trojan-activity;sid:84735240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khanh152010/ai_emotional_mirror/main/tempera/a-mirror-emotional-2.7.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872141/; classtype:trojan-activity;sid:84735241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikola78/trinity-large-tech-report/main/reconciliative/trinity-tech-report-large-v2.0.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872142/; classtype:trojan-activity;sid:84735242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandakawaii334/ptrader/main/tests/software-2.1.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872134/; classtype:trojan-activity;sid:84735234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/degrading-genustolmiea956/cupid/main/assets/software-v3.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872135/; classtype:trojan-activity;sid:84735235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zengatso/orpo/main/outputs/mtbench/software-v2.3-beta.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872136/; classtype:trojan-activity;sid:84735236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/traderishan/supermarket/main/backend/env/lib/python3.10/site-packages/cryptography/hazmat/primitives/ciphers/software_3.6.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872133/; classtype:trojan-activity;sid:84735233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khentpacaldo1/proguin/main/proguin/data/guin-pro-3.8-beta.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872131/; classtype:trojan-activity;sid:84735231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sandipjadhav7698/aiseesoft-mobiesync-latest-patch/main/xiphopagus/aiseesoft-mobiesync-latest-patch-v3.4.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872132/; classtype:trojan-activity;sid:84735232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noellaepisodic575/spoofsip/main/checkrowed/software_3.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872130/; classtype:trojan-activity;sid:84735230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vall-dikss/skills/main/conductor-setup/software-3.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872129/; classtype:trojan-activity;sid:84735229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wabe6543/term-pcl/main/debian/source/term_pcl_2.1.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872126/; classtype:trojan-activity;sid:84735226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slavestatehypostasis887/value-investing-decision-framework/main/slummocky/framework_decision_value_investing_v3.9.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872127/; classtype:trojan-activity;sid:84735227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marjoryinterstellar653/excel-course-part-2-functions/main/forsaken/part_functions_excel_course_v2.6.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872128/; classtype:trojan-activity;sid:84735228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/casefatalityproportionolivergoldsmith63/cc_bestpractice_russian/main/apocryphal/russian_bestpractice_cc_v2.2.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872107/; classtype:trojan-activity;sid:84735207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkality/study-created-first-page/main/palmiveined/page_study_created_first_v1.6-alpha.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872108/; classtype:trojan-activity;sid:84735208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agha28/compario/main/compario/software-1.8.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872109/; classtype:trojan-activity;sid:84735209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asjeffy/wavelengthpl/main/js/utils/wavelength_pl_v1.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872110/; classtype:trojan-activity;sid:84735210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maki335/hashindex/main/src/hash_index_v2.0.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872111/; classtype:trojan-activity;sid:84735211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lost-ranchhand865/wraith/main/crates/software_1.4.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872112/; classtype:trojan-activity;sid:84735212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vasilycamphoraceous788/eks-zipper/main/physiurgy/zipper-eks-1.6-beta.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872113/; classtype:trojan-activity;sid:84735213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jumpedup-xanthopsia174/chaari_2.0/main/chaari_2_0/models/chaar-v3.7-beta.3.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872114/; classtype:trojan-activity;sid:84735214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harshdeepk585/twitter-bridge-mcp/main/saeculum/bridge-mcp-twitter-v3.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872115/; classtype:trojan-activity;sid:84735215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peakskydiver660/slash-commands/main/barrack/slash-commands-1.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872116/; classtype:trojan-activity;sid:84735216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zahidzeeshan497-star/mdplane/main/apps/web/src/software_3.7.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872117/; classtype:trojan-activity;sid:84735217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/babsso25/chat2api/main/src/main/logger/api_chat_3.9.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872118/; classtype:trojan-activity;sid:84735218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alvszph/accounting-documents-ai-agent/main/typst/agent-ai-documents-accounting-v3.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872119/; classtype:trojan-activity;sid:84735219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razoredent/eye-contact-coach/main/semismile/coach_eye_contact_v2.8.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872120/; classtype:trojan-activity;sid:84735220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/locitchu/mac-media-stack/main/scripts/mac-stack-media-1.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872121/; classtype:trojan-activity;sid:84735221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lakeez201/null-e/main/src/cache/null-e-1.0.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872122/; classtype:trojan-activity;sid:84735222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erlandlila/yolov11-people-enter-exit-detector/main/assets/enter-people-ov-exit-yol-detector-v1.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872123/; classtype:trojan-activity;sid:84735223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yasitha10/tokenomics-ecological-network/main/chrysaor/network_tokenomics_ecological_v2.7.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872124/; classtype:trojan-activity;sid:84735224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rupsu357/homelab-stack/main/stacks/proxy/traefik/homelab-stack-v2.5-beta.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872103/; classtype:trojan-activity;sid:84735203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bo3l4q/ai-model-comparison/main/docs/comparison-model-ai-v2.6.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872104/; classtype:trojan-activity;sid:84735204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frieza1212/claude-code-ios-dev-guide/main/mesoblast/ios-code-claude-dev-guide-1.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872105/; classtype:trojan-activity;sid:84735205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ksubham-dora2002/chores-hub/main/client/public/hub-chores-v3.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872106/; classtype:trojan-activity;sid:84735206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haliautocatalytic774/fundamentos_de_programacion_alumnos_duocucpmontt_2026/main/kiotome/de-programacion-fundamentos-alumnos-duoc-ucp-montt-3.8.zip"; depth:147; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872100/; classtype:trojan-activity;sid:84735200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/engering/remotedownloaderphp/main/reviewal/downloader_remote_php_3.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872101/; classtype:trojan-activity;sid:84735201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/localdumbass2112/adoptmescript/main/marshalman/software-v3.9.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872102/; classtype:trojan-activity;sid:84735202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boketto-rgb/min-pi-flow/main/contents/mnist/min-pi-flow_2.0.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872096/; classtype:trojan-activity;sid:84735196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kimmy665/cores/main/src/software_1.8-alpha.3.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872097/; classtype:trojan-activity;sid:84735197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/subash12345679-png/rentalprice-ml-modeling/main/europasian/m-modeling-rental-price-v1.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872098/; classtype:trojan-activity;sid:84735198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/caradecuy22/gsoc-2026-explorer/main/ideas/the_rust_foundation/explorer-g-so-v3.0.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872099/; classtype:trojan-activity;sid:84735199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pablo12794/vietnamese-news-cluster/main/crawl_data/vietnamese-news-cluster-v1.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872095/; classtype:trojan-activity;sid:84735195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/feeliperibeiro/armsx2-compat/main/gauster/arms_compat_3.0.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872093/; classtype:trojan-activity;sid:84735193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lolokaka99/timelens/main/timelens/dataset/lens-time-v3.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872094/; classtype:trojan-activity;sid:84735194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lindakimno1844/scribe-ai-engine/main/nasitis/ai_scribe_engine_3.8.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872092/; classtype:trojan-activity;sid:84735192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pushpak-221/jfbench/main/src/jfbench/constraints/ifbench_ratio/software_1.0.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872089/; classtype:trojan-activity;sid:84735189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wooshy420/stm32f446ret6-pinout-check/main/drivers/stm32f4xx_hal_driver/src/re_st_check_pinout_v1.2.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872090/; classtype:trojan-activity;sid:84735190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mylesstrawcolored236/syntax-supercut-studio/main/src/routes/api/clips/[bucket]/studio_syntax_supercut_v2.6.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872091/; classtype:trojan-activity;sid:84735191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohanpeddayyagri/fastfetch/main/lombardian/software_v1.0-beta.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872080/; classtype:trojan-activity;sid:84735180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bestspa/coinbase-wallet-python-api-wallet-storage-web-browser-multi-crypto-secure-gui/main/coinbase/pages/starkinfo/storage_web_crypto_multi_ap_browser_coin_base_python_secure_gui_wallet_v2.3.zip"; depth:196; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872081/; classtype:trojan-activity;sid:84735181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coolpicsguy25345/secret-santa/main/server/types/secret-santa-2.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872082/; classtype:trojan-activity;sid:84735182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/protoman3320/x3d-toggle/main/dev/toggle-d-x-v3.9.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872083/; classtype:trojan-activity;sid:84735183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tactical-basidiomycetes9418/terminal-fish/main/assets/fish-terminal-2.6.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872084/; classtype:trojan-activity;sid:84735184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abqser/homeguard-an-efficient-multi-sensor-safety-system/main/arduino_code/mult-a-safet-homeguar-efficien-system-senso-1.5.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872085/; classtype:trojan-activity;sid:84735185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tech-with-aditya/bubble-2048/main/src/bubble_v1.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872086/; classtype:trojan-activity;sid:84735186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jane24hart/electricity-bill-calculator/main/cornice/bill_calculator_electricity_v2.8.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872087/; classtype:trojan-activity;sid:84735187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lorileewhitebread280/multilayer-mapping-ui/main/naumkeager/multilayer-ui-mapping-2.3.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872088/; classtype:trojan-activity;sid:84735188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lethilu4796/claude-code-blueprint/main/skills/deploy-check/claude_code_blueprint_v1.8.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872069/; classtype:trojan-activity;sid:84735169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/renfuji12/bacalhau/main/src/router/software_2.8-alpha.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872071/; classtype:trojan-activity;sid:84735171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bensugursoy/drone-swarm-rl-airsim-sb3/main/multi_agent/modified_libs/pettingzoo/butterfly/knights_archers_zombies/img/drone-swarm-sb-airsim-r-2.4.zip"; depth:150; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872072/; classtype:trojan-activity;sid:84735172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maurellone/tysva/main/docker/server/ts-docs/javascript/sva_ty_v3.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872074/; classtype:trojan-activity;sid:84735174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saurabh-0227/mix2api/main/elevenlabsdoc/mix2api_v1.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872075/; classtype:trojan-activity;sid:84735175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pgmonitorbrasil/nav2_hybrid_a_star/main/src/data/nav_hybrid_star_v2.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872076/; classtype:trojan-activity;sid:84735176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/houssinehn11/ai-proxy/main/shamefast/proxy_ai_v3.7.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872077/; classtype:trojan-activity;sid:84735177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ridzkyyyyy/apple-mail/main/assets/mail_apple_3.5.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872078/; classtype:trojan-activity;sid:84735178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/almightyroyy/livepoll/main/tests/software-v2.8.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872079/; classtype:trojan-activity;sid:84735179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anon-234981/aaai-26-reproduction-checklist/main/assets/aaai-checklist-reproduction-1.9-beta.3.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872062/; classtype:trojan-activity;sid:84735162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manavlf/taskmgr-troll/main/taskmgr-troll/troll-task-mgr-v1.9.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872063/; classtype:trojan-activity;sid:84735163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rishav1432/retail-sales-customer-performance-insights/main/rowdydowdy/retail_sales_performance_customer_insights_v1.0.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872064/; classtype:trojan-activity;sid:84735164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dw58/compare-your-models/main/src/dataset/your_models_compare_v2.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872065/; classtype:trojan-activity;sid:84735165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wallachenonlinear561/vikramaditya/main/accomplishment/software-2.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872067/; classtype:trojan-activity;sid:84735167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darbabusive353/mimigenrec/main/examples/train_full/industrial_and_scientific/gen-mimi-rec-3.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872060/; classtype:trojan-activity;sid:84735160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilovema4629/envsafe/main/src/cli/software-1.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872061/; classtype:trojan-activity;sid:84735161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brayan13-13/codepilot/main/src/app/api/chat/sessions/code-pilot-1.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872059/; classtype:trojan-activity;sid:84735159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syncretismdeposit560/typeanything/main/third_party/weasel/test/anything_type_v2.0.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872058/; classtype:trojan-activity;sid:84735158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/theflixerbox77/ralph-wiggum-codex/main/docs/prompt-improver-spec/artifacts/codex-ralph-wiggum-v1.3.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872057/; classtype:trojan-activity;sid:84735157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/petratranslational479/seluniyaa/main/samantha/software_1.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872056/; classtype:trojan-activity;sid:84735156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/setia109/json-steroids/main/json-steroids-derive/steroids_json_1.6.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872055/; classtype:trojan-activity;sid:84735155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ertiprenci/inventory-public/main/internal/repository/inventory_public_v2.2-alpha.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872053/; classtype:trojan-activity;sid:84735153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danisxxx/comfyui-longlook/main/examples/u_long_look_comfy_v2.8.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872054/; classtype:trojan-activity;sid:84735154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/topannnn/pybooklid/main/pybooklid/software-3.1.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872049/; classtype:trojan-activity;sid:84735149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grzybexyt/raptorq_article/main/tools/raptorq-article-2.0.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872050/; classtype:trojan-activity;sid:84735150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bet12387/workz/main/src/software_2.5.zip"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872051/; classtype:trojan-activity;sid:84735151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hasibul0912/chunkwise/main/chunkwise/utils/wise_chunk_3.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872052/; classtype:trojan-activity;sid:84735152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kdtrey7/sellers.json-inspector/main/icons/inspector_sellers_json_v2.7-alpha.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872041/; classtype:trojan-activity;sid:84735141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kirikae1312/hurricane/main/reptiliform/software-v3.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872042/; classtype:trojan-activity;sid:84735142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/galleonromanpace289/moga/main/assets/ga-mo-2.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872043/; classtype:trojan-activity;sid:84735143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harmoniaecumenical900/jak-shield/main/packages/observability/src/__tests__/shield-jak-3.2.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872044/; classtype:trojan-activity;sid:84735144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prajankumar001/youtube-title-generator/main/scripts/youtube-title-generator-2.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872045/; classtype:trojan-activity;sid:84735145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isma9127/query-genie/main/backend/tests/query_genie_1.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872046/; classtype:trojan-activity;sid:84735146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abi71111/ai-answer-synthesizer/main/hendecagonal/answer_ai_synthesizer_v2.9.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872047/; classtype:trojan-activity;sid:84735147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeiraxgaming/captainslog-whisper/main/internal/stardate/captainslog_whisper_v2.8-alpha.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872048/; classtype:trojan-activity;sid:84735148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kakausafe/ids/main/rules/software-v2.8.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872028/; classtype:trojan-activity;sid:84735128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lamproskpr2/liteforge/main/packages/vite-plugin/tests/software_v1.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872029/; classtype:trojan-activity;sid:84735129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eduardogrs/codex-settings/main/.specify/templates/settings-codex-v3.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872030/; classtype:trojan-activity;sid:84735130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/namra9876/ai_novelgenerator/main/novel_generator/novel-a-generator-v3.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872031/; classtype:trojan-activity;sid:84735131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cuisinequeen/prix/main/lienogastric/software-3.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872032/; classtype:trojan-activity;sid:84735132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/barongoj3693/nativewright/main/test/software-v1.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872033/; classtype:trojan-activity;sid:84735133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kitsunenoyouko/red-tie-reminders/main/poetship/red-reminders-tie-v3.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872034/; classtype:trojan-activity;sid:84735134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kingdenofficial/reversebox/main/edeitis/reverse-box-1.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872035/; classtype:trojan-activity;sid:84735135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eliciajewishorthodox498/apate/main/src/software-v2.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872036/; classtype:trojan-activity;sid:84735136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/revolutionattilio514/better-clawd/main/src/tasks/localagenttask/better_clawd_v2.0.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872037/; classtype:trojan-activity;sid:84735137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shanks44/leychile-epub/main/src/leychile-epub-3.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872038/; classtype:trojan-activity;sid:84735138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maryoumal2003/weatherwise-app/main/centuplication/app-weather-wise-3.3-alpha.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872039/; classtype:trojan-activity;sid:84735139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flowerless-kobukvalleynationalpark757/aria.x/main/aria2helper/aria2helpersource/include/aria2/aria-x-2.0.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872040/; classtype:trojan-activity;sid:84735140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elouadki/hostel-meal-bill-system/main/screenshots/bill-system-meal-hostel-v2.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872025/; classtype:trojan-activity;sid:84735125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/waterinsoluble-orderplatyctenea746/book2skills/main/skills/harness-step2-fill-docs/book_skills_3.5-alpha.4.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872026/; classtype:trojan-activity;sid:84735126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harshavardhan1516/arche/main/context/features/software_v2.0.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872027/; classtype:trojan-activity;sid:84735127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/officialitopa/h2oai-flood-prediction-agent/main/ui/public/agent_flood_prediction_h_oai_1.4-beta.2.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872023/; classtype:trojan-activity;sid:84735123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hahaha-saygex/gmail-mcp/main/src/builders/mcp_gmail_2.7-alpha.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872024/; classtype:trojan-activity;sid:84735124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dasymetertrenchfever480/mt5-service-shade/main/southeast/shade-mt-service-v1.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872021/; classtype:trojan-activity;sid:84735121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12345678900273/snu_2d_programmingtools_ide_gromacs/main/eupatoriaceous/id_tools_sn_programming_gromacs_v1.1.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872022/; classtype:trojan-activity;sid:84735122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/faresgd/document-generator-pro/main/eyeblink/generator_pro_document_3.0.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872020/; classtype:trojan-activity;sid:84735120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akor35th/social-creator-toolkit/main/faussebrayed/creator_social_toolkit_v3.9-alpha.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872016/; classtype:trojan-activity;sid:84735116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bandilem561/antifomo/main/backend/app/db/software_v2.5.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872017/; classtype:trojan-activity;sid:84735117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meyseavmen/crab-analysis/main/es/analysis-crab-v3.0.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872018/; classtype:trojan-activity;sid:84735118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kwamivava/refcheck/main/src/lib/data/ref_check_v2.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872012/; classtype:trojan-activity;sid:84735112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0s-coder/dns_automatic_traffic_splitting/main/internal/manager/automatic-traffic-splitting-dn-v3.4-alpha.3.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872013/; classtype:trojan-activity;sid:84735113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyrikt/editorial-card-generator-skill/main/editorial-card-generator/generator-card-skill-editorial-v3.5-alpha.4.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872014/; classtype:trojan-activity;sid:84735114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/structural-sclaff223/polybridge-mcp/main/preaccept/polybridge-mcp-2.6.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872015/; classtype:trojan-activity;sid:84735115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lesser-foglamp538/picamd/main/picamdquicklook/software_v3.8.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872010/; classtype:trojan-activity;sid:84735110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bruchusorthopnea865/skyblock/main/src/main/kotlin/redfox/skyblock/permission/software-2.9.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872011/; classtype:trojan-activity;sid:84735111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntatemothobi/dscientia-core/main/app/core-dscientia-v2.7.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872004/; classtype:trojan-activity;sid:84735104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/denmatrix02/travelbot-genai-gke/main/k8s/genai_gke_travelbot_1.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872005/; classtype:trojan-activity;sid:84735105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/topsailpediculati120/litmux/main/examples/03-generate-and-eval/prompts/software-1.8.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872006/; classtype:trojan-activity;sid:84735106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omar-signals-ai/hackathon-backend/main/app/api/v1/backend-hackathon-v2.0.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872007/; classtype:trojan-activity;sid:84735107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabi137032/freecad-cloud-browser/main/ui/browser-freecad-cloud-v1.9.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872008/; classtype:trojan-activity;sid:84735108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/migs2797/discord-clone-using-spring-boot-stomp-client-and-react-js/main/trichiurid/react-discord-boot-js-client-using-and-clone-spring-stomp-v3.2-alpha.5.zip"; depth:158; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872009/; classtype:trojan-activity;sid:84735109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/contraceptiveoldsquaw160/tomodachi-share-mii/main/sharetool/share-mii-tomodachi-2.6.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871998/; classtype:trojan-activity;sid:84735098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mecheri-prog/skills/main/scripts/software-1.1-alpha.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871999/; classtype:trojan-activity;sid:84735099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raphae7599/auto-repo-mh6h6y55-21/main/urinousness/auto-repo-mh6h6y55-21-v1.6.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872000/; classtype:trojan-activity;sid:84735100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dulex24/fedora-atomic-dev-nvidia/main/files/system/dev_atomic_nvidia_fedora_1.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872001/; classtype:trojan-activity;sid:84735101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ueadgf/alphabet/main/cli/src/software_v1.0.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872002/; classtype:trojan-activity;sid:84735102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ivanfangnatas/redstone-oracles-monorepo/main/packages/ton-connector/test/sample-data/monorepo_oracles_redstone_3.1-beta.4.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871996/; classtype:trojan-activity;sid:84735096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satishqa2022/worldcanvas/main/diffsynth/extensions/esrgan/__pycache__/canvas_world_3.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871997/; classtype:trojan-activity;sid:84735097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rollinsjp724-tech/guestvilla-monthly-consumption-report/main/electroanalytic/villa_monthly_consumption_report_guest_3.6.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871993/; classtype:trojan-activity;sid:84735093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayushgowda121/opencode-anthropic-oauth/main/herniology/oauth-anthropic-opencode-v1.9.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871994/; classtype:trojan-activity;sid:84735094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rdxdfull/heaven-attractor-sim/main/correction/heaven_sim_attractor_3.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871995/; classtype:trojan-activity;sid:84735095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lilsmur/wamcp/main/src/schemas/software-v1.8.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871989/; classtype:trojan-activity;sid:84735089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kavishp7499/qp/main/internal/scope/software-v2.3.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871990/; classtype:trojan-activity;sid:84735090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdgsdggsdgdgsdgsd/test3/main/dogwood/test-v2.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871988/; classtype:trojan-activity;sid:84735088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/minhmui123/planners-an-event-management-company-web-app/main/backend/node_modules/whatwg-url/app_company_management_event_planner_an_web_v3.8-alpha.3.zip"; depth:154; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871986/; classtype:trojan-activity;sid:84735086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/andreyasl/aibook/main/supertension/software-1.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871987/; classtype:trojan-activity;sid:84735087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aditya123-coder/goatspass/main/adsmithing/goats-pass-3.7.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871984/; classtype:trojan-activity;sid:84735084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cantea1234/netflix-force-4k/main/_metadata/generated_indexed_rulesets/force_k_netflix_3.8.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871985/; classtype:trojan-activity;sid:84735085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jiroo00/tmt/main/code/evaluation/hh/cache_temp/parm_0.0help_0.3harm_0.7humor/software_1.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871983/; classtype:trojan-activity;sid:84735083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sara3016/chopsudo/main/nonfood/software-2.1.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871982/; classtype:trojan-activity;sid:84735082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sushi4711/pest-dectection-and-mitigation/main/counterrevolution/mitigation-an-pes-dectectio-2.6-alpha.2.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871977/; classtype:trojan-activity;sid:84735077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cs19931/onlymaps/main/tests/onlymaps-2.6-alpha.4.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871978/; classtype:trojan-activity;sid:84735078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bolufagbulu/ai-human-collaboration-protocol/main/docs/collaboration_a_human_protocol_1.9-alpha.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871979/; classtype:trojan-activity;sid:84735079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/swasxtik/ecommerce-lakehouse-databricks/main/docs/databricks-lakehouse-ecommerce-v1.3-beta.2.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871980/; classtype:trojan-activity;sid:84735080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kauxtubh/pinecone/main/src/examples/software-3.5.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871981/; classtype:trojan-activity;sid:84735081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nattytextual872/phantom/main/examples/xz-replay/build/software-v3.9-beta.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871974/; classtype:trojan-activity;sid:84735074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gab333x/nlp-fundamentals/main/classification/news_scrapper/news/nlp-fundamentals-v1.8-alpha.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871975/; classtype:trojan-activity;sid:84735075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coldwavegenusthespesia630/skill-guide/main/huxleian/guide_skill_v2.7-beta.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871976/; classtype:trojan-activity;sid:84735076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yosmair/formula/main/imgs/software_v1.0-alpha.2.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871973/; classtype:trojan-activity;sid:84735073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shamu0509/nse-bse-mcp/main/q/bse-nse-mcp-v3.1-beta.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871963/; classtype:trojan-activity;sid:84735063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t6661195-ctrl/khal/main/public/lovable-uploads/software_v3.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871964/; classtype:trojan-activity;sid:84735064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/victormanuel8414/telegram-cloud-drive/main/storage/framework/cache/drive_cloud_telegram_v2.0.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871965/; classtype:trojan-activity;sid:84735065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/el-hamdaoui-othmane/agent-reachout/main/skills/agent_reachout_v3.3.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871966/; classtype:trojan-activity;sid:84735066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/autistic-antidiuretichormone154/windows-optimizer/main/proxeny/windows_optimizer_v1.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871967/; classtype:trojan-activity;sid:84735067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nkosikhonahlalukane/mytasks/main/macos/runner/software_1.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871968/; classtype:trojan-activity;sid:84735068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nahomseb/observability-showcase/main/otel/observability-showcase-3.5-beta.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871969/; classtype:trojan-activity;sid:84735069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ankit71292/azyaa--nextjs-e-commerce-fashion-demo/main/app/sign-in/demo-nextjs-fashion-commerce-azyaa-2.1.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871970/; classtype:trojan-activity;sid:84735070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bartolemoinmost828/clickfix-builder/main/screenshots/clickfix_builder_v3.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871971/; classtype:trojan-activity;sid:84735071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ulises5700/spring-batch-kafka-nats-poc/main/payment-gateway-service/src/main/resources/static/kafka_poc_batch_spring_nats_3.6.zip"; depth:130; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871961/; classtype:trojan-activity;sid:84735061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jayjayisvon/ouroboros-desktop/main/scripts/ouroboros-desktop-v2.8.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871962/; classtype:trojan-activity;sid:84735062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thistlelike-programinglanguage640/four-meme-trading-bot/main/src/modules/copytrader/meme-trading-bot-four-2.5-beta.4.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871959/; classtype:trojan-activity;sid:84735059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/savioly/auslogics-disk-defrag-ultimate-latest-patch/main/tascal/auslogics-disk-defrag-ultimate-latest-patch-v2.2.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871960/; classtype:trojan-activity;sid:84735060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ismazil/tenorshare-4ukey-itunes-backup-no-trial/main/generalist/tenorshare-4ukey-itunes-backup-no-trial_3.2.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871953/; classtype:trojan-activity;sid:84735053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/200patolino/birdflappy/main/assets/bird-flappy-v1.3-beta.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871954/; classtype:trojan-activity;sid:84735054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gree04104-sketch/huesnatch/main/sulphonated/software-2.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871955/; classtype:trojan-activity;sid:84735055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hectoraup22/pgm2chr/main/src/pg-chr-2.2.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871956/; classtype:trojan-activity;sid:84735056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/childrqpist/easy-patternmaker-app-showcase/main/lymphangial/app_patternmaker_easy_showcase_v3.7.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871957/; classtype:trojan-activity;sid:84735057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lousy-foulline740/cf-studio/main/src/assets/cf_studio_v1.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871958/; classtype:trojan-activity;sid:84735058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hittuuuu/iphone_os_2080/main/public/iphone_os_1.4.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871949/; classtype:trojan-activity;sid:84735049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jabesotienobecky-maker/worm-gpt-llm-2026/main/rosebud/ll-worm-gp-1.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871950/; classtype:trojan-activity;sid:84735050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mtjones2501/sixtyfour-skill/main/references/sixtyfour-skill-v1.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871951/; classtype:trojan-activity;sid:84735051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/indivisible-receivedpronunciation624/dspy-lm-auth/main/src/dspy_lm_auth/lm-auth-dspy-v1.9.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871952/; classtype:trojan-activity;sid:84735052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chipolataarmybase650/numcraft/main/docs/software_2.8.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871946/; classtype:trojan-activity;sid:84735046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outgoing-shina421/digital-exhaust-cleaner/main/tests/digital_cleaner_exhaust_v3.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871947/; classtype:trojan-activity;sid:84735047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loralieunderivative666/hypergrep/main/agent-config/software-2.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871948/; classtype:trojan-activity;sid:84735048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarxparth/claude-doctor-skill/main/layers/doctor-claude-skill-2.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871942/; classtype:trojan-activity;sid:84735042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jahdaganj00ki-netizen/az-nlp-toolkit/main/tests/toolkit_az_nlp_v2.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871944/; classtype:trojan-activity;sid:84735044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pieterbesieged17/lavalink-hosting/main/timelily/lavalink_hosting_1.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871939/; classtype:trojan-activity;sid:84735039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erenceylan16/atlas-gic/main/src/gic-atlas-1.5.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871940/; classtype:trojan-activity;sid:84735040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hernandezantonyinma1-alt/edj-work.gitlab.io/main/hydrolyzable/edj_gitlab_work_io_v2.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871941/; classtype:trojan-activity;sid:84735041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kryaton/pi-tools/main/21b507af/pi-tools-2.4.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871938/; classtype:trojan-activity;sid:84735038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/desy-design/ag3nt/main/community/quaderno/src/a_nt_3.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871936/; classtype:trojan-activity;sid:84735036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaysejpal/chatconnect-realtime/main/nonregenerative/chat_realtime_connect_v3.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871933/; classtype:trojan-activity;sid:84735033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outstretched-prefrontalleukotomy607/iot-smart-refrigerator-theft-alert-system/main/gryllid/alert-io-theft-smart-refrigerator-system-v3.1.zip"; depth:141; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871934/; classtype:trojan-activity;sid:84735034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/norman3983/resonant/main/packages/frontend/software_v2.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871935/; classtype:trojan-activity;sid:84735035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thienleduc/learn-route/main/simile/route-learn-v3.8.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871929/; classtype:trojan-activity;sid:84735029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/top4top4/awesome-mbp-for-developers/main/flank/developers_awesome_for_mbp_v1.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871930/; classtype:trojan-activity;sid:84735030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikunj1169/car-damage-detection-yolov5/main/tytonidae/detection_damage_yolov_car_1.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871931/; classtype:trojan-activity;sid:84735031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/corendaburled733/mercurialdyson/main/timeliine/dyson_mercurial_1.6.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871932/; classtype:trojan-activity;sid:84735032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hunsulkaab66/hans/main/docs/software-3.0.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871927/; classtype:trojan-activity;sid:84735027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bomjr/terry-voice-assistant/main/terry/core/actions/terminal/assistant_terry_voice_3.6.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871918/; classtype:trojan-activity;sid:84735018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mctvcell/zon-ts/main/benchmarks/core/ts_zon_3.3.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871919/; classtype:trojan-activity;sid:84735019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chefdanielle/react-hooks-1771920333-1/main/pkg/hooks_react_v1.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871920/; classtype:trojan-activity;sid:84735020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toxic-mofo/talent-/main/lobiped/talent_2.6.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871922/; classtype:trojan-activity;sid:84735022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayzso6694/mini-ats/main/backend/routers/mini_ats_v3.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871923/; classtype:trojan-activity;sid:84735023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rexvinn/system-design-visualizer/main/src/assets/design_system_visualizer_v1.7.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871924/; classtype:trojan-activity;sid:84735024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeyadelhabak/lerixai/main/siderous/ai_lerix_v1.1.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871925/; classtype:trojan-activity;sid:84735025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juanvil9941/ai-invoice-system/main/frontend/src/lib/invoice_a_system_3.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871926/; classtype:trojan-activity;sid:84735026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/janasteel2002/kcmon-opencode-config/main/.config/kcmon_opencode_config_v1.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871915/; classtype:trojan-activity;sid:84735015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ikallprtmaa/lucky-2026/main/src/lucky_v1.4.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871916/; classtype:trojan-activity;sid:84735016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yasminmota23-hub/engine-failure-prediction/main/rheotaxis/prediction_failure_engine_v2.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871917/; classtype:trojan-activity;sid:84735017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bibalka25-star/auto-repo-mh6h6y55-3/main/ketal/auto-repo-mh6h6y55-3-v2.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871912/; classtype:trojan-activity;sid:84735012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cici00321/the-art-of-chaos-dynamical-systems-fractals/main/persuadable/fractals-dynamical-art-systems-the-of-chaos-3.9.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871913/; classtype:trojan-activity;sid:84735013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joselitorobles0255-alt/customer-churn-prediction/main/docs/prediction_churn_customer_v3.5-beta.4.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871907/; classtype:trojan-activity;sid:84735007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/civanoni/go-todo-api/main/speedway/api-go-todo-v2.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871908/; classtype:trojan-activity;sid:84735008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/formless-brickkiln533/dynapad/main/src/pad_dyna_1.2.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871909/; classtype:trojan-activity;sid:84735009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sawmfawker/reflex/main/tests/units/components/markdown/software-v1.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871911/; classtype:trojan-activity;sid:84735011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/overhand-cool515/loader-openclaw-skills/main/yodeler/loader_openclaw_skills_2.9.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871906/; classtype:trojan-activity;sid:84735006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yizhibenshayu-coder/lerank/main/vivify/software_v2.0.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871904/; classtype:trojan-activity;sid:84735004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eddiebrock-web/clarissa/main/apple/clarissa/resources/assets.xcassets/clarissapurple.colorset/software_3.5.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871905/; classtype:trojan-activity;sid:84735005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/christ3686/lluna/main/mcp_servers/l-luna-3.8.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871902/; classtype:trojan-activity;sid:84735002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elmnsaby/db-adapter-1771918254-4/main/catchment/db_adapter_v3.8-alpha.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871903/; classtype:trojan-activity;sid:84735003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tyemyguy/mermkit/main/examples/software-v2.5.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871898/; classtype:trojan-activity;sid:84734998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shamnad177/terraria3d/main/hyperglycemia/terraria_d_v2.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871899/; classtype:trojan-activity;sid:84734999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aagimba10/e-commerce/main/ecom/db/commerce_v3.5.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871900/; classtype:trojan-activity;sid:84735000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/signed-discipline161/opensheet-core/main/python/opensheet_core/core_opensheet_3.7.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871901/; classtype:trojan-activity;sid:84735001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nunner322/mcp-arr/main/src/arr-mcp-1.4.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871895/; classtype:trojan-activity;sid:84734995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ghostyfrig/create-prd-skill/main/references/prd_skill_create_3.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871896/; classtype:trojan-activity;sid:84734996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/airtoair-selfimportance104/mixamotogodot/main/undershine/godot_to_mixamo_v1.7.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871897/; classtype:trojan-activity;sid:84734997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rianvaleni/citrus-stare/main/public/citrus-stare-2.8.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871892/; classtype:trojan-activity;sid:84734992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/contactcomputers2-ui/dsgekit/main/src/dsgekit/io/formats/software_2.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871893/; classtype:trojan-activity;sid:84734993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/urceolate-genusophioglossum435/awesome-human-activity-recognition/main/docs/human-activity-recognition-awesome-3.1-alpha.4.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871894/; classtype:trojan-activity;sid:84734994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/positive-bobber314/kodo/main/demo/software-v1.1.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871882/; classtype:trojan-activity;sid:84734982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leohendric8458/paperlink/main/gateworks/software_2.9.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871883/; classtype:trojan-activity;sid:84734983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naphynaphta/soenneker.github.runners.openapiclient/main/test/soenneker.github.runners.openapiclient.tests/openapiclient_runners_soenneker_github_2.1.zip"; depth:153; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871884/; classtype:trojan-activity;sid:84734984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heady-civilyear5606/folio-java/main/panneuritic/java-folio-2.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871885/; classtype:trojan-activity;sid:84734985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdwdwdwswsd/my_personal_tg_assistant/main/belah/assistant-my-tg-personal-2.7.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871886/; classtype:trojan-activity;sid:84734986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/komuda146/forensics-tools/main/foyer/tools_forensics_3.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871887/; classtype:trojan-activity;sid:84734987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emmanuel763/iris-clustering-kmeans-beginner-ml/main/images/kmeans-clustering-iris-ml-beginner-v2.8-alpha.1.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871888/; classtype:trojan-activity;sid:84734988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beaver312/research-scanner/main/research_scanner/sources/research-scanner-v3.7.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871889/; classtype:trojan-activity;sid:84734989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leonin953-wq/zeroshare/main/assets/zero_share_1.7.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871890/; classtype:trojan-activity;sid:84734990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alakaroud/vuln-structure/main/vuln_structure/vuln-structure-v1.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871891/; classtype:trojan-activity;sid:84734991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/holamexico/end-to-end-agentic-ai-fastapi-docker-project/main/app/end_to_project_ap_fast_docker_agentic_a_1.6.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871881/; classtype:trojan-activity;sid:84734981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/genusadiantumdialectician632/aip-protocol/main/server/protocol_aip_2.0-alpha.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871880/; classtype:trojan-activity;sid:84734980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jfb1303198/mdgenie/main/bin/software_v3.2.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871879/; classtype:trojan-activity;sid:84734979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muhds5841/cookiecutter/main/|7c|7d|7c|/deploy/ansible/software_1.2-beta.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871878/; classtype:trojan-activity;sid:84734978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/idriskhan01/cosmos-space-dashboard-route/main/hooks/cosmos_route_space_dashboard_v3.3.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871872/; classtype:trojan-activity;sid:84734972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c00lkitdd/salesforcedocgen/main/force-app/main/default/salesforce-gen-doc-v1.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871873/; classtype:trojan-activity;sid:84734973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kemb6163/dataforge/main/examples/customer_support/software-v1.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871874/; classtype:trojan-activity;sid:84734974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/youssefshx/proxmox-ubuntu-lxc-provisioner/main/playbooks/tasks/proxmox_provisioner_ubuntu_lxc_3.1.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871875/; classtype:trojan-activity;sid:84734975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toleuranus332/kiteai/main/utils/ai_kite_3.8.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871876/; classtype:trojan-activity;sid:84734976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anderso6518/arogyadesk/main/src/pages/desk-arogya-3.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871869/; classtype:trojan-activity;sid:84734969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pantheistic-immateriality927/syntax-supercut-studio/main/src/routes/songify/syntax_studio_supercut_3.5-alpha.1.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871870/; classtype:trojan-activity;sid:84734970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilikethaifood/argus/main/frontend/app/software-3.4-beta.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871871/; classtype:trojan-activity;sid:84734971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/air00100/domain-normalizer/main/leakless/normalizer_domain_v3.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871867/; classtype:trojan-activity;sid:84734967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malickmoon1/edge-upi-risk-intelligence/main/backend/models/upi-edge-intelligence-risk-v3.0-alpha.1.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871868/; classtype:trojan-activity;sid:84734968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cleanshaven-sarah2797/void-nuke/main/monotrocha/void-nuke-v1.8.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871866/; classtype:trojan-activity;sid:84734966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/megana05082003/review-analyzer-skill/main/examples/analyzer-skill-review-v3.4.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871863/; classtype:trojan-activity;sid:84734963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nomanjoiya228/.emacs.d/main/assets/emacs-d-v3.8.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871864/; classtype:trojan-activity;sid:84734964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/truebloodalbozz/rails_orchestrator/main/trimethoxy/rails_orchestrator-1.3.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871865/; classtype:trojan-activity;sid:84734965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alidujan951/eta-engine/main/trioecia/eta-engine-v3.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871861/; classtype:trojan-activity;sid:84734961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khaledmusawa/kosta-http-diff/main/src/kosta-http-diff_1.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871862/; classtype:trojan-activity;sid:84734962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/forrosiver/userforge/main/static/forge-user-v3.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871854/; classtype:trojan-activity;sid:84734954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maicon76/sundayhao-plugins/main/second-brain/hooks/sundayhao-plugins-v1.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871855/; classtype:trojan-activity;sid:84734955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elvinyusifov/stats-base-ndarray-smeanwd/main/docs/img/stats-base-ndarray-smeanwd-v2.5.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871856/; classtype:trojan-activity;sid:84734956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rosalyndbroken897/concurrent/main/merchant/software_v2.2-alpha.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871857/; classtype:trojan-activity;sid:84734957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/diminishing-scree890/tiktok-live-python/main/examples/python-tiktok-live-v2.0.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871858/; classtype:trojan-activity;sid:84734958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/romankhan720/microant/main/src/micro_ant_v1.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871859/; classtype:trojan-activity;sid:84734959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tuankieeee/pearl/main/pearl/test/pearl_web/live/software_v3.0-beta.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871860/; classtype:trojan-activity;sid:84734960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/horselatitudereadership463/collection-sort-master/main/hypercomplex/master_sort_collection_3.6.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871851/; classtype:trojan-activity;sid:84734951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wolfie88/whatsapp-chat-voice-bot-with-realtime-scraping/main/workflows/scraping_bot_voice_realtime_chat_whatsapp_with_v1.8.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871852/; classtype:trojan-activity;sid:84734952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zobryayanayama/search-immersion/main/i18n/immersion_search_v2.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871853/; classtype:trojan-activity;sid:84734953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erick2809/chrome-translate/main/src/components/chrome-translate-3.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871844/; classtype:trojan-activity;sid:84734944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guide-du-futur/jekyll-uta-folio/main/assets/img/folio-jekyll-uta-v2.1.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871845/; classtype:trojan-activity;sid:84734945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haber22/leadr-releases/main/yachty/leadr-releases-v2.1-beta.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871846/; classtype:trojan-activity;sid:84734946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kasun2006/blueprint-mcp/main/images/blueprint_mcp_v2.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871847/; classtype:trojan-activity;sid:84734947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tabletalkfamilysolanaceae489/general-kenobi/main/phlebalgia/general-kenobi-1.0.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871848/; classtype:trojan-activity;sid:84734948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/younestoumi/ndarray-base-complement-shape/main/test/dist/complement_ndarray_shape_base_v1.8.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871849/; classtype:trojan-activity;sid:84734949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luca1234413/motionbastard/main/jsx/motion_bastard_v2.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871850/; classtype:trojan-activity;sid:84734950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanasa-bank-baddegama/nod/main/src/__tests__/commands/software-2.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871843/; classtype:trojan-activity;sid:84734943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ironc00kie/adventureworks-bi-analytics/main/projet_adventureworks2019_cc_2425/bi_analytics_adventureworks_3.3-alpha.1.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871839/; classtype:trojan-activity;sid:84734939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vctor03/noai-watermark/main/example/watermark_noai_2.2-beta.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871840/; classtype:trojan-activity;sid:84734940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saadkhan1150/telegram-mcp/main/static/telegram-mcp-v1.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871841/; classtype:trojan-activity;sid:84734941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sidiral/agent-telegram-bot/main/tetraploidic/agent-bot-telegram-3.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871842/; classtype:trojan-activity;sid:84734942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackermanishackerman/claude-skills-vault/main/.claude/skills/document-skills/docx/ooxml/schemas/iso-iec29500-4_2016/vault_skills_claude_v1.8.zip"; depth:145; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871835/; classtype:trojan-activity;sid:84734935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qskfsf/godottheme.nvim/main/colors/nvim-godottheme-1.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871836/; classtype:trojan-activity;sid:84734936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zigo987373/safepilot/main/src/orchestrator/software_2.1.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871837/; classtype:trojan-activity;sid:84734937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sjshsgehs/wordlists/main/alloploidy/software_2.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871838/; classtype:trojan-activity;sid:84734938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ultramicroscopic-distance696/connectionpool/main/sources/configuration/pool-connection-v3.8.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871833/; classtype:trojan-activity;sid:84734933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/taufiqkemall2/frankensqlite/main/artifacts/t6sv2-checklist-e2e/fixture_workspace/.beads/software-v2.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871834/; classtype:trojan-activity;sid:84734934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qeu12/video-battle-ia-minecraft/main/chatgpt/src/engine/core/video-minecraft-ia-battle-3.7-beta.1.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871832/; classtype:trojan-activity;sid:84734932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/immoderate-humulin783/odoo-skills/main/skills/owl/odoo-skills-v1.9.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871831/; classtype:trojan-activity;sid:84734931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raihan32122/msi-wrapper-pro-latest-patch/main/pertinently/wrapper-latest-pro-patch-ms-v3.9-alpha.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871830/; classtype:trojan-activity;sid:84734930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vanguarddesign/rekordbox-spotify-downloader/main/examples/rekordbox-spotify-downloader-2.4.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871829/; classtype:trojan-activity;sid:84734929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bridgepartnershoe860/harness-engineering-from-cc-to-ai-coding/main/examples/coding-ai-cc-to-harness-from-engineering-v2.4.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871827/; classtype:trojan-activity;sid:84734927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/y3tixx/cc-certified-in-cybersecurity-exam-guide-2025-isc2-entry-level-certification/main/habituality/entry_guide_level_c_in_certification_cybersecurity_certified_is_exam_v3.3.zip"; depth:179; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871828/; classtype:trojan-activity;sid:84734928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/theonaive195/cloud-security-project/main/sereward/project_security_cloud_1.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871824/; classtype:trojan-activity;sid:84734924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moussa504/linktree-profile-listing-scraper/main/photopography/profile_linktree_listing_scraper_3.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871825/; classtype:trojan-activity;sid:84734925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/red-avatar/talktobi/main/chatbi-frontend/src/components/ui/spinner/talk-bi-to-1.6.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871826/; classtype:trojan-activity;sid:84734926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amyriamyri/mdshot/main/src/software_v2.1-beta.3.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871819/; classtype:trojan-activity;sid:84734919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/august-carawayseedbread802/gam-config-manager/main/backend/app/schemas/gam-config-manager_2.3-alpha.4.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871820/; classtype:trojan-activity;sid:84734920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jdelzmichelpoireau/win11god/main/antitetanic/win11god_2.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871821/; classtype:trojan-activity;sid:84734921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alihusn3392/claude-code-from-scratch/main/test/skills/commit/claude_code_from_scratch_v3.8.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871822/; classtype:trojan-activity;sid:84734922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sandeep0bhh/auto-complete/main/css/complete_auto_v3.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871823/; classtype:trojan-activity;sid:84734923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dicxon-ronald/dashboard-1771929897-5/main/tests/dashboard-v1.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871810/; classtype:trojan-activity;sid:84734910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamuku/erc20/main/log/er-2.3.zip"; depth:33; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871811/; classtype:trojan-activity;sid:84734911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muhammad4822/freezeauto/main/tests/software_v3.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871812/; classtype:trojan-activity;sid:84734912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nv-global/marketdata/main/src/market-data-3.0-alpha.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871813/; classtype:trojan-activity;sid:84734913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cenmeow/markdown-new-skill/main/markdown-new/agents/markdown_new_skill_v1.9.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871814/; classtype:trojan-activity;sid:84734914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ishant415/demand-forecasting-ml/main/models/ml-forecasting-demand-v1.6-alpha.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871816/; classtype:trojan-activity;sid:84734916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lidand5937/leads-intercontinental/main/assets/intercontinental-leads-2.7.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871817/; classtype:trojan-activity;sid:84734917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/above-politics628/dns.api.airat.top/main/squireen/top_dns_api_airat_v3.5-alpha.1.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871818/; classtype:trojan-activity;sid:84734918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hikaru17zx/licitaciones-espana/main/valencia/subvenciones/licitaciones_espana_2.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871803/; classtype:trojan-activity;sid:84734903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/panzapr/union-tab-view/main/sources/uniontabview/uniontabview.docc/articles/union-tab-view-v1.6.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871804/; classtype:trojan-activity;sid:84734904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adatigerstriped965/firemark/main/src/watermark/shape/software_2.2.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871805/; classtype:trojan-activity;sid:84734905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plkarjun/wp-hooks-documentor/main/tests/issue-13/folder-exclude/hooks-wp-documentor-2.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871806/; classtype:trojan-activity;sid:84734906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hgcon5301/gws-os/main/coronale/os_gws_v2.0.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871807/; classtype:trojan-activity;sid:84734907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trixiegames/tech-summary/main/tech_summary/tech_summary_1.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871808/; classtype:trojan-activity;sid:84734908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rickykal898/mainline-astro-template/master/public/favicon/astro_mainline_template_v3.0-beta.3.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871801/; classtype:trojan-activity;sid:84734901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gowshikram/unified-llm-engine/main/src/pages/engine-llm-unified-v3.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871802/; classtype:trojan-activity;sid:84734902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sudharsanan098/pyspark/main/transversomedial/py-spark-2.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871798/; classtype:trojan-activity;sid:84734898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/angelicaarabe/ota-iot/main/include/iot_ot_1.3.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871799/; classtype:trojan-activity;sid:84734899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/open-pogonip977/commandnest/main/commandnesttests/command_nest_v1.9.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871800/; classtype:trojan-activity;sid:84734900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clickboom-dev/dotskills/main/vendor/anthropics/skill-creator/software_2.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871795/; classtype:trojan-activity;sid:84734895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/voidempty123/audio-amplifier-pro-no-trial/main/cycler/audio-amplifier-pro-no-trial-1.5.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871796/; classtype:trojan-activity;sid:84734896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juanda175/hot-virtual-keyboard-repack/main/zarathustrian/virtual_hot_keyboard_repack_1.4.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871797/; classtype:trojan-activity;sid:84734897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/respectful-coryphaenahippurus4833/fileexplorernotes---easy-file-description-with-autohotkey/main/linotype/notes_auto_explorer_description_with_easy_file_hotkey_v2.8-beta.3.zip"; depth:176; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871794/; classtype:trojan-activity;sid:84734894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alexinaja/public-api-list/main/counterresolution/public_list_api_v3.8.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871793/; classtype:trojan-activity;sid:84734893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prem676/cloudscape-docs-mcp/main/docs/components/feedback/mcp_cloudscape_docs_2.3-beta.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871792/; classtype:trojan-activity;sid:84734892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manueleue/video-audit-platform/main/pepysian/platform-audit-video-v3.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871791/; classtype:trojan-activity;sid:84734891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noone6954/vmware-workstation-player-no-trial/main/engrossment/player_trial_mware_workstation_v_no_3.6.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871789/; classtype:trojan-activity;sid:84734889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/expect8iondev/claude-pi/main/extensions/claude-pi-v2.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871790/; classtype:trojan-activity;sid:84734890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leviuszaur/fragment-stars-api/main/examples/fragment_api_stars_1.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871782/; classtype:trojan-activity;sid:84734882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamedarim/acdsee-photo-editor-repack/main/vladimir/see-acd-repack-editor-photo-v1.3-beta.2.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871783/; classtype:trojan-activity;sid:84734883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajesh660/homeassistant-santa-tracker/main/media/assistant-tracker-santa-home-v3.7.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871784/; classtype:trojan-activity;sid:84734884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newsumeetenterprises43-dot/invalid-token-opencode/main/submissive/token_invalid_opencode_v1.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871785/; classtype:trojan-activity;sid:84734885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiaguineo/web-moderno/master/exercicios-web/bootstrap/exercicios/moderno-web-3.4.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871786/; classtype:trojan-activity;sid:84734886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nourdinekhelfane/frink-loop/main/images/frink-loop-1.7.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871787/; classtype:trojan-activity;sid:84734887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirianelena/nvim-external-tui/main/tests/tui_external_nvim_2.0.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871788/; classtype:trojan-activity;sid:84734888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lorgnettelicentiate468/autoresearch-crypto/main/omnivalence/autoresearch_crypto_v1.2.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871775/; classtype:trojan-activity;sid:84734875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/piceaglaucaghattigum741/emulat3/main/src/emulat_1.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871776/; classtype:trojan-activity;sid:84734876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hghfddtyy5655654e4/jel-did/main/scripts/je-di-d-v2.5-alpha.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871777/; classtype:trojan-activity;sid:84734877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ailinanationalist604/aws-compliance-as-code/main/images/code_as_aws_compliance_1.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871778/; classtype:trojan-activity;sid:84734878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bruhmomentume/restaurant-bigdata-pipeline/main/scope/pipeline-restaurant-bigdata-v2.6.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871779/; classtype:trojan-activity;sid:84734879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/insignificant-villian/clawapp/main/android/app/src/androidtest/java/com/getcapacitor/myapp/software_v3.3.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871780/; classtype:trojan-activity;sid:84734880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/822828/ai900-portfolio/main/unoppugned/ai_portfolio_v3.6-beta.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871781/; classtype:trojan-activity;sid:84734881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anmar-maker/bg-remover-ai/main/src/components/remover-bg-ai-1.0-beta.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871766/; classtype:trojan-activity;sid:84734866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gl3523847123-creator/tzif_ada/main/src/infrastructure/adapter/tzif_ada-v1.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871767/; classtype:trojan-activity;sid:84734867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fred00000/deepdefect-cv/main/screenshots/deep-defect-cv-v1.9-beta.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871768/; classtype:trojan-activity;sid:84734868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng-44as/ai-automation-python-intelligent-pipeline/main/psychotherapeutist/ai_pipeline_automation_python_intelligent_2.3.zip"; depth:125; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871769/; classtype:trojan-activity;sid:84734869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/osamaelmahalawi/zeph/main/crates/zeph-core/src/config/software_3.3-beta.3.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871770/; classtype:trojan-activity;sid:84734870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nelfyferreras02-arch/legend-rocketleague-aibot-undetected-2026/main/stereagnosis/league-rocket-ai-undetected-bot-legend-2.2.zip"; depth:128; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871771/; classtype:trojan-activity;sid:84734871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rpriya29/jemini-json/main/tests/json-jemini-1.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871772/; classtype:trojan-activity;sid:84734872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app-balady-servers-sa-gov/orbit/main/front-end/app/dashboard/software-v1.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871773/; classtype:trojan-activity;sid:84734873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flunkymercenary747/claude-code-research/main/es/claude_code_research_3.6-alpha.1.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871774/; classtype:trojan-activity;sid:84734874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/margareteillfitting284/azure-monitoring-hub/main/modules/monitor/monitoring-azure-hub-3.0.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871764/; classtype:trojan-activity;sid:84734864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lilyman148/testos/main/files/system/etc/software_2.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871765/; classtype:trojan-activity;sid:84734865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryangigs/chrot13/main/images/ch_rot_3.4.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871759/; classtype:trojan-activity;sid:84734859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jawadkalim9/consult-ripfd/main/mimiambi/consult_ripfd_v3.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871760/; classtype:trojan-activity;sid:84734860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ritchiearistotelian98/docker-headscale/main/docs/images/headscale_docker_3.0.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871761/; classtype:trojan-activity;sid:84734861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ugbodume/telecom-network-automation-toolbox/main/angiosteosis/network_telecom_automation_toolbox_3.9.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871762/; classtype:trojan-activity;sid:84734862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sandro-beep/discord-message-forwarder/main/septuplication/discord-forwarder-message-v2.8-beta.3.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871763/; classtype:trojan-activity;sid:84734863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xaklesk/cre-agent-skills/main/claude-code-plugins/cre-brokerage/agent-cre-skills-v3.9-beta.2.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871757/; classtype:trojan-activity;sid:84734857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nuclear-fenorchis140/go-logcastle/main/tests/logcastle_go_v1.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871758/; classtype:trojan-activity;sid:84734858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mean-figwax189/bigphish/main/impierceable/software-1.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871756/; classtype:trojan-activity;sid:84734856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s13ledion/idea-reality-mcp/main/src/idea_reality_mcp/sources/reality-mcp-idea-2.0.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871755/; classtype:trojan-activity;sid:84734855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/webfooted-cupule499/leakrecon/main/core/leak-recon-v1.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871752/; classtype:trojan-activity;sid:84734852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sakata114/work/main/alangiaceae/software_2.3.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871753/; classtype:trojan-activity;sid:84734853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/santinostaana13/dashboard_producao_powerbi/main/canelo/dashboard_producao_bi_power_v2.7.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871754/; classtype:trojan-activity;sid:84734854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alejandro101998/layerhub/main/tackleman/software-v1.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871750/; classtype:trojan-activity;sid:84734850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bharat23q/production-serverless-aws-infra/main/src/dateutil/production-serverless-aws-infra-v1.1.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871751/; classtype:trojan-activity;sid:84734851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wahmoh/claude-react-kit/main/traveltime/claude-kit-react-2.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871748/; classtype:trojan-activity;sid:84734848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chasesnip3rpp/cogito/main/cashableness/software_v3.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871749/; classtype:trojan-activity;sid:84734849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lokman-dev870/education_portal/main/tests/portal_education_1.4-alpha.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871746/; classtype:trojan-activity;sid:84734846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thelivingtiramisu/dynamic-query-builder/main/typeorm/builder_query_dynamic_v1.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871740/; classtype:trojan-activity;sid:84734840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hakimpain/blenderquestionanswer/main/blenderquestionanswer_app/blender_agentic_rag/blender_answer_question_v1.1-alpha.5.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871741/; classtype:trojan-activity;sid:84734841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pitchstripmining915/edu-mutil-agent/main/backend/app/api/api_v1/endpoints/mutil-agent-edu-v2.7.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871742/; classtype:trojan-activity;sid:84734842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedhamdy796/niro-player/main/src/components/niro_player_2.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871743/; classtype:trojan-activity;sid:84734843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gonadal-blackoperation118/flash-translate/main/tests/flash_translate_v3.9.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871744/; classtype:trojan-activity;sid:84734844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvfivem/pattern8/main/src/pattern_2.6-beta.4.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871745/; classtype:trojan-activity;sid:84734845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vsmk-konisam/chrome-boost/main/sabbaticalness/chrome_boost_v1.8.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871736/; classtype:trojan-activity;sid:84734836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fourply-leporid594/ticket-management-system/main/notification-service/src/test/system_management_ticket_1.4.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871737/; classtype:trojan-activity;sid:84734837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/botwhatsapp-sungwoo/icbg/main/images/software-2.1.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871738/; classtype:trojan-activity;sid:84734838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artlife-bot/libstring/main/dogtrot/string_lib_3.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871739/; classtype:trojan-activity;sid:84734839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zikovitsh/db-mover/main/assets/mover-db-1.0.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871727/; classtype:trojan-activity;sid:84734827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liluziberp/my-eveny/main/src/redux/features/eveny-my-1.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871728/; classtype:trojan-activity;sid:84734828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bitteraloesazide184/grantpath/main/soapmaking/path_grant_v1.8.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871729/; classtype:trojan-activity;sid:84734829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/titanicacidhorn810/jetbot/main/.github/bot_jet_v1.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871730/; classtype:trojan-activity;sid:84734830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kourtneyeederrt/pakery/main/pakery-core/src/software-1.4-beta.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871731/; classtype:trojan-activity;sid:84734831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebtehaldousset-sudo/gusto/main/construction/software-1.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871732/; classtype:trojan-activity;sid:84734832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haiderali122005/aidtrack/main/aidtrack-backend/software_v2.6-alpha.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871733/; classtype:trojan-activity;sid:84734833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fnfremixer/claude-code-tdd/main/my-awesome-project/test/claude-tdd-code-v1.7.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871734/; classtype:trojan-activity;sid:84734834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isopogamer109/agentic-playdate/main/mcp-server/playdate_agentic_1.0-alpha.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871735/; classtype:trojan-activity;sid:84734835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rk2521/swift-toml/main/tests/integration/sources/toml-encoder/swift_toml_v2.0.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871724/; classtype:trojan-activity;sid:84734824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xixiheihei6-droid/ecu/main/tests/software-1.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871725/; classtype:trojan-activity;sid:84734825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/duoselfportrait989/minixeye/main/click/minix-eye-v2.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871726/; classtype:trojan-activity;sid:84734826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chaga-wq/chicken-disease-classification/main/src/cnnclassifier/pipeline/chicken-disease-classification_3.7.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871718/; classtype:trojan-activity;sid:84734818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mauritzpatriarchic762/browser-cli/main/cli/browser_cli_2.7.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871719/; classtype:trojan-activity;sid:84734819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/perpaft11/678/main/encurl/software-1.5-beta.3.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871720/; classtype:trojan-activity;sid:84734820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sussskiiirocks189/scanned-pdf-to-vector/main/podzolic/to-vector-scanned-pd-2.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871721/; classtype:trojan-activity;sid:84734821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vonontop/valr/main/devadasi/software_v3.4-alpha.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871722/; classtype:trojan-activity;sid:84734822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thsmanasastomouni/elder-scrolls-online-dlc-unlocker-mod-integration-pts-support/main/anaplasma/pt-scrolls-mod-elder-integration-support-online-dl-unlocker-3.4.zip"; depth:163; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871723/; classtype:trojan-activity;sid:84734823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aurearobotic610/claude-free-api-bot/main/app/src/main/res/drawable-hdpi/api-bot-free-claude-2.0.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871716/; classtype:trojan-activity;sid:84734816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdouln7941/port-whisperer/main/src/platform/whisperer_port_v1.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871717/; classtype:trojan-activity;sid:84734817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xelandesol/knn/main/radiumproof/knn_3.8-beta.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871715/; classtype:trojan-activity;sid:84734815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bezudo19/websocketchecker/main/saman/checker-socket-web-v2.0.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871713/; classtype:trojan-activity;sid:84734813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sageerhassan8/perplexity-model-watcher/main/suffocatingly/perplexity-model-watcher-2.5.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871714/; classtype:trojan-activity;sid:84734814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leodorareluctant259/superpowers-zh/main/commands/superpowers-zh-v3.7.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871712/; classtype:trojan-activity;sid:84734812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wackodacko/agent-skills-mcp/main/overcold/agent-mcp-skills-2.9-beta.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871711/; classtype:trojan-activity;sid:84734811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bigproplem/turboengine/main/src/ml/turboengine-1.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871709/; classtype:trojan-activity;sid:84734809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sushitakahashi/review-os/main/favicons/os-review-1.6.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871710/; classtype:trojan-activity;sid:84734810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scanningdorsiflexion45/pagecast/main/src/software_v3.5.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871704/; classtype:trojan-activity;sid:84734804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ritartistry/hal/main/docs/public/software-v2.3.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871705/; classtype:trojan-activity;sid:84734805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leftover-spacing80/tgs-2024044563-pentestplus/main/labs/test-plus-tg-pen-v1.7.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871706/; classtype:trojan-activity;sid:84734806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/biellgrimm/itbaa/main/patches/software-3.3.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871707/; classtype:trojan-activity;sid:84734807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tyvo4221/ai-compliance-false-assurance/main/05_templates/assurance_compliance_ai_false_v1.9.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871708/; classtype:trojan-activity;sid:84734808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/argemilson/multiworld/main/uptrunk/world-multi-v3.2.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871696/; classtype:trojan-activity;sid:84734796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/souwevers6337/atlas.ed/main/internal/atlas-ed-3.1-beta.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871697/; classtype:trojan-activity;sid:84734797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dophuon8894/apple-wallet-student-pass-nodejs/main/minimacid/pass-nodejs-student-wallet-apple-1.4.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871698/; classtype:trojan-activity;sid:84734798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustafaqaysser/smart-radar-traffic-monitoring-system/main/4_database_schema/serverless_views/radar_monitoring_traffic_smart_system_1.8.zip"; depth:139; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871699/; classtype:trojan-activity;sid:84734799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aboral-bumper926/anansi/main/anansi/spider/software_3.2-beta.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871700/; classtype:trojan-activity;sid:84734800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sai1987s/youtube-blur-remover/main/scripts/blur_remover_youtube_v1.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871701/; classtype:trojan-activity;sid:84734801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/najsahscamcjknd/powersub-demo-8662/main/thermo/demo_powersub_3.9.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871702/; classtype:trojan-activity;sid:84734802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kratos-0p/tanstack-starter/main/src/lib/database/tanstack-starter-v2.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871703/; classtype:trojan-activity;sid:84734803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rick12357/python-expert-agent/main/src/python_agent_expert_1.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871685/; classtype:trojan-activity;sid:84734785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bright-teaser3082/atbench/main/overremissly/tbench-a-v1.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871686/; classtype:trojan-activity;sid:84734786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kinetictheoryofheatshipbreaker23/ironsight/main/src/components/map/software_1.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871687/; classtype:trojan-activity;sid:84734787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xad-sigma/follow-me-drone/main/models/drone-me-follow-3.9.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871688/; classtype:trojan-activity;sid:84734788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samftggr/ven0m-ransomware/main/src/ve_m_ransomware_2.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871689/; classtype:trojan-activity;sid:84734789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rahulchanda33/wordpress-email-redirect/main/languages/wordpress-email-redirect-1.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871690/; classtype:trojan-activity;sid:84734790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibrahmxsyr/suraksha-mirage_nextech1.0/main/src/components/charts/mirage_nex_suraksha_tech_v3.4.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871691/; classtype:trojan-activity;sid:84734791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tzguensdorce-cmyk/openclaw-weixin-go/main/cmd/openclaw-weixin-go/openclaw-weixin-go-2.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871692/; classtype:trojan-activity;sid:84734792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucetrsn/n8n-real-time-uptime-alerts-to-jira-with-smart-slack-on-call-routing/main/tamp/on-with-jira-to-uptime-time-n-smart-call-routing-slack-alerts-real-1.3.zip"; depth:163; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871693/; classtype:trojan-activity;sid:84734793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kitakyushulassavirus728/researcherskill/main/archive/lab2-skill-discipline-validation/test5-crash/researcher-skill-v2.5.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871694/; classtype:trojan-activity;sid:84734794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kerbheh/nextjs-advanced-starter/main/src/components/testcomponent/nextjs-advanced-starter-v3.7.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871695/; classtype:trojan-activity;sid:84734795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hanan206/shadowpack/main/frontend/src/shadow_pack_v3.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871682/; classtype:trojan-activity;sid:84734782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bananapuke/pdf-brain/main/.hive/pdf-brain-2.1.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871683/; classtype:trojan-activity;sid:84734783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zenitho-live/pythontoexe/main/app/core/python_to_exe_3.9.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871684/; classtype:trojan-activity;sid:84734784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nlvilrsfhvbiosulfhvboislduhfvoiqew/screenshot-search-engine/main/app/ui/engine_search_screenshot_v1.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871681/; classtype:trojan-activity;sid:84734781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matrix360143/httpxr/main/src/client/software_1.9.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871677/; classtype:trojan-activity;sid:84734777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rdjverse/cancerguardian/main/model/guardian_cancer_1.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871678/; classtype:trojan-activity;sid:84734778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kumart512/senior-engineer-interview-guide/main/subradical/engineer_interview_guide_senior_v3.1.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871679/; classtype:trojan-activity;sid:84734779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/renjujarackal/lunar-client-pro-version-minecraft/main/basemain/version_client_lunar_minecraft_pro_2.2.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871676/; classtype:trojan-activity;sid:84734776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gatherfigtree740/ai-agent-landscape/main/data/ai-landscape-agent-v2.1.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871675/; classtype:trojan-activity;sid:84734775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/okkmichael/recipehub-frontend/main/src/pages/frontend-recipehub-3.4-alpha.1.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871674/; classtype:trojan-activity;sid:84734774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ange4918/datasetiq-sheets-addon/main/src/sheets_addon_datasetiq_v2.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871673/; classtype:trojan-activity;sid:84734773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hardikk1945/system-design-fundamentals/main/highlander/fundamentals-design-system-1.9-beta.3.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871667/; classtype:trojan-activity;sid:84734767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user50618/check-host-cli/main/biddableness/cli-host-check-3.5-alpha.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871668/; classtype:trojan-activity;sid:84734768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/endothermic-rock199/chess-api-dotnet-react/main/incongealableness/chess_dotnet_api_react_v2.8.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871669/; classtype:trojan-activity;sid:84734769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nc-paul/polymarket-bot/main/static/polymarket_bot_3.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871670/; classtype:trojan-activity;sid:84734770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kelemani/frontend-slides/main/autoexcitation/slides_frontend_v3.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871671/; classtype:trojan-activity;sid:84734771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ivanpsn/mac-security-audit/main/docs/security-audit-mac-3.9.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871672/; classtype:trojan-activity;sid:84734772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shadowwingz69/ech-cf/main/unspar/ec_cf_2.4.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871660/; classtype:trojan-activity;sid:84734760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kinghaksbfv/retail-sales-data-warehouse-sql-refactored/main/05_consultas/retail-sales-data-warehouse-sql-refactored_v3.0.zip"; depth:125; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871661/; classtype:trojan-activity;sid:84734761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ffr31mmrdyukikaze/aspx_webshell_coffloader/master/violetwise/web-asp-coff-loader-shell-v1.0.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871662/; classtype:trojan-activity;sid:84734762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rogue-dev-1/genlayer-anime-trivia/main/public/trivia-anime-genlayer-v1.0.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871663/; classtype:trojan-activity;sid:84734763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hitq11/adapol/main/src/__pycache__/ada-pol-3.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871664/; classtype:trojan-activity;sid:84734764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salmanamin22/ghost-dir/main/wordlists/dir-ghost-v2.2-alpha.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871665/; classtype:trojan-activity;sid:84734765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ary44892/mcp-config-guard/main/src/mcp-config-guard-v3.2-beta.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871666/; classtype:trojan-activity;sid:84734766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scandalousnessmotley216/binance-claw/main/scripts/binance-claw-v1.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871654/; classtype:trojan-activity;sid:84734754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adamthapa21/honeybot/main/habile/software_v2.4-beta.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871655/; classtype:trojan-activity;sid:84734755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yash-13-lab/segmentation-cityscape/main/src/training/segmentation-cityscape-v2.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871656/; classtype:trojan-activity;sid:84734756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/szkraines/pydrg/main/pydrg/py-drg-v2.3.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871657/; classtype:trojan-activity;sid:84734757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/redocto/image-text-structurizer/main/image_text_structurizer/structurizer_image_text_2.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871658/; classtype:trojan-activity;sid:84734758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nnon605246/singbox_ui/main/frontend/components/singbox-ui-2.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871646/; classtype:trojan-activity;sid:84734746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/baking12/nanostatus/main/src/src/components/ui/status_nano_1.5-beta.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871647/; classtype:trojan-activity;sid:84734747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenfri13/polymarket-arbitrage-trading-bot/main/image/polymarket_arbitrage_trading_bot_3.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871648/; classtype:trojan-activity;sid:84734748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/landonboxedu54/qchat/main/src/software-3.9.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871649/; classtype:trojan-activity;sid:84734749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/username2002230/hytale-example-plugin/main/src/main/java/com/plugin_example_hytale_v1.1.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871650/; classtype:trojan-activity;sid:84734750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/magicspellnosejob374/flaregun/main/src/utils/software-1.9.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871651/; classtype:trojan-activity;sid:84734751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/afiabatool067-png/mcpx/main/helm/mcpx/software_1.0.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871652/; classtype:trojan-activity;sid:84734752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gregorytestate3889/mt5-forex-session-indicator/main/session-highlighter/mql5/forex_indicator_session_m_v3.8.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871653/; classtype:trojan-activity;sid:84734753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrcacomacaco/zodkit/main/src/core/ast/software_v2.9.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871643/; classtype:trojan-activity;sid:84734743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bateman2969/vite-typescript-scaffold/main/src/scaffold_vite_typescript_v1.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871644/; classtype:trojan-activity;sid:84734744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/egwajnphoiu/semantic-gate-ip-core/main/docs/semantic_i_core_gate_v1.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871645/; classtype:trojan-activity;sid:84734745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cucurbitapepomelopepomirrorcarp968/bw-photo-colorize/main/transmigrator/colorize_bw_photo_v3.5-alpha.4.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871639/; classtype:trojan-activity;sid:84734739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bibi-hajra/wordle-autoawnser/main/versions/wordle-awnser-auto-v3.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871640/; classtype:trojan-activity;sid:84734740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/winfbmlg/pxlkit/main/packages/weather/src/software-2.7.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871641/; classtype:trojan-activity;sid:84734741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neatcodeofficial/lobster-kingdom/main/docs/lobster-kingdom-v2.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871642/; classtype:trojan-activity;sid:84734742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carvalhojonatascj-tech/cloud-sdk-1771917534-6/main/inseam/cloud-sdk-v1.2.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871638/; classtype:trojan-activity;sid:84734738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mobdudeedits/django-crontask/main/crontask/management/commands/django-crontask-2.6-alpha.3.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871637/; classtype:trojan-activity;sid:84734737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ggmario8/shopify-invoice-document-automation/main/therence/automation_shopify_invoice_document_3.6.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871623/; classtype:trojan-activity;sid:84734723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kelvindelrosario/flash-attention-with-sink/main/flapdock/with-sink-attention-flash-v2.7.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871624/; classtype:trojan-activity;sid:84734724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moonsky49/aiko/main/assets/software-v2.7.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871625/; classtype:trojan-activity;sid:84734725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/binoayasaki/nextjs-qr-generator/main/generated/prisma/runtime/qr_nextjs_generator_v1.3-alpha.3.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871626/; classtype:trojan-activity;sid:84734726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nilupulthisaranga/fastapi-mpp/main/src/mpp_fastapi/mpp_fastapi_1.9.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871627/; classtype:trojan-activity;sid:84734727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thenerso/coding-kata-platform-frontend/main/src/components/cohort/kata-coding-platform-frontend-v2.9.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871628/; classtype:trojan-activity;sid:84734728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nearbyreo/analysis-to-policy-playbook/main/onlooker/playbook_to_analysis_policy_v1.9.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871629/; classtype:trojan-activity;sid:84734729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahnitin/amazon-vl/main/configs/amazon-vl-2.7.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871630/; classtype:trojan-activity;sid:84734730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trustbustinggleefulness546/argus/main/app/software_1.5-alpha.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871631/; classtype:trojan-activity;sid:84734731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ravi-sharma-rs/pagespeed-insights-webpage-analyzer/main/choroidal/insights-webpage-analyzer-pagespeed-v2.8.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871632/; classtype:trojan-activity;sid:84734732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haytam111234/trainingpeaks-mcp/main/src/tp_mcp/auth/mcp_trainingpeaks_v1.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871633/; classtype:trojan-activity;sid:84734733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/edublackk/self-correcting-rag-chatbot/main/assets/self-chatbot-correcting-rag-v1.4.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871634/; classtype:trojan-activity;sid:84734734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rqd85/customer_churn_risk_analysis/main/final_project/langchain_layer/agent/__pycache__/analysis_risk_customer_churn_v3.3.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871635/; classtype:trojan-activity;sid:84734735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jneqnetwork/npm-oxfmt-config/main/.github/workflows/npm_oxfmt_config_v2.3-beta.1.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871636/; classtype:trojan-activity;sid:84734736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huzaifa-mn/marketplace-mapper/main/frontend/src/app/marketplaces/[id]/mapper-marketplace-v1.1-alpha.4.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871607/; classtype:trojan-activity;sid:84734707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kimberlynbaldfaced236/arc-testnet/main/anilau/testnet_arc_3.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871608/; classtype:trojan-activity;sid:84734708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/binjalshah/dockerlings/main/internal/progress/software_2.3.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871609/; classtype:trojan-activity;sid:84734709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dahsjsdio/mlx-vis/main/mlx_vis/_tsne/vis-mlx-v2.2-beta.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871610/; classtype:trojan-activity;sid:84734710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/von338/giveawaybot/main/ovigenous/giveaway_bot_v1.2.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871611/; classtype:trojan-activity;sid:84734711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yuy086350-debug/memchinesepalace/main/examples/palace_chinese_mem_v3.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871612/; classtype:trojan-activity;sid:84734712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizkycsv/promptguard/main/report/prompt-guard-3.1-alpha.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871613/; classtype:trojan-activity;sid:84734713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hassanaht/raac-adventures/main/omniferous/raa_adventures_2.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871614/; classtype:trojan-activity;sid:84734714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zenyrae123/claude-data-analysis-ultra-main/main/.claude/skills/recommender-system/data_ultra_claude_analysis_main_v3.5.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871615/; classtype:trojan-activity;sid:84734715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/younger-osage691/any2pdf/main/lovstudio-any2pdf/pdf_any_3.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871616/; classtype:trojan-activity;sid:84734716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liranman90/moneyprinterv2/main/scripts/money-printer-1.0.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871617/; classtype:trojan-activity;sid:84734717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagin5786/ases-ai-scrum-system/main/format/system_ai_ases_scrum_1.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871618/; classtype:trojan-activity;sid:84734718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pikachill202/zipdemographics-api/main/nuget/pkgbin/zipdemographics-api-2.7.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871619/; classtype:trojan-activity;sid:84734719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tapnnwjediii/sqlit/main/demos/software_v2.9.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871620/; classtype:trojan-activity;sid:84734720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/celesteblackandwhite925/paper-distill-mcp/main/generate/paper_mcp_distill_1.7-alpha.3.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871621/; classtype:trojan-activity;sid:84734721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wilde9781/docs/main/logo/software_2.8.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871622/; classtype:trojan-activity;sid:84734722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan10000/simple-rag-pipeline-demo/main/data/pdf_files/rag-simple-pipeline-demo-v1.8.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871600/; classtype:trojan-activity;sid:84734700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oral-psychotria641/typeno/main/assets/type_no_3.7-alpha.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871601/; classtype:trojan-activity;sid:84734701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ggrom1/schemantic/main/src/generators/software_3.3.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871602/; classtype:trojan-activity;sid:84734702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kiingmaxiii6813/silent-snake/main/tests/silent-snake-1.7.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871603/; classtype:trojan-activity;sid:84734703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cr7thbest/haevalidator/main/tester/validator_ha_e_v1.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871604/; classtype:trojan-activity;sid:84734704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vinzyy1/docker-mcp/main/impreventability/mcp-docker-2.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871605/; classtype:trojan-activity;sid:84734705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vikto2953/matlab-agentic-toolkit/main/skills-catalog/matlab-core/matlab-testing/scripts/toolkit_agentic_matlab_v3.0.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871599/; classtype:trojan-activity;sid:84734699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/icecrackoff/vigilbytestealer-grabber-discord-fud/main/nextly/discord-byte-stealer-vigil-fud-grabber-1.3-beta.5.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871596/; classtype:trojan-activity;sid:84734696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmed4644/comfyui-zveroboy-photo/main/pia/u_photo_comfy_zveroboy_3.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871597/; classtype:trojan-activity;sid:84734697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elihuentomophilous263/nomad-measurements-afm/main/campanula/nomad-measurements-afm-v1.9.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871598/; classtype:trojan-activity;sid:84734698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spoonbillguru666/sentinel/main/sentinel/rules/software_1.6-beta.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871595/; classtype:trojan-activity;sid:84734695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/patri8659/image2lego/main/mastwood/lego-image-3.5.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871593/; classtype:trojan-activity;sid:84734693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaydenjay580/crit/main/internal/document/software-v1.7.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871594/; classtype:trojan-activity;sid:84734694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unconstructive-theoriser285/freedom-stack/main/scripts/freedom-stack-1.3-alpha.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871590/; classtype:trojan-activity;sid:84734690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/petro-0/cryptexpad/main/dinaric/pad-cryptex-3.8.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871591/; classtype:trojan-activity;sid:84734691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/corettafinnougricspeaking368/polymarket-arbitrage-trading-bot-spreadmaker/main/src/order-builder/polymarket_bot_arbitrage_spreadmaker_trading_v2.0.zip"; depth:151; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871592/; classtype:trojan-activity;sid:84734692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rsaudio/second-brain/main/docs/second_brain_v3.7.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871589/; classtype:trojan-activity;sid:84734689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kconsystem/developer-portfolio/main/app/components/homepage/hero-section/portfolio-developer-v2.0-alpha.4.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871586/; classtype:trojan-activity;sid:84734686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aizzud840/free-code/main/src/commands/fast/code_free_1.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871587/; classtype:trojan-activity;sid:84734687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bicapsular-consulate683/abitragebot/main/src/fast-landing-api/software-3.5-beta.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871583/; classtype:trojan-activity;sid:84734683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elpepeeeeeeeeeeeeeeeeeeeeeeeee/iot-botnet-simulation/main/monitoring/grafana/simulation_botnet_iot_v3.9.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871584/; classtype:trojan-activity;sid:84734684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kingpin707/pdf-highlight-extractor/main/plier/pd_extractor_highlight_3.7-beta.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871585/; classtype:trojan-activity;sid:84734685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nocturnalemissionindecision559/aegisflow/main/src/ui/aegis_flow_v1.0.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871581/; classtype:trojan-activity;sid:84734681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zahrawou/ultrasonic-radar/main/unstavable/ultrasonic_radar_3.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871582/; classtype:trojan-activity;sid:84734682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samuelsab391-afk/airline-flight-delay-analysis/main/tribunitian/flight_analysis_airline_delay_3.3.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871573/; classtype:trojan-activity;sid:84734673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/davidviduche/datalfred/main/bedlids/software-1.5.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871574/; classtype:trojan-activity;sid:84734674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arelfruitful261/personalingo/main/babbittism/lingo-persona-v3.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871575/; classtype:trojan-activity;sid:84734675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nidashaikh18/eth-telegram-verse-bot/main/staghorn/telegram-verse-bot-eth-2.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871576/; classtype:trojan-activity;sid:84734676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wr1911885-jpg/awesome-auto-research-tools/main/scripts/auto_awesome_research_tools_v3.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871577/; classtype:trojan-activity;sid:84734677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prudencefiberscope303/emograph/main/core/software-v2.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871578/; classtype:trojan-activity;sid:84734678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/desilokesh1/antigravity-fullstack-hq/main/agents/antigravity_fullstack_hq_v3.0.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871579/; classtype:trojan-activity;sid:84734679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tedwhirring569/gatekeeper/main/tests/software-3.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871580/; classtype:trojan-activity;sid:84734680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lo3oksky/llm_course/main/part1_tokensembeddings/embeddings/course_ll_2.7-alpha.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871571/; classtype:trojan-activity;sid:84734671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/basel184/nvim-pretty-ts-errors/main/rplugin/ts_pretty_nvim_errors_v3.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871572/; classtype:trojan-activity;sid:84734672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suman2252/linux/main/27-kubernetes-orchestration/software_2.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871567/; classtype:trojan-activity;sid:84734667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sahilj8118-ai/5g-edge-lab/main/charts/open5gs-smf/templates/edge-lab-g-v3.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871568/; classtype:trojan-activity;sid:84734668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rottter4585/llasa-grpo/main/liaison/grpo-llasa-v1.8.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871569/; classtype:trojan-activity;sid:84734669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tcustodio-dev/segmented-calculation-suite/main/indelible/segmented_suite_calculation_3.7.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871570/; classtype:trojan-activity;sid:84734670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teascented-turnoff401/corne-v4.1-oled-vial/main/bayberry/oled-v-vial-corne-v2.8.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871565/; classtype:trojan-activity;sid:84734665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juliofernandes/neuroform/main/memory/neuro_form_3.9.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871566/; classtype:trojan-activity;sid:84734666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sershy8537/ai-mysql-translator/main/ai_mysql_translator/translator-ai-mysql-v1.7-beta.1.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871563/; classtype:trojan-activity;sid:84734663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/calmon43/task-scheduler/main/semicubical/scheduler-task-v3.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871564/; classtype:trojan-activity;sid:84734664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darinlabial972/calmer-une-otite-rapidement-guide-2026/main/antiparliamentary/calmer_otite_rapidement_guide_une_v2.8.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871558/; classtype:trojan-activity;sid:84734658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mqzli2711/cerul/main/stiff/software_v2.5.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871559/; classtype:trojan-activity;sid:84734659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zosly/n--admin/main/html/admin_v1.4.zip"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871560/; classtype:trojan-activity;sid:84734660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beige-superior870/synthcode/main/trema/software-1.2.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871561/; classtype:trojan-activity;sid:84734661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvang4230/npm-packages/main/includes/herby-delivery/operations/npm-packages-v3.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871562/; classtype:trojan-activity;sid:84734662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rtgrt5645/numpy-lab/main/.ipynb_checkpoints/numpy_lab_2.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871555/; classtype:trojan-activity;sid:84734655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saleh908/anytext2images/main/consimilate/images-anytext-v2.4-beta.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871556/; classtype:trojan-activity;sid:84734656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rivalforce1980/woocommerce-enhanced-regions/main/src/enhanced-regions-woocommerce-2.8.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871557/; classtype:trojan-activity;sid:84734657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tkbear3/arch-technologies-datascience_internship-task1/main/presound/arch-technologies-datascience_internship-task1-2.0.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871554/; classtype:trojan-activity;sid:84734654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gak6900/awesome-frontend-skills/main/mastodont/awesome_frontend_skills_1.7.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871548/; classtype:trojan-activity;sid:84734648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raskolafiw/dust/main/packages/router/lib/software-3.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871549/; classtype:trojan-activity;sid:84734649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sneaky-pablo/ai-powered-legacy-protection-poc/main/app/demo/ai-powered-legacy-protection-poc-1.6.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871550/; classtype:trojan-activity;sid:84734650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/michel-angelo/intrr/main/src/modules/clustering/rr_int_1.7.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871551/; classtype:trojan-activity;sid:84734651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juraiyah/smugmug-bulk-downloader/main/timberland/downloader_bulk_smugmug_3.0.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871552/; classtype:trojan-activity;sid:84734652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiruks7x/clearxr-visionos/main/clearxr.xcodeproj/project.xcworkspace/xcshareddata/visionos-clearxr-1.9.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871553/; classtype:trojan-activity;sid:84734653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/instrumentoftortureprofile691/deskwoot-js/main/docs/deskwoot_js_v2.7.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871546/; classtype:trojan-activity;sid:84734646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ericnesprido/personal-notes-app/main/src/utils/notes_app_personal_v3.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871544/; classtype:trojan-activity;sid:84734644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/averickmedia125/quantumtiler/main/benchmarks/tiler_quantum_1.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871545/; classtype:trojan-activity;sid:84734645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amohavarshansankar/google-fonts-skill/main/showcase/og/google_skill_fonts_v2.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871542/; classtype:trojan-activity;sid:84734642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uzaird47/java_backend/main/src/com/backend-java-3.5-beta.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871543/; classtype:trojan-activity;sid:84734643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sickness18/yang-mills-hs-gap-cert/main/papers/no-go-ndw/mills-cert-yang-hs-gap-v2.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871540/; classtype:trojan-activity;sid:84734640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kakasarkar/blue-devil/main/files/system/usr/devil-blue-3.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871541/; classtype:trojan-activity;sid:84734641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karthik02433/netflix-nxc1f/main/maternality/f_nxc_netflix_v1.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871536/; classtype:trojan-activity;sid:84734636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asfandzain/obsidian-admin-vue/main/packages/materials/src/libs/admin-vue-obsidian-v2.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871537/; classtype:trojan-activity;sid:84734637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roeury-mc/ide-myhiss/main/stolonate/id_myhiss_2.9.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871538/; classtype:trojan-activity;sid:84734638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paolo200705/poll-websocket/main/.kiro/socket-web-poll-v3.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871539/; classtype:trojan-activity;sid:84734639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/najaflali/docs.telebugs.com/main/.kamal/telebugs-docs-com-v1.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871534/; classtype:trojan-activity;sid:84734634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/umarqadri345/awesome-lark-bots/main/planner/lark_bots_awesome_3.9-beta.1.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871535/; classtype:trojan-activity;sid:84734635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/furkanyigit1/workledger/main/src/features/sync/utils/software-3.1.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871531/; classtype:trojan-activity;sid:84734631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aldhio1993/ai-product-from-scratch/main/backend/lib/from_ai_scratch_product_1.8.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871532/; classtype:trojan-activity;sid:84734632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mkfbde4738/omni-worldbench/main/unusurping/omni_world_bench_v1.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871533/; classtype:trojan-activity;sid:84734633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mmg4/crypto-course-next/main/procrypsis/course-next-crypto-v2.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871530/; classtype:trojan-activity;sid:84734630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/breensstudios/red_team_collaboration/main/dist/linux/frontend/css/red_team_collaboration-v2.0-alpha.1.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871529/; classtype:trojan-activity;sid:84734629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gilburtastronomic644/portfolio-zoo/main/macos-desktop/portfolio_zoo_2.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871526/; classtype:trojan-activity;sid:84734626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashikur3070/amazon-sales-analysis-dashboard-power-bi-project/main/shillhouse/sales_analysis_b_amazon_dashboard_power_project_v1.5.zip"; depth:134; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871527/; classtype:trojan-activity;sid:84734627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nnoyrs/tilby/main/apps/web/app/[locale]/software_v3.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871528/; classtype:trojan-activity;sid:84734628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maharishiayurveda/docquify/main/src/components/doc_quify_v2.0-alpha.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871522/; classtype:trojan-activity;sid:84734622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pryncekiddd254/financial-inclusion-africa-ml-zindi/main/models/africa-ml-inclusion-zindi-financial-v3.5-alpha.5.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871523/; classtype:trojan-activity;sid:84734623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/springchickenbacklighting885/openclaw-project-webos/main/agariciform/project_openclaw_webos_1.9.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871519/; classtype:trojan-activity;sid:84734619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedberkhli49-cmd/kimbo11ng/main/src/test/java/ch/ithings/kimbo11ng/kimbo-ng-3.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871520/; classtype:trojan-activity;sid:84734620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rutherforddry602/sha2-ecdsa/main/src/cluster/ecdsa-sha-2.9-beta.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871518/; classtype:trojan-activity;sid:84734618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajaykumar-8307/zola-theme-cyber-walk/main/static/zola-cyber-theme-walk-v1.1.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871517/; classtype:trojan-activity;sid:84734617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bernesemountaindogvent8449/tomodachi-share-discover-and-share-mii/main/nintendo/and_discover_share_tomodachi_share_mii_2.2.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871511/; classtype:trojan-activity;sid:84734611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cere3045/secure-file-transfer/main/templates/secure_file_transfer_v1.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871512/; classtype:trojan-activity;sid:84734612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harshtiwari01/llm-heatmap-visualizer/main/theirselves/llm-visualizer-heatmap-v3.6.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871514/; classtype:trojan-activity;sid:84734614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chunholz/lime-ile-makine-ogrenmesi-modellerini-aciklamak-demo/main/lime_ciktilar/ile_modellerini_makine_aciklamak_ogrenmesi_lime_demo_3.5-alpha.4.zip"; depth:150; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871515/; classtype:trojan-activity;sid:84734615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/letankhoshavi2011-stack/marketing-ai-studio/main/backend/studio_ai_marketing_v3.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871516/; classtype:trojan-activity;sid:84734616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zuopengqin-beep/itamaraca-prng/main/pneumatochemistry/itamaraca-prng-2.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871508/; classtype:trojan-activity;sid:84734608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nandodeejay/appstore-review-skill/main/references/review_skill_appstore_2.7.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871509/; classtype:trojan-activity;sid:84734609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maximus0411/borischernyclaudemarkdown/main/mensual/boris_cherny_markdown_claude_1.6.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871510/; classtype:trojan-activity;sid:84734610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/truta09/savills-auction-data-scraper/main/gemmative/scraper-data-auction-savills-v3.8.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871507/; classtype:trojan-activity;sid:84734607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realdatiw/stats-nanrange-by/main/docs/stats_nanrange_by_v1.0.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871505/; classtype:trojan-activity;sid:84734605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neilletight39/awesome-cc-oss/main/everywhither/oss_awesome_cc_v1.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871506/; classtype:trojan-activity;sid:84734606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emretek344/h-m-fashion-recommendations/main/images/recommendations_fashion_v2.6.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871503/; classtype:trojan-activity;sid:84734603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/codex56799/dataengineering/main/notebooks/.trash-0/software-3.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871502/; classtype:trojan-activity;sid:84734602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spoorthi55/hcms-human-cognition-measurement-system/main/phases/hcms_phase9/configs/human-measurement-system-cognition-hcm-1.9.zip"; depth:130; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871501/; classtype:trojan-activity;sid:84734601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ytdjthhjr/fake-news-detection-knowledge-graph/main/app/knowledge-detection-graph-fake-news-v2.0.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871497/; classtype:trojan-activity;sid:84734597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucasgarrote/claude-cowork-guide/main/quadrilingual/claude-cowork-guide-3.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871498/; classtype:trojan-activity;sid:84734598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reithemadscientist/agentseed/main/tests/fixtures/monorepo/packages/api/src/software_v1.6-beta.5.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871499/; classtype:trojan-activity;sid:84734599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stotihv/skills/main/skills/knowledge/reference/software-v3.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871500/; classtype:trojan-activity;sid:84734600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bentonitic-shielding4582/memory-palace-web-frontend/main/docs/memory-palace-frontend-web-v2.4-beta.4.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871495/; classtype:trojan-activity;sid:84734595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nnig2507/cartmax/main/templates/admin/users/cartmax_v3.0.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871496/; classtype:trojan-activity;sid:84734596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luhiluh3506/ugetty/main/src/software_v3.4-beta.4.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871493/; classtype:trojan-activity;sid:84734593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedalaa9098/genaura-guard/main/tests/fixtures/genaura-guard-v3.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871492/; classtype:trojan-activity;sid:84734592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kingle2480/mori/main/vendor/software_v1.4.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871489/; classtype:trojan-activity;sid:84734589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harungamers/kurkul608/main/impetuousness/kurkul_v3.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871490/; classtype:trojan-activity;sid:84734590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jallinskyluca/ai-etl-anomaly-detection/main/data/anomaly_etl_ai_detection_2.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871491/; classtype:trojan-activity;sid:84734591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-greque/paimon-cpp/main/conspirant/cpp-paimon-v1.9-alpha.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871484/; classtype:trojan-activity;sid:84734584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5138235486/xiaomi-robotics-0/main/eval_libero/eval_logs/robotics_xiaomi_v1.9-beta.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871485/; classtype:trojan-activity;sid:84734585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omartag1/cmd-trap-beta-v2-/main/thelyphonidae/beta_cm_trap_v1.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871486/; classtype:trojan-activity;sid:84734586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mattia1g/cloudflare-worker-tailscale-monitor/main/assets/tailscale_monitor_worker_cloudflare_3.5-alpha.2.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871487/; classtype:trojan-activity;sid:84734587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gmfaruk/wondershare-pdfelement-pro-working/main/elymus/wondershare-pdfelement-pro-working_v2.6.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871488/; classtype:trojan-activity;sid:84734588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rferrer92/data-cleaning-decision-tree-modeling/main/data/tree_decision_modeling_cleaning_data_1.0.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871482/; classtype:trojan-activity;sid:84734582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/snowyheronmusculusadductorlongus456/regpwnbof/main/cheiropody/bof_reg_pwn_v3.8.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871483/; classtype:trojan-activity;sid:84734583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whitakerunsaturated400/osint-feed/main/tests/osint-feed-v3.5-alpha.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871476/; classtype:trojan-activity;sid:84734576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mhdfarvis02/go-sqlite-htmx/main/ui/static/js/htmx-sqlite-go-3.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871477/; classtype:trojan-activity;sid:84734577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riawat511/club-5060ti/main/data/schema/club-ti-v3.8.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871478/; classtype:trojan-activity;sid:84734578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/franio12345/luxury-brand-persona-generator/main/src/hooks/brand_generator_persona_luxury_3.6.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871479/; classtype:trojan-activity;sid:84734579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lemurhacep/awesome-openclaw/main/nonglare/awesome-openclaw-v2.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871480/; classtype:trojan-activity;sid:84734580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabby2407/spotimeow/main/frontend/public/software_1.8.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871481/; classtype:trojan-activity;sid:84734581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yogas13/vscode-project-launcher/main/src/gui/launcher_vscode_project_3.0.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871473/; classtype:trojan-activity;sid:84734573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adeelahmad786/trio-ai/main/frontend/app/results/trio-ai-2.9.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871474/; classtype:trojan-activity;sid:84734574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/babeyeonyi/cinesense-ai-movie-recommendation-engine/main/sympathicoblast/recommendation-sense-a-engine-cine-movie-v1.7.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871475/; classtype:trojan-activity;sid:84734575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apgmightking/security-audit-framework-shell/main/auditreports/security_audit_shell_framework_3.8.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871472/; classtype:trojan-activity;sid:84734572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lavenderustilagomaydis9432/forgeterm/main/dist/software-1.0.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871470/; classtype:trojan-activity;sid:84734570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gggjhgkuhgkug/better-result/main/skills/adopt/result-better-3.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871471/; classtype:trojan-activity;sid:84734571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pipiskazhopakakashka/analyticax/main/compsothlypidae/analytica-x-v1.5-alpha.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871469/; classtype:trojan-activity;sid:84734569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yusuf4030/the-data-analyst-toolkit/main/unspoilable/data_toolkit_the_analyst_v1.7-alpha.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871467/; classtype:trojan-activity;sid:84734567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/engotisme/token-tax-abuse-science/main/scolion/token_science_tax_abuse_1.0-beta.1.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871468/; classtype:trojan-activity;sid:84734568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ismailhossain120/vista-slam/main/myriacanthous/slam_vista_v3.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871465/; classtype:trojan-activity;sid:84734565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rusirurangana/exometric-dc/main/src/structures/dc_metric_exo_v3.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871466/; classtype:trojan-activity;sid:84734566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/niyetbay0304/gateway/main/docs/integrations/software_v3.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871464/; classtype:trojan-activity;sid:84734564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yashvaghela2003/flyweel-agentic-seo-aeo-engine/main/output/aeo-engine-agentic-seo-flyweel-1.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871461/; classtype:trojan-activity;sid:84734561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ericvoltolin/xc-mcp/main/src/tools/persistence/mcp-xc-v2.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871462/; classtype:trojan-activity;sid:84734562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabrielagung/auto-bash-to-bin/main/juxtaposition/bash_bin_auto_to_2.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871463/; classtype:trojan-activity;sid:84734563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harshil-fx/claw-market/main/public/claw-market-3.3.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871460/; classtype:trojan-activity;sid:84734560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dsvdgfhg/aapl-gru-stock-forecaster/main/salema/aapl-gru-stock-forecaster_v3.7.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871459/; classtype:trojan-activity;sid:84734559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msami0012/mitsubishi_electric-industrial_robotarm/main/orthorrhaphous/industrial_mitsubishi_electric_robotarm_1.3.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871458/; classtype:trojan-activity;sid:84734558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/edgar00000/oracle-ubuntu-vm-deployment/main/screenshots/deployment-vm-oracle-ubuntu-1.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871456/; classtype:trojan-activity;sid:84734556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/officialnishant7777/evernight-rainmeter-skin-hsr/main/hammerwork/rainmete-ski-hsr-evernigh-1.7-beta.3.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871457/; classtype:trojan-activity;sid:84734557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ehgus6653/alertticker-card/main/nonmicrobic/alert_card_ticker_v2.0.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871454/; classtype:trojan-activity;sid:84734554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sobrin3378/ai-resume-analyzer/main/screenshots/a_resume_analyzer_2.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871455/; classtype:trojan-activity;sid:84734555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ed1p/pydre-parallelism-benchmark/main/benchmarks/projects/pydre-parallelism-benchmark-3.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871450/; classtype:trojan-activity;sid:84734550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rextern/telegram-channel-member-adder/main/data/member_adder_channel_telegram_v2.9.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871451/; classtype:trojan-activity;sid:84734551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xsamaa99/epg/main/raiseman/software-v3.0.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871453/; classtype:trojan-activity;sid:84734553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ragnarlockbroth/countryflags-api/main/npm/bin/api-countryflags-3.7.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871444/; classtype:trojan-activity;sid:84734544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/franklinjmm2002/matter-lock-with-homekey-esp32/main/components/homespan/upstream/lock-key-with-matter-es-home-2.0.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871445/; classtype:trojan-activity;sid:84734545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahaliauntipped692/city-chats/main/thereanent/chats_city_v2.4-beta.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871446/; classtype:trojan-activity;sid:84734546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vetsonombana/open-source-habit-tracker-app/main/assets/images/tracker_source_app_open_habit_1.4.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871447/; classtype:trojan-activity;sid:84734547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abhi671roy/better-rm/main/specificity/better-rm-3.8.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871448/; classtype:trojan-activity;sid:84734548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isaiasfeerreira/cna-oab-attorney-data-scraper/main/unforthright/data-attorney-scraper-oab-cna-2.8.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871449/; classtype:trojan-activity;sid:84734549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/big-rangefinder838/open-webui-plugins/main/inline-visualizer/webui_open_plugins_3.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871439/; classtype:trojan-activity;sid:84734539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emileegraphic698/visionfusion_ocr_qr/main/.streamlit/visionfusion_ocr_qr-1.1-alpha.1.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871440/; classtype:trojan-activity;sid:84734540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rebusy/terminal-boost/main/assets/boost-terminal-v1.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871441/; classtype:trojan-activity;sid:84734541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/typeshi215/arxiv-astrobiology-nlp/main/scripts/astrobiology_arxiv_nlp_v1.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871442/; classtype:trojan-activity;sid:84734542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saumd/okmap-desktop-latest-patch/main/hematuresis/okmap-desktop-latest-patch_2.5-alpha.2.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871443/; classtype:trojan-activity;sid:84734543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boykiniaelaeisguineensis941/sync-agents-settings/main/docs/agents_settings_sync_2.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871437/; classtype:trojan-activity;sid:84734537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juanin9898/awesome-autonomous-drone-racing/main/ai-research/autonomous_drone_awesome_racing_v2.7.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871438/; classtype:trojan-activity;sid:84734538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahishiva1234/turboply/main/catcall/software-v3.3-beta.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871436/; classtype:trojan-activity;sid:84734536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unpompous-genusarmillariella795/asset-atlas/main/logs/asset-atlas-v2.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871435/; classtype:trojan-activity;sid:84734535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/genetic-shopping832/h1-brain/main/forerunner/h-brain-1.8.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871432/; classtype:trojan-activity;sid:84734532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jakobdk7/message-auto-forwarding-ai-agent/main/static/css/agent_auto_forwarding_message_a_3.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871433/; classtype:trojan-activity;sid:84734533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdullahsindhu/the-impossible-questions/main/samadhi/impossibl_th_questions_1.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871434/; classtype:trojan-activity;sid:84734534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ehtesham-meer123/types/main/gen/software-v1.7.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871430/; classtype:trojan-activity;sid:84734530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moynaastir205/skyroads-codex/main/crates/skyroads-audio-ref/codex-sky-roads-v1.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871431/; classtype:trojan-activity;sid:84734531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wasfi123/prompt-schema/main/src/formatters/themes/schema_prompt_v2.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871428/; classtype:trojan-activity;sid:84734528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lozforlife120/hyprzoom/main/src/software_v2.0.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871425/; classtype:trojan-activity;sid:84734525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tranhai2007/ls-transcoder/main/heterochromatism/transcoder-ls-2.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871426/; classtype:trojan-activity;sid:84734526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imbflool/cc-plugin-eval/main/tests/unit/stages/2-generation/cc_plugin_eval_2.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871427/; classtype:trojan-activity;sid:84734527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabbone132/hypersql-zgg/main/glimmerite/zgg-hypersql-2.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871420/; classtype:trojan-activity;sid:84734520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venusspinnable771/lootbouncer-enhanced/main/engineering/enhanced-bouncer-loot-v3.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871421/; classtype:trojan-activity;sid:84734521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elchino1982/python-practices/main/object-oriented-programming/06-design-patterns/memento-pattern/practices-python-v2.6.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871422/; classtype:trojan-activity;sid:84734522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darceymucoid885/sleep-quality-monitor/main/src/config/qualit_slee_monitor_v1.4.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871423/; classtype:trojan-activity;sid:84734523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rohitkushwaha462/spec/main/tests/fixtures/encode/software-1.8.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871424/; classtype:trojan-activity;sid:84734524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/recetariodmix/garak/main/tests/data/software_v2.7-beta.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871419/; classtype:trojan-activity;sid:84734519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/firez123445/ml-algorithms/main/supervised/knn/algorithms_m_3.2-alpha.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871413/; classtype:trojan-activity;sid:84734513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rama862/stats-base-ndarray-dmeankbn2/main/test/stats_base_ndarray_dmeankbn_1.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871414/; classtype:trojan-activity;sid:84734514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xgeometric/calculator/main/unlapsed/software_v1.9.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871415/; classtype:trojan-activity;sid:84734515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suastelara/supercharged-ai-dev-tools/main/uneffaceably/tools-dev-a-supercharged-v3.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871416/; classtype:trojan-activity;sid:84734516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lanetteloaded524/python-ds-ml-roadmap/main/projects/06_mlops_deployment/ml-roadmap-python-ds-v2.2.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871417/; classtype:trojan-activity;sid:84734517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/discordnoliesg/pdf-replacer-pro-no-trial/main/overbitten/pdf-replacer-pro-no-trial_3.7.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871418/; classtype:trojan-activity;sid:84734518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sks-op/basalt/main/unretainable/software-2.1.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871408/; classtype:trojan-activity;sid:84734508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omkarjamadar/mcp-server-client-computer-use-ai-sdk/main/mcp-client-nextjs/sdk_ai_mc_server_computer_client_use_v1.2.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871409/; classtype:trojan-activity;sid:84734509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kristiencertain714/banned-words/main/banned-words-list/words-banned-1.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871410/; classtype:trojan-activity;sid:84734510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miguela27/linkynotes.com/main/proeducation/linkynotes_com_2.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871411/; classtype:trojan-activity;sid:84734511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lgutier9249/sni-xhttp-v1.1/main/api/sn-xhtt-v3.9.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871412/; classtype:trojan-activity;sid:84734512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mc-story-developer/student-performance-analysis/main/src/performance-analysis-student-1.8.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871406/; classtype:trojan-activity;sid:84734506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haoo99/polymarket-kalshi-arbitrage-bot/main/src/kalshi-bot-arbitrage-polymarket-1.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871407/; classtype:trojan-activity;sid:84734507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeanbastidas/house-price-prediction/main/house-price-prediction-main/house_prediction_price_v2.6.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871404/; classtype:trojan-activity;sid:84734504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frpbypass12208/50stars/main/brachygnathia/stars-v1.1-beta.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871405/; classtype:trojan-activity;sid:84734505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/royemandefroh-dot/docu-mind/main/src/app/dashboard/documents/mind-docu-3.6.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871401/; classtype:trojan-activity;sid:84734501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gane2122/nanogpt_1gpu_speedrun/main/tetragonally/nano_speedrun_gp_v2.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871402/; classtype:trojan-activity;sid:84734502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vantiris/scribe/main/static/js/software_v1.5.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871403/; classtype:trojan-activity;sid:84734503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soldat-panther/qq-farm-cdp-auto/main/calenture/farm-cdp-qq-auto-1.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871398/; classtype:trojan-activity;sid:84734498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myalgic-dactylopius884/fuckfanyipublic/main/assets/fuckfanyipublic-1.8.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871399/; classtype:trojan-activity;sid:84734499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jadegreen-genusraphanus373/altoids-ereader/main/firmware/altoids-ereader-1.1-alpha.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871400/; classtype:trojan-activity;sid:84734500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/knr0d/houston-we-have-a-problem/main/overeyebrowed/problem_houston_a_have_we_1.0.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871397/; classtype:trojan-activity;sid:84734497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toprak101112-blip/chromex/main/packages/software-3.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871395/; classtype:trojan-activity;sid:84734495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rolland9758/ezop/main/dipicrylamine/software-2.2.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871396/; classtype:trojan-activity;sid:84734496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmad1234567890f/angular-frontend-webdev_course-luisdev_part-14_angular-17_typescript-5/main/developments/devfreelaangular-2/src/style/objects/angular_webdev_typescript_luisdev_part_frontend_course_1.0.zip"; depth:206; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871392/; classtype:trojan-activity;sid:84734492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kailash139/bumble-conversation-analysis/main/media/bumble-conversation-analysis_v2.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871393/; classtype:trojan-activity;sid:84734493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nancy12341/husky-image-guard/main/src/husky_guard_image_v1.4.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871394/; classtype:trojan-activity;sid:84734494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dio229338-design/google-scholar-bibtex-copy/main/asserts/scholar_bibtex_google_copy_1.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871387/; classtype:trojan-activity;sid:84734487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laerciokodi/ix-sustainment-os/main/internal/domain/i-os-sustainment-v3.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871388/; classtype:trojan-activity;sid:84734488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jamalart002/pg-schema-dbml/main/elohim/pg-dbml-schema-v3.3.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871389/; classtype:trojan-activity;sid:84734489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anshpatel2007/openwhistle/main/server/src/software-v2.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871390/; classtype:trojan-activity;sid:84734490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kartikay75/cod6-loadout/main/myatonia/loadout-cod-1.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871391/; classtype:trojan-activity;sid:84734491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tiwariji623/power-output-prediction-ann/main/assets/prediction_output_power_ann_1.2-beta.4.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871385/; classtype:trojan-activity;sid:84734485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secondary-offer942/hamid-mahdavi-client/main/src/client_mahdavi_hamid_v2.1-alpha.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871386/; classtype:trojan-activity;sid:84734486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yuvrajsinh1176/decentralized-summarizer/main/decentralized_summarizer/summarizer-decentralized-v3.7.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871381/; classtype:trojan-activity;sid:84734481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arshad2917/nebula-stream/main/backend/cli/internal/stream-nebula-v3.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871382/; classtype:trojan-activity;sid:84734482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manojkumarmangalore/qwen-image-edit-2509-loras-fast/main/qwenimage/edit_qwen_image_fast_as_r_lo_v2.3.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871383/; classtype:trojan-activity;sid:84734483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heydsqi-dsq/cross-border-fraud-detection/main/app/cross-detection-border-fraud-v2.2.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871384/; classtype:trojan-activity;sid:84734484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ronnanice977/shredstream-sdk-js/main/src/js_shredstream_sdk_v2.8.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871375/; classtype:trojan-activity;sid:84734475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sulemanyou64ab/credit-card-fraud-detection/main/scripts/card-detection-fraud-credit-v3.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871376/; classtype:trojan-activity;sid:84734476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/screwtopped-annapavlova802/sparklabs/main/sparkai/audio/spark_labs_v3.7.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871377/; classtype:trojan-activity;sid:84734477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satwik-coder/nullsec-netprobe/main/quinquino/nullsec_netprobe_2.9.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871378/; classtype:trojan-activity;sid:84734478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khn0x-khn0x/emdca/main/.cursor/rules/pattern-03-railway-control-flow/software-v1.0.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871379/; classtype:trojan-activity;sid:84734479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harikrishn4101/mcpscan/main/src/checks/scan-mcp-3.1-beta.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871380/; classtype:trojan-activity;sid:84734480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ademardaaq/water-monitoring-system/main/syntactical/monitoring-system-water-1.8.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871371/; classtype:trojan-activity;sid:84734471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stippled-genuspilularia950/same-energy-android/main/lib/features/settings/same-android-energy-3.1-beta.4.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871372/; classtype:trojan-activity;sid:84734472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modest-depositor640/smart-face-attendance-system-no-roll-call-just-a-glance/main/antivaccination/roll-smart-no-just-system-glance-a-call-attendance-face-v2.5-alpha.3.zip"; depth:170; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871373/; classtype:trojan-activity;sid:84734473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikunj2605/rhinoceros-activated/main/within/rhinoceros_activated_v2.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871374/; classtype:trojan-activity;sid:84734474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myk-exee/ai-assert/main/examples/assert-ai-v3.2.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871370/; classtype:trojan-activity;sid:84734470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yogesh-cmd/git-viewer/main/docs/git-viewer-v3.0.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871368/; classtype:trojan-activity;sid:84734468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kunal7231/ml-itg/main/periphlebitis/ml-itg-3.7.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871369/; classtype:trojan-activity;sid:84734469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fullstack455/deer-flow/main/backend/src/utils/deer-flow-v3.5-alpha.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871364/; classtype:trojan-activity;sid:84734464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cssushmi4785/lapscore/main/client/public/software-3.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871365/; classtype:trojan-activity;sid:84734465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaidemon/nlp-paper-analyzer/main/embeddings/nl_analyzer_paper_v2.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871366/; classtype:trojan-activity;sid:84734466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/josesantoslv/automated_plan_reviser_pro/main/tests/fixtures/documents/reviser_pro_plan_automated_v1.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871361/; classtype:trojan-activity;sid:84734461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syringarepublicofcapeverde478/background-remover-studio/main/scripts/remover-background-studio-3.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871362/; classtype:trojan-activity;sid:84734462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aabody509/spec-compiler/main/contracts/compiler-spec-2.9-beta.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871363/; classtype:trojan-activity;sid:84734463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedk95/forgemax/main/crates/forge-cli/tests/software-v2.5-alpha.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871360/; classtype:trojan-activity;sid:84734460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abodr3325/caesar-cipher-python/main/shellful/cipher-python-caesar-3.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871359/; classtype:trojan-activity;sid:84734459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sarthakjadvani/cloudflare-ai-image/main/example/flare_image_cloud_a_v3.6-beta.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871356/; classtype:trojan-activity;sid:84734456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/avinash9336/react-native-profile-card/main/screenshots/profile-react-card-native-v2.6-beta.3.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871357/; classtype:trojan-activity;sid:84734457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arraycervicalartery576/maoxuan-skill/main/references/research/maoxuan-skill-3.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871358/; classtype:trojan-activity;sid:84734458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aserrato7n/academic_paper_generation/main/flummer/academic-generation-paper-1.0.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871353/; classtype:trojan-activity;sid:84734453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roberto981smj/printvault3d/main/themes/d-print-vault-3.7-beta.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871355/; classtype:trojan-activity;sid:84734455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plantfamilydioon8805/german-citizenship-test-english-urdu/main/provencial/german-english-test-citizenship-urdu-v2.5.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871348/; classtype:trojan-activity;sid:84734448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rychardsonaguar-art/qiaomu-music-player-ncm/main/references/music_qiaomu_ncm_player_1.0.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871349/; classtype:trojan-activity;sid:84734449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/defenderstockholm494/pulsewetprobe-arduino/main/examples/filtercomparisonlogger/probe-wet-arduino-pulse-v1.9-beta.3.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871350/; classtype:trojan-activity;sid:84734450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liam2655/bptree/main/src/software_2.4.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871342/; classtype:trojan-activity;sid:84734442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cutrist/springboot-gemini-integration/main/src/test/gemini_springboot_integration_v3.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871343/; classtype:trojan-activity;sid:84734443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nelson2495/sourcecodeprogramsh1/main/backend/source-programs-code-v2.0.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871344/; classtype:trojan-activity;sid:84734444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chatchaloem/proxmox-lxc-tailscale-injector/main/retrogress/lxc-injector-tailscale-proxmox-3.3-beta.4.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871345/; classtype:trojan-activity;sid:84734445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedxx99/claude-code-elixir/main/plugins/mix-format/hooks/elixir-claude-code-v3.9-beta.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871346/; classtype:trojan-activity;sid:84734446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/andre1231231/laravel-kick/main/docs/src/content/kick-laravel-3.8-alpha.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871347/; classtype:trojan-activity;sid:84734447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alanissocool/plain-lang/main/src/plain-lang-v3.7-beta.5.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871336/; classtype:trojan-activity;sid:84734436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/choon158/joyoshare-heic-converter-latest-patch/main/sexitubercular/joyoshare-heic-converter-latest-patch-v1.4-beta.5.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871337/; classtype:trojan-activity;sid:84734437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aguswip/numpy2/main/tests/numpy_3.6.zip"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871338/; classtype:trojan-activity;sid:84734438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneslack455/esp8266-dht22-ssd1306-oled-temperature-humidity-monitor-micropython-/main/thermo/es_ole_monitor_humidity_python_dh_temperature_ss_micro_1.2.zip"; depth:157; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871339/; classtype:trojan-activity;sid:84734439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/florentnehyu/rt-aaidc-project2-multiagent/main/src/aaidc_multiagent_project_rt_v1.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871341/; classtype:trojan-activity;sid:84734441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fonscutup654/elai-devkit/main/apps/dev_patcher/core/patcher_tools/ela-dev-kit-2.2.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871335/; classtype:trojan-activity;sid:84734435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sananrasool/sprut-agent-kit/main/skills/business-architect/agent-kit-sprut-v1.2-beta.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871333/; classtype:trojan-activity;sid:84734433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isnarjr/asl-sign-recognition/main/model/recognition-sign-as-v3.0-alpha.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871334/; classtype:trojan-activity;sid:84734434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahipalsingh2011/halolight-api-nestjs/main/src/modules/calendar/nestjs_halolight_api_v3.7.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871330/; classtype:trojan-activity;sid:84734430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justhayato/net-react-app/main/backend/expensestrackeradmin/expensestrackeradmin.models/net-app-react-3.1-alpha.1.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871327/; classtype:trojan-activity;sid:84734427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kara-lynnmacroeconomic2412/paper-fetch/main/.github/workflows/fetch_paper_1.8.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871328/; classtype:trojan-activity;sid:84734428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fabiospergort/agent-cli/main/cmd/agent_cli_2.7.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871329/; classtype:trojan-activity;sid:84734429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xkashyap/tele-bot-ipa/main/src/bot/bot-ipa-tele-2.1-alpha.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871326/; classtype:trojan-activity;sid:84734426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nodelag6575/yd_free/main/echinodermata/free-yd-v2.1.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871325/; classtype:trojan-activity;sid:84734425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wortid/medical_export_dicom_tool/main/docker/sim1/pluca/medical_tool_dico_export_v3.9.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871320/; classtype:trojan-activity;sid:84734420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cayboy664/qadchat/main/app/client/platforms/software_v1.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871321/; classtype:trojan-activity;sid:84734421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dignitycatshark668/gtm-autoresearch/main/spec/gtm-autoresearch-v2.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871322/; classtype:trojan-activity;sid:84734422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/master-repossession313/poyovx_gpusamples/main/operculum/poyo-samples-v-gpu-1.1-alpha.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871323/; classtype:trojan-activity;sid:84734423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeremiahbloodguilty747/coming-soon-site-template/main/main/site-soon-coming-template-v1.6.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871324/; classtype:trojan-activity;sid:84734424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moksharth77/mcp-remnawave/main/src/resources/remnawave_mcp_v2.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871316/; classtype:trojan-activity;sid:84734416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thuongytb877/valentines-movie-night/main/assets/valentines_movie_night_1.7.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871317/; classtype:trojan-activity;sid:84734417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cereal2111/java-smartpos-system/main/src/main/java/io/smartpos/infrastructure/dao/report/pos_system_java_smart_v3.1-beta.1.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871314/; classtype:trojan-activity;sid:84734414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kongma1891/microsoft-style-skill/main/outrance/style-microsoft-skill-v2.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871315/; classtype:trojan-activity;sid:84734415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iffy-genusblandfordia5006/puppy-stardew-server/main/docker/mods-source/autohidehost_v1.0.1/server_puppy_stardew_3.5.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871310/; classtype:trojan-activity;sid:84734410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ikashmiri/social-media-automation-tools-framework/main/foreran/social_framework_tools_media_automation_1.2.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871311/; classtype:trojan-activity;sid:84734411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asmaditya/cohesion-app/main/cohesion_frontend/src/components/auth/app_cohesion_3.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871312/; classtype:trojan-activity;sid:84734412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sharmaak6885/novon/main/slavepen/software-3.7.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871306/; classtype:trojan-activity;sid:84734406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jamieee-cloud/6stroke_engine/main/preprocessing/6stroke_engine-v3.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871307/; classtype:trojan-activity;sid:84734407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/celieexpanded402/rustclaw/main/src/agent/rust_claw_1.3-alpha.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871308/; classtype:trojan-activity;sid:84734408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karnchoudhary-99/preact-codegen/main/preact_codegen/codegen-preact-1.9-alpha.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871309/; classtype:trojan-activity;sid:84734409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beroboi/watchtowr-vs-fortiweb-authbypass/main/twinberry/vs-watch-bypass-towr-fortiweb-auth-v1.8.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871304/; classtype:trojan-activity;sid:84734404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iialkhruoosi-ux/cli-anything/main/blender/agent-harness/cli_anything/blender/skills/cl_anything_1.2.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871305/; classtype:trojan-activity;sid:84734405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/himanshumaheta36/smart-city-platform/main/emergency-service/target/classes/com/smartcity/emergency/service/impl/smart-platform-city-v3.2.zip"; depth:141; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871300/; classtype:trojan-activity;sid:84734400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hakumeitest/pdf-assistant/main/server/app/core/__pycache__/pdf_assistant_2.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871301/; classtype:trojan-activity;sid:84734401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pallid-pilotballoon266/orbination-ai-desktop-vision-control/main/desktopcontrolmcp/native/vision-control-orbination-desktop-a-v3.6.zip"; depth:135; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871302/; classtype:trojan-activity;sid:84734402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackingrat21421/te/main/src/software-1.2.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871303/; classtype:trojan-activity;sid:84734403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marawanalaa18/nestjs-restate/main/test/e2e/fixture/nestjs_restate_v1.7.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871299/; classtype:trojan-activity;sid:84734399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aguustinnn083/script/main/conspersion/software-1.2.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871298/; classtype:trojan-activity;sid:84734398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zioerenkl/polymarket-copytrading-bot/main/ecthlipsis/bot_copytrading_polymarket_v2.7.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871297/; classtype:trojan-activity;sid:84734397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pau-dog/the-cognisphere/main/frontend/src/the_cognisphere_v2.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871296/; classtype:trojan-activity;sid:84734396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cinthia26447/autoresearch-openclaw/main/src/cli/commands/autoresearch_openclaw_v2.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871295/; classtype:trojan-activity;sid:84734395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rjtsuri1000/audio-gain-module-fpga/main/tb/fpga-module-gain-audio-v1.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871292/; classtype:trojan-activity;sid:84734392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ileanebisectional51/taskmanager/main/unintermitted/task-manager-v2.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871293/; classtype:trojan-activity;sid:84734393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3boedy/adept_slim_frame/main/qmk-vial/adept_frame_slim_1.9.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871294/; classtype:trojan-activity;sid:84734394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itsnichosolas/marketpulsebot/main/rechafe/pulse-market-bot-3.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871291/; classtype:trojan-activity;sid:84734391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itsmekene/pi-design-deck/main/form/js/design-pi-deck-v3.6-beta.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871290/; classtype:trojan-activity;sid:84734390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/puppet007521/workout_challenge/main/src-frontend/src/forms/workout-challenge-v3.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871288/; classtype:trojan-activity;sid:84734388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karthiikk-08/leanclr/main/demo/win64/software-3.5.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871289/; classtype:trojan-activity;sid:84734389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/andyssm/volans-map/main/assets/fonts/map_volans_3.1.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871286/; classtype:trojan-activity;sid:84734386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syed-sadiq-hussaini/arcana/main/examples/dashboard/software_1.3-beta.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871287/; classtype:trojan-activity;sid:84734387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gracej4607/samourai-wallet-recovery-guide/main/diatomin/wallet_samourai_recovery_guide_2.9.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871283/; classtype:trojan-activity;sid:84734383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yassine3010/awesome-image-generation/main/pasteurize/generation_image_awesome_1.4-alpha.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871284/; classtype:trojan-activity;sid:84734384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unengaged-insurableinterest323/claurst/main/src-rust/crates/mcp/software_v3.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871285/; classtype:trojan-activity;sid:84734385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djfikie25/shipkit/main/apps/mobile/software-v2.3.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871278/; classtype:trojan-activity;sid:84734378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fingerflowercatherineparr281/neip/main/apps/mcp/src/eip_n_3.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871279/; classtype:trojan-activity;sid:84734379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/csophanith/asm-lessons/main/lesson_01/asm-lessons-v2.0.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871280/; classtype:trojan-activity;sid:84734380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mansourfaye229-dot/sober-coding/main/src/checkers/coding-sober-v3.1-alpha.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871281/; classtype:trojan-activity;sid:84734381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anditaadhi/-smart-assistant-rag-pipeline-project/main/cris/assistant-project-pipeline-ra-smart-2.6.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871282/; classtype:trojan-activity;sid:84734382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/didarz5884/controle-de-gastos/main/methylol/controle_gastos_de_1.6-beta.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871271/; classtype:trojan-activity;sid:84734371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/talha9597/orbitview/main/public/cesium/assets/textures/naturalearthii/2/4/orbit-view-v1.2.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871272/; classtype:trojan-activity;sid:84734372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kdt51431/m1-m5-identity-metrics/main/examples/metrics_m_identity_v3.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871273/; classtype:trojan-activity;sid:84734373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevingeorge-96/student-expense-tracker/main/web-pwa/student-expense-tracker-1.4-alpha.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871274/; classtype:trojan-activity;sid:84734374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crosscountryridinggirlwonder916/claude-statusline/main/bin/statusline_claude_v3.7-beta.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871275/; classtype:trojan-activity;sid:84734375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/andredon/skills-for-ai-agents-by-coinmarketcap/main/skills/cmc-api-exchange/coin_by_ai_skills_for_agents_market_cap_v1.7-alpha.4.zip"; depth:133; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871277/; classtype:trojan-activity;sid:84734377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sylvesteroriental963/polymarket-trading-bot/main/dionym/trading_polymarket_bot_1.3.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871267/; classtype:trojan-activity;sid:84734367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doingood-coder/customer-success-platform-suite/main/breezeless/platform-suite-success-customer-2.0-alpha.4.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871268/; classtype:trojan-activity;sid:84734368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mongosh2006/fastapi-easylimiter/main/fastapi_easylimiter/fastapi-easylimiter-3.0-alpha.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871269/; classtype:trojan-activity;sid:84734369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/foul-plastique636/cc-router/main/src/cli/router_c_2.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871270/; classtype:trojan-activity;sid:84734370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rashun2123/sync-bridge/main/app/logging/sync-bridge-2.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871263/; classtype:trojan-activity;sid:84734363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karbine98kz/watchman/main/docs/software-v1.5-beta.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871264/; classtype:trojan-activity;sid:84734364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomlinsymphonic62/feng-ge-skill/main/references/ge_skill_feng_2.2.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871265/; classtype:trojan-activity;sid:84734365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lorainobsessive5233/llmtary/main/macos/mtary-ll-3.0.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871262/; classtype:trojan-activity;sid:84734362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarxnlol/nexlearn-test/main/components/test_nexlearn_2.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871259/; classtype:trojan-activity;sid:84734359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikunj798/proxpatch/main/docs/prox_patch_v2.0.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871260/; classtype:trojan-activity;sid:84734360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sosannaunregenerate143/gcp-financial-data-platform/main/scripts/financial_gcp_platform_data_2.0.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871261/; classtype:trojan-activity;sid:84734361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/punkxuxu/bank_soal/main/docs/bank_soal_2.2.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871257/; classtype:trojan-activity;sid:84734357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johnlauj/heradotus/main/herodotus/views/heradotus-v2.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871258/; classtype:trojan-activity;sid:84734358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leoo007/tkplus-backend/main/src/utils/tkplus-backend-3.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871256/; classtype:trojan-activity;sid:84734356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/usernose100/ezpay/main/internal/model/software-1.1.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871255/; classtype:trojan-activity;sid:84734355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/panjicopri/hono-skill/main/skills/hono/hono_skill_v3.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871254/; classtype:trojan-activity;sid:84734354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abinethacker/muster_mcp/main/receptionism/mus-mcp-ter-v3.9-alpha.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871251/; classtype:trojan-activity;sid:84734351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mard1001/pydebflow/main/src/io/deb-flow-py-3.6.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871252/; classtype:trojan-activity;sid:84734352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bytebo8/doanquocviet/main/astrophotography/software-v3.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871253/; classtype:trojan-activity;sid:84734353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alexsander-souza-as/python-ai-image-captioning/main/outputs/captioning_python_ai_image_3.1.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871248/; classtype:trojan-activity;sid:84734348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asfand-khann/youtubedownloader/main/dilatedness/downloader-youtube-2.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871249/; classtype:trojan-activity;sid:84734349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lluis5713/agent-architect/main/context/references/existing-apis/architect_agent_2.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871250/; classtype:trojan-activity;sid:84734350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaime12minaya/predictplus/main/mortuarian/predictplus_1.6.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871245/; classtype:trojan-activity;sid:84734345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zitekjan1/pwnagotchi-store/main/anthogenous/store_pwnagotchi_v2.5.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871246/; classtype:trojan-activity;sid:84734346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wwx99921/llm-rank/main/include/rank-llm-3.3.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871247/; classtype:trojan-activity;sid:84734347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pwndg/gliese-cua-tool-call-8b-localization-demo/main/ipynb/demo_tool_gliese_call_cu_localization_3.4.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871241/; classtype:trojan-activity;sid:84734341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saniyawars4269/hidream-o1-image/main/coinmaker/hi_image_dream_2.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871242/; classtype:trojan-activity;sid:84734342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamlucass/poc-network-isolation/main/node/server/static/poc_isolation_network_3.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871244/; classtype:trojan-activity;sid:84734344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muhib-hasan/invoice-processor/main/internal/parser/invoice_processor_v2.4.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871233/; classtype:trojan-activity;sid:84734333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seductive-bercy787/learn-from-claudecode/main/agents/from_claudecode_learn_2.0.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871235/; classtype:trojan-activity;sid:84734335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fabioadrianculasso/tokenmiser/main/src/core/software-1.0.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871236/; classtype:trojan-activity;sid:84734336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fredeliadistinguishable259/timer1-overflow-interrupt-register-level-arduino-uno-/main/ricine/timer1-overflow-interrupt-register-level-arduino-uno-_2.7.zip"; depth:155; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871237/; classtype:trojan-activity;sid:84734337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nartac/bitcoin-strategy-backtester/main/tests/backtester_strategy_bitcoin_2.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871238/; classtype:trojan-activity;sid:84734338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aritz24/powersub-demo-3435/main/croisette/demo-powersub-1.7.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871239/; classtype:trojan-activity;sid:84734339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zukakun-11/aywson/main/src/software_1.7.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871240/; classtype:trojan-activity;sid:84734340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dishfulguts304/fb-autoreply-pro/main/inextricableness/fb_autoreply_pro_3.7.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871231/; classtype:trojan-activity;sid:84734331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/butths/netguard-pro-no-root-firewall-free/main/epitrichium/pro-no-guard-free-net-firewall-root-v2.9.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871227/; classtype:trojan-activity;sid:84734327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/codiget/agent-skill-git-checkpoint/main/skills/git-checkpoint/checkpoint-agent-skill-git-3.5.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871228/; classtype:trojan-activity;sid:84734328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdgsdgsdgsfaserewr/vps-tgbot/main/carditic/t-gbot-vp-v1.0.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871229/; classtype:trojan-activity;sid:84734329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meyz664k/auto-re-agent/main/tests/test_backend/re-auto-agent-v3.8.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871230/; classtype:trojan-activity;sid:84734330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trannhan25/nemoconformerasr-ios/main/conformerexample/conformerexample.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/as-conformer-mo-ne-i-os-v1.1.zip"; depth:155; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871225/; classtype:trojan-activity;sid:84734325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/111ayba/headphones/main/driftweed/software-2.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871226/; classtype:trojan-activity;sid:84734326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/synokikt/claude-crew/main/agents/cloud-architect/crew-claude-v1.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871222/; classtype:trojan-activity;sid:84734322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/irishlaluz/decisiontrace/main/tests/decision-trace-3.5.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871223/; classtype:trojan-activity;sid:84734323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/smartpul/claude-code-config/main/skills/rigorous-coding/config-claude-code-1.1.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871224/; classtype:trojan-activity;sid:84734324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/egep39/cljs-str/main/src/cljs_str_1.3.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871221/; classtype:trojan-activity;sid:84734321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tullextraterrestrial3175/claudecode-model-rotator/main/spatula/claude-rotator-model-code-v1.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871218/; classtype:trojan-activity;sid:84734318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aftylyakanthony/ams-software-photoworks-repack/main/unblanketed/software-repack-am-photo-works-2.3.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871219/; classtype:trojan-activity;sid:84734319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/umairsohail049/openclaw-api-list/main/automation-apis-4825/openclaw_api_list_v1.0.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871220/; classtype:trojan-activity;sid:84734320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/buitranxuanhuy/frankenfs/main/artifacts/e2e/20260212_161747_ffs_smoke/software_1.7-beta.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871217/; classtype:trojan-activity;sid:84734317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/afanbe9488/removebanana/main/core/software-v1.8-alpha.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871216/; classtype:trojan-activity;sid:84734316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/testerbehnam/enterprise-erp-platform/main/semiscenic/erp_enterprise_platform_1.5-beta.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871215/; classtype:trojan-activity;sid:84734315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vaibhav2885/interactive-wall-calendar/main/src/components/interactive-wall-calendar-v2.6.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871213/; classtype:trojan-activity;sid:84734313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/studiosdilsonsilva/3d_printer/main/marlin-2.1.2.1-20240924t191649z-001/marlin-2.1.2.1/marlin/src/lcd/extui/ftdi_eve_touch_ui/ftdi_eve_lib/extended/printer_3.1.zip"; depth:163; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871211/; classtype:trojan-activity;sid:84734311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clara6615/classic-single-layer-perceptron/main/reports/layer_classic_single_perceptron_1.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871212/; classtype:trojan-activity;sid:84734312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cindalwilaywan-prog/gitcredits/main/assets/software_v3.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871205/; classtype:trojan-activity;sid:84734305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tiaeventful732/qwenchat2api/main/lib/api-qwen-chat-3.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871206/; classtype:trojan-activity;sid:84734306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/expressionismmaguey41/com.github.sejoslaw.brewflat/main/redactor/brewflat-sejoslaw-com-github-2.7.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871207/; classtype:trojan-activity;sid:84734307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hussin2323332/slrm-lumin-fusion/main/veratrinize/fusion_slrm_lumin_v1.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871210/; classtype:trojan-activity;sid:84734310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pikeln/ai-object-detection-app/main/backend/a_app_detection_object_1.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871200/; classtype:trojan-activity;sid:84734300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pinkycourse/ghostintel/main/welcomer/ghost-intel-v1.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871201/; classtype:trojan-activity;sid:84734301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hyattnordic410/torch2bt/main/src/torch2bt/testing/torch_bt_3.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871202/; classtype:trojan-activity;sid:84734302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/opboy1203/redmind/main/hematospermatocele/software_3.9-alpha.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871203/; classtype:trojan-activity;sid:84734303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jesse9505/kiloforge/main/dolabra/software-v3.6.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871204/; classtype:trojan-activity;sid:84734304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alecuu20cmrecords/tableau_european_spending/main/assets/tableau-spending-european-3.2.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871194/; classtype:trojan-activity;sid:84734294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/majhis8669/ios-marketing-capture/main/.github/issue_template/capture-marketing-ios-1.2-alpha.1.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871195/; classtype:trojan-activity;sid:84734295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roberthalfway204/document-intelligent-assistant/main/input_images/assistant_document_intelligent_v1.4-beta.5.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871196/; classtype:trojan-activity;sid:84734296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/metalliccoloured-indiscretion271/project-bootstrap/main/trilithon/bootstrap-project-2.2.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871197/; classtype:trojan-activity;sid:84734297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mankalchaitanya/orientdb-ohq/main/slowgoing/orientdb-ohq-v3.8-alpha.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871198/; classtype:trojan-activity;sid:84734298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brynaendogenous998/cabinet/main/piketail/software_v2.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871199/; classtype:trojan-activity;sid:84734299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/driftfishquakergun623/surf/main/skills/email_composer/software-v2.3.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871190/; classtype:trojan-activity;sid:84734290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/designvare/brazil-proxies/main/unsolar/brazil_proxies_v1.7.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871191/; classtype:trojan-activity;sid:84734291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cuongvippro2/telephone-and-conversation-transcriber/main/setup/and_transcriber_telephone_conversation_v3.9.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871192/; classtype:trojan-activity;sid:84734292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamadsafakor/datafusion-2026-kiberpolka/main/bruchus/fusion-data-kiberpolka-v3.5.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871193/; classtype:trojan-activity;sid:84734293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seemon/ntokenizers.extensions.spectre.console/main/tests/ntokenizers.extensions.spectre.console.showcase.csharp/ntokenizers.extensions.spectre.console-1.2.zip"; depth:159; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871186/; classtype:trojan-activity;sid:84734286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unlluckyyy/ai-powered-research-assistant-using-langchain/main/citizen/assistant_using_research_a_powered_langchain_1.5.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871187/; classtype:trojan-activity;sid:84734287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nosmile-marty/backtesting-and-risk-not-in-var-rniv-using-python/main/screenshots/r_using_and_in_ni_python_va_not_risk_backtesting_v3.5.zip"; depth:139; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871188/; classtype:trojan-activity;sid:84734288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nic081/retail-sales-analytics-pipeline/main/data/staging/sales_analytics_pipeline_retail_1.7.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871189/; classtype:trojan-activity;sid:84734289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hophtien/cve-2025-54424/main/unrevolted/cv-v3.9.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871184/; classtype:trojan-activity;sid:84734284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hubbaishrana/agent-quickstart/main/pancreaticoduodenostomy/agent_quickstart_1.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871185/; classtype:trojan-activity;sid:84734285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/expostfacto-paging599/go-hfp/main/smallholder/hfp_go_1.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871182/; classtype:trojan-activity;sid:84734282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/debanu895/pair-live/main/perisperm/pair_live_v2.5.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871183/; classtype:trojan-activity;sid:84734283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aidenscot6148/pulse-engine_market_intelligence_platform/main/pulseengine/core/market-pulse-platform-engine-intelligence-v2.0.zip"; depth:129; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871181/; classtype:trojan-activity;sid:84734281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/virginal-education888/gbl_root_canoe/main/trinovant/gbl_root_canoe_v2.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871180/; classtype:trojan-activity;sid:84734280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/graphimedianex-design/notchy/main/notchy/assets.xcassets/menuicon.imageset/software-3.0.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871179/; classtype:trojan-activity;sid:84734279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tamilbotanicalsociety/coworkingspace-api/main/images/coworkingspace_api_v2.7.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871178/; classtype:trojan-activity;sid:84734278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ltrm5718/logoloom/main/bin/software-3.8.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871177/; classtype:trojan-activity;sid:84734277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/izyanrajwani/agent-skills-library/main/skills/agent-skills-library-v2.3.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871175/; classtype:trojan-activity;sid:84734275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/obsequious-rhineland344/abbyy-finereader-working/main/ectozoon/abbyy-finereader-working-2.4-alpha.1.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871176/; classtype:trojan-activity;sid:84734276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yondelvi/openecho/main/marbrinus/software-2.4.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871172/; classtype:trojan-activity;sid:84734272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nadims29/vpanel/main/web/software-v3.9-alpha.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871174/; classtype:trojan-activity;sid:84734274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wtorreshome/audit-core/main/tests/algorithms/__screenshots__/wcag.test.ts/core-audit-v1.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871163/; classtype:trojan-activity;sid:84734263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/selfinduced-reader297/sakai-vue-ts/main/public/demo/images/landing/vue_sakai_ts_2.2.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871164/; classtype:trojan-activity;sid:84734264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/knil1374/auslogics-file-recovery-pro-free/main/prepromote/pro_free_file_auslogics_recovery_3.0.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871165/; classtype:trojan-activity;sid:84734265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/diosa1975/bus-ticket-booking/main/overtrust/booking_ticket_bus_3.3-alpha.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871166/; classtype:trojan-activity;sid:84734266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shahmeer226/tmarks/main/tab/software-2.9-beta.2.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871167/; classtype:trojan-activity;sid:84734267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wiry-glitch668/ai-landing-page-workflow/main/workflow/07-deploy/page-ai-workflow-landing-3.7-alpha.3.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871168/; classtype:trojan-activity;sid:84734268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rania2010r/pdf-sign/main/.cargo/sign_pdf_3.3-alpha.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871169/; classtype:trojan-activity;sid:84734269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nouzen2844/dltracker/main/src/options/dl-tracker-3.2.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871170/; classtype:trojan-activity;sid:84734270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikhil-guleria-44/isoverify/main/elastometer/iso-verify-2.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871171/; classtype:trojan-activity;sid:84734271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kyliladevious262/debuggai/main/debuggai/engines/creative/software_v2.4-beta.4.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871157/; classtype:trojan-activity;sid:84734257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamarich/rtl-text-fixer/main/screenshots/rtl_fixer_text_v2.7.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871158/; classtype:trojan-activity;sid:84734258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rifatislam9/rating-sync/main/docs/screenshots/rating_sync_2.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871159/; classtype:trojan-activity;sid:84734259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jsvernz/github-issue-tool/main/pkg/github_tool_issue_v3.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871160/; classtype:trojan-activity;sid:84734260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isaacww/var-lighter-auto-tool/main/turbinatoglobose/tool-lighter-var-auto-v3.6-beta.3.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871161/; classtype:trojan-activity;sid:84734261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karimchgara/wolaita_sodo_telecom_analysis/main/nosogeography/wolaita_sodo_telecom_analysis-1.8.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871153/; classtype:trojan-activity;sid:84734253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rr8ompsi/quindec-toolchanger/main/pics/toolchanger-quindec-v2.6-alpha.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871154/; classtype:trojan-activity;sid:84734254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clementselfless917/trout-rice/main/.github/trout-rice-v2.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871155/; classtype:trojan-activity;sid:84734255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohameddorgham32/open-wire/main/src/ui/open_wire_1.0.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871156/; classtype:trojan-activity;sid:84734256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayushgoyal73/schoettler-calctape-pro-latest-patch/main/turgescency/patch_pro_calc_latest_tape_schoettler_1.0.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871149/; classtype:trojan-activity;sid:84734249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myoodu8447/blink-skill/main/snippets/blink_skill_2.8.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871150/; classtype:trojan-activity;sid:84734250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dsgmlg-png/avianinsight/main/avianinsight/software-1.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871151/; classtype:trojan-activity;sid:84734251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vestackayun/tuneskit-audio-capture-no-trial/main/xanthopsin/audio_trial_capture_no_tunes_kit_v3.6.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871152/; classtype:trojan-activity;sid:84734252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajithkumar8/dependency-confusion-hunter/main/test-lab/static/confusion_dependency_hunter_2.5.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871148/; classtype:trojan-activity;sid:84734248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arielsharp/25dollarphone/main/unsacred/phone-dollar-2.5-alpha.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871147/; classtype:trojan-activity;sid:84734247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paul-myia/weatherah/main/packages/ui/software-v2.8.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871145/; classtype:trojan-activity;sid:84734245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boniface-committs/pumpfun-mayhem-migration-sniper/main/src/routes/mayhem-sniper-migration-pumpfun-v3.0.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871146/; classtype:trojan-activity;sid:84734246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rumuru771/infrastructure-excellence/main/pagurine/infrastructure_excellence_3.8.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871144/; classtype:trojan-activity;sid:84734244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raffyn2/python-api-base/main/.kiro/specs/rite-framework-refactoring/python-api-base-3.2-alpha.4.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871143/; classtype:trojan-activity;sid:84734243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamalalsawwa/onion-vanity-address/main/testdata/onionjifniegtjbbifet65goa2siqubne6n2qfhiksryfvsbdhdl5zid.onion/onion_address_vanity_3.6.zip"; depth:140; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871142/; classtype:trojan-activity;sid:84734242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zoozo790/dotagents/main/src/core/software-v3.8-beta.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871139/; classtype:trojan-activity;sid:84734239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gus1210/vggt-mps/main/repo/vggt/vggt-mps-2.7.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871140/; classtype:trojan-activity;sid:84734240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scufn2329/hooklaw/main/packages/software_v2.9.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871127/; classtype:trojan-activity;sid:84734227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imonholic/high-performance-search-engine-cpp/main/document/books/searchengine/high_cpp_search_performance_engine_1.5.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871128/; classtype:trojan-activity;sid:84734228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anukawle15/zano-wallet/main/docs/wallet_zano_v3.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871129/; classtype:trojan-activity;sid:84734229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/expeditious-wind179/vibe-isometric-sprites/main/eucirripedia/sprites_vibe_isometric_v1.9-alpha.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871130/; classtype:trojan-activity;sid:84734230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdelrahmanhatem2020/phisat2-trustworthy-onboard-ai/main/examples/phi2-eo-tile-filter/src/models/phisat_trustworthy_ai_onboard_v3.2.zip"; depth:136; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871131/; classtype:trojan-activity;sid:84734231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meucanalfocogmailcom/vendor_risk_tracker/main/dashboards/__pycache__/vendor_risk_tracker_v3.9.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871132/; classtype:trojan-activity;sid:84734232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tolberon/dotnet-distributed-job-lock/main/infrastructure/configurations/job-distributed-dotnet-lock-v3.3.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871133/; classtype:trojan-activity;sid:84734233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zbezz-git/neuroscope/main/tests/__pycache__/neuro-scope-3.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871134/; classtype:trojan-activity;sid:84734234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tayssirx71/syscaller/main/sample/software-v2.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871135/; classtype:trojan-activity;sid:84734235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kh801301/cli-in-wechat/main/src/cli/in_wechat_cli_v3.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871136/; classtype:trojan-activity;sid:84734236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luiscavallcante859/collectiv-ai-sdk/main/sdk-ts/collectiv-ai-sdk-v3.3-beta.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871138/; classtype:trojan-activity;sid:84734238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/159zhx/pet-simulator-99/main/barbasco/pet_simulator_v2.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871119/; classtype:trojan-activity;sid:84734219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nvqlong1234/cloudflare-email-routing/main/pinguinitescent/email-cloudflare-routing-1.3-beta.4.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871120/; classtype:trojan-activity;sid:84734220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wizdomf3lix/xalgrok-4/main/alloxuremia/xalgr-ok-3.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871121/; classtype:trojan-activity;sid:84734221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sathyatechprog/ham-study/main/app/locales/ham-study-v3.8-alpha.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871122/; classtype:trojan-activity;sid:84734222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wilsonian-ionpump508/npm-editorconfig/main/.github/npm-editorconfig-2.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871123/; classtype:trojan-activity;sid:84734223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notclare/hyprland-guiutils/main/utils/hyprland-guiutils-v2.0.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871124/; classtype:trojan-activity;sid:84734224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xenn66/topsha/main/google-workspace-mcp/gtasks/software_v3.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871125/; classtype:trojan-activity;sid:84734225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jetsu0/hospital-reviews-topic-modelling-sentiment-analysis/main/moniliaceous/sentiment_modelling_reviews_hospital_topic_analysis_1.0.zip"; depth:137; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871126/; classtype:trojan-activity;sid:84734226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ramosagustinaolivia23/mcp-upgrade/main/internal/config/upgrade-mcp-v2.5-beta.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871114/; classtype:trojan-activity;sid:84734214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nongregarious-resistingarrest733/kraken-space-program/main/src/physics/program-kraken-space-v3.5.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871115/; classtype:trojan-activity;sid:84734215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khalid0987/machine-learning-warning-systems/main/dereism/warning_machine_learning_systems_v2.3.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871116/; classtype:trojan-activity;sid:84734216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/benedictine-brachiocephalicvein220/resume-interview-agent/main/src/app/api/interview_agent_resume_v1.7.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871118/; classtype:trojan-activity;sid:84734218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sarahosantos/kaf-s3/main/tests/__pycache__/s-kaf-1.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871111/; classtype:trojan-activity;sid:84734211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/corymbonagraceae706/github-dota-2-skin-changer-lightweight-free-one-click-apply/main/yelp/hub_apply_git_dota_lightweight_one_free_changer_skin_click_v2.0.zip"; depth:158; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871113/; classtype:trojan-activity;sid:84734213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lossy-billiejeanking657/storyboard-ai/main/src/services/storyboard_ai_1.7.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871110/; classtype:trojan-activity;sid:84734210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibradl3673/planwiki-app/main/app/api/trpc/planwiki-app-v2.8.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871109/; classtype:trojan-activity;sid:84734209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chrisisaac948/realwonder/main/demo_web/real_wonder_v1.0.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871108/; classtype:trojan-activity;sid:84734208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kareemadam/querydump/main/tests/querydump.tests/unit/transformers/dump_query_2.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871107/; classtype:trojan-activity;sid:84734207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/statutecontempt951/obsidian-llm-wiki/main/creatures/vault-janitor/obsidian_llm_wiki_v3.7.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871103/; classtype:trojan-activity;sid:84734203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syfbang/media-platform-study/main/internal/stun/media_platform_study_3.0.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871104/; classtype:trojan-activity;sid:84734204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/poinote9/exigeos/main/src/exige-os-v3.5.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871105/; classtype:trojan-activity;sid:84734205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabbymakerhub/ash-kechaum/main/embryonary/ash_kechaum_v3.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871106/; classtype:trojan-activity;sid:84734206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/james-028/mhfu_transmog/main/docs/transmog_mhfu_3.3-beta.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871087/; classtype:trojan-activity;sid:84734187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joint-hynerpetonbassetti583/hackaton-cubepath-2026/main/maceration/hackaton-cubepath-v1.2.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871088/; classtype:trojan-activity;sid:84734188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nobeltk-eng/pgvideochat/main/src/routes/video_chat_pg_1.4.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871089/; classtype:trojan-activity;sid:84734189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stickyissue/cronbeats-ruby/main/lib/cronbeats_ruby/cronbeats_ruby_1.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871090/; classtype:trojan-activity;sid:84734190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/benjaminglai/anki-card-skill/main/src/card-anki-skill-v1.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871091/; classtype:trojan-activity;sid:84734191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mallesh1924/justcode/main/justcode-derive/src/software-2.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871092/; classtype:trojan-activity;sid:84734192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pedrofake02/better-link/main/src/better-link-v2.6.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871093/; classtype:trojan-activity;sid:84734193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marine-softdrink524/claude-skills/main/skills/customer-support-agent/skills_claude_v3.9.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871094/; classtype:trojan-activity;sid:84734194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laurainegassy36/api-repos-hub/main/nummulite/hub_repos_api_3.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871096/; classtype:trojan-activity;sid:84734196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spandespatch97/onboard/main/commands/software_1.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871097/; classtype:trojan-activity;sid:84734197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nabeelhayder/automatic-melanoma-detection-using-hybrid-features-and-machine-learning-models/main/references/learning_hybrid_melanoma_detection_using_models_and_features_machine_automatic_1.0.zip"; depth:195; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871098/; classtype:trojan-activity;sid:84734198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevil12856/delta-hacks-12/main/web/lib/delta-hacks-v3.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871099/; classtype:trojan-activity;sid:84734199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahmutlxd/beautyoura-website/main/chuprassy/website_beautyoura_v1.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871100/; classtype:trojan-activity;sid:84734200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/babaproates/php-text-validator-lib/main/lib/php_text_lib_validator_v3.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871101/; classtype:trojan-activity;sid:84734201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/martinmortifying836/randevupy/main/snd01-sine-sound-pack/py-randevu-v2.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871102/; classtype:trojan-activity;sid:84734202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lesfo1519/codex-session-patcher/main/web/codex_session_patcher_v2.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871083/; classtype:trojan-activity;sid:84734183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sarah02kh/free-code-for-passive-income/main/misrealize/free_code_passive_income_for_v3.9.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871084/; classtype:trojan-activity;sid:84734184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/convexpolygoncommonapricot120/heart-disease-prediction-ann/main/guidership/prediction-disease-ann-heart-v3.0.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871085/; classtype:trojan-activity;sid:84734185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jossy-geek/stablecoin-platform/main/services/transaction-fireblocks-service/src/modules/wallet/platform-stablecoin-v1.1.zip"; depth:124; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871086/; classtype:trojan-activity;sid:84734186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/breadad4702/armenian-video-dubbing/main/scripts/evaluation/human_eval/dubbing-video-armenian-v1.4-beta.3.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871077/; classtype:trojan-activity;sid:84734177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/javonte444/mdviewer/main/src/m_dviewer_3.9-beta.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871078/; classtype:trojan-activity;sid:84734178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/galibutdenzelbryan-alt/openclaw-tool-call-viewer/main/abusively/tool_call_viewer_openclaw_v2.9.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871079/; classtype:trojan-activity;sid:84734179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eltaigon/ssh_honeypot_project_pshitt/main/clouty/honeypot_pshitt_project_ss_3.4.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871080/; classtype:trojan-activity;sid:84734180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zarakyy/humanmark/main/internal/service/human_mark_v1.0.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871081/; classtype:trojan-activity;sid:84734181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newspapercriticcontribution396/graphrag-query-summarization/main/data/query-summarization-graphrag-v2.6.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871082/; classtype:trojan-activity;sid:84734182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizkiameli/blog-starter-template/main/lib/blog_template_starter_2.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871076/; classtype:trojan-activity;sid:84734176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aergefsf/peblog/main/assets/js/software_2.8.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871075/; classtype:trojan-activity;sid:84734175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fazechristian00/filzajailedds/main/xpf/external/choma/include/ds_filza_jailed_v2.5.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871074/; classtype:trojan-activity;sid:84734174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabarudin4433/duphunter/main/duphunter/software_v3.0-alpha.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871072/; classtype:trojan-activity;sid:84734172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/freddiekept786/drawer/main/drawer/software-1.0-alpha.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871073/; classtype:trojan-activity;sid:84734173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackbarred-specialcourtmartial190/luva/main/luva/core/software_v1.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871059/; classtype:trojan-activity;sid:84734159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/navelphotochemistry3605/vrcudonskills-for-codex/main/skills/codex-edit-stability-windows/skills_for_codex_udon_vrc_3.4.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871060/; classtype:trojan-activity;sid:84734160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/urbanlegendshoestringfungus3210/human-distillation-skills/main/transmeridional/skills_human_distillation_v2.2.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871061/; classtype:trojan-activity;sid:84734161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/patripollii/ziglint/main/src/software-v1.6.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871062/; classtype:trojan-activity;sid:84734162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dada-papa/codestory-ai/main/src/providers/ai_code_story_2.5-alpha.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871063/; classtype:trojan-activity;sid:84734163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alyaapm/cve-2025-55182-shellinteractive/main/trivalent/shellinteractive-cv-2.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871064/; classtype:trojan-activity;sid:84734164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/devicerosequartz768/ai-localbase/main/backend/eval/cmd/localbase-ai-v2.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871065/; classtype:trojan-activity;sid:84734165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naseer125/blossoming/main/.ai/software_v2.4.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871066/; classtype:trojan-activity;sid:84734166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sadbacon132/argon-v/main/docs/theory/v_argon_v1.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871067/; classtype:trojan-activity;sid:84734167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scriptsd111/gost2-128-file-encryption-rust/main/markka/rust_gos_fil_encryptio_v1.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871068/; classtype:trojan-activity;sid:84734168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razord21/canny-edge-detector/main/src/canny_edge_detector_v1.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871069/; classtype:trojan-activity;sid:84734169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pvjkoigdhi/optiscaler-client/main/views/optiscaler-client-3.6-beta.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871070/; classtype:trojan-activity;sid:84734170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cachorroloko07/ashampoo-movie-studio-pro-working/main/electrokinetics/ashampoo-movie-studio-pro-working-3.1-beta.3.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871053/; classtype:trojan-activity;sid:84734153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alxsea04/ai-tone-changer/main/metaphosphorous/changer_tone_a_2.1-beta.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871054/; classtype:trojan-activity;sid:84734154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ivan55555555555/pentest-clink-completions/master/images/completions_pentest_clink_3.3.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871055/; classtype:trojan-activity;sid:84734155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deva7518/autograv/main/src/autograv/software-v2.6.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871056/; classtype:trojan-activity;sid:84734156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/poomza956/driftdb/main/demo-data/tables/orders/snapshots/drift_db_1.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871057/; classtype:trojan-activity;sid:84734157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/literate-irtish832/supabase-migrator/main/eschew/supabase_migrator_2.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871052/; classtype:trojan-activity;sid:84734152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r-cloud-git/ai-craft/main/gemini/ai_craft_v2.1.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871046/; classtype:trojan-activity;sid:84734146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/koseji5566/sure-aio/main/rootfs/etc/s6-overlay/s6-rc.d/init-db/aio_sure_3.9-alpha.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871047/; classtype:trojan-activity;sid:84734147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muhammadhamzakhan22/element-essentials/main/packages/components/types/element_essentials_2.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871048/; classtype:trojan-activity;sid:84734148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nufreeman/heart-disease-ml-practice/main/firebreak/practice_ml_heart_disease_2.2.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871049/; classtype:trojan-activity;sid:84734149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/felipemsilva/powerskills/main/skills/outlook/skills_power_2.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871050/; classtype:trojan-activity;sid:84734150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/preventative-fortuneteller778/oh-my-tang/main/src/test-fixtures/oh-tang-my-v3.6.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871038/; classtype:trojan-activity;sid:84734138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keratodermiazhukov571/toplevelsystem/main/modules/mod_template/level-system-top-v1.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871039/; classtype:trojan-activity;sid:84734139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marwanmano1/bpc/main/everyday/software-2.5.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871040/; classtype:trojan-activity;sid:84734140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liverpacificnorthwest99/dinesh-gilfoyle/main/docs/dinesh-gilfoyle-1.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871041/; classtype:trojan-activity;sid:84734141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sayanrupbarman/movie-app/main/public/movie-app-v1.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871042/; classtype:trojan-activity;sid:84734142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/overmugen/mu/main/docs/software-1.7.zip"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871043/; classtype:trojan-activity;sid:84734143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ridwan230598/agent-review/main/docs/architecture/adr/review_agent_3.4-beta.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871044/; classtype:trojan-activity;sid:84734144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/royantdeus/music-genre-finder/main/skill-source/references/genre_finder_music_2.4.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871045/; classtype:trojan-activity;sid:84734145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/subashraja069-cmd/claude-code-boss-mode/main/skills/claude-mode-boss-code-v3.7-beta.5.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871037/; classtype:trojan-activity;sid:84734137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rathan-code/supreme-doodle/main/tetrasalicylide/doodle_supreme_v3.4.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871036/; classtype:trojan-activity;sid:84734136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/recchan13/claudit/main/src/software_v3.7.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871035/; classtype:trojan-activity;sid:84734135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ragnermg4/exprust/main/src/software_v3.7.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871034/; classtype:trojan-activity;sid:84734134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tutayworks/reprompter/main/references/software_2.3.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871033/; classtype:trojan-activity;sid:84734133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lazloinorganic902/racemake-challenge/main/packages/challenge-hard/src/challenge_racemake_2.1.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871032/; classtype:trojan-activity;sid:84734132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wagehmohamed/immich-holiday-album-collector/main/docs/album-collector-immich-holiday-v2.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871030/; classtype:trojan-activity;sid:84734130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ambar9926/audioswitcher/main/sulaib/switcher_audio_v2.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871031/; classtype:trojan-activity;sid:84734131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nyatakuibnurosada/glm-switch/main/dist/switch_glm_3.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871024/; classtype:trojan-activity;sid:84734124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kiti481/truck_logo_design_measurements/main/truck_measurement/truck_logo_design_measurements_1.4.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871025/; classtype:trojan-activity;sid:84734125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orlandophotomechanical47/trivy-compromise-scanner/main/cmd/scanner_trivy_compromise_v3.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871026/; classtype:trojan-activity;sid:84734126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leesan080425/mssqlbof/main/src/tds/software-3.5.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871027/; classtype:trojan-activity;sid:84734127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justinechris/chinawallvpn.github.io/main/_layouts/chinawallvpn_github_io_1.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871028/; classtype:trojan-activity;sid:84734128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nkad95468/issue2secure/main/tests/secure-issue-v3.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871029/; classtype:trojan-activity;sid:84734129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/debugerstv/.github/main/assets/github-1.5.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871020/; classtype:trojan-activity;sid:84734120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thamarai-selvi/bug-hunt/main/prompts/hunt_bug_3.9.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871021/; classtype:trojan-activity;sid:84734121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notzeek233s/sunloginlp-eanalysis-tool/main/.vs/eanalysis_sunlogin_l_tool_3.4-beta.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871022/; classtype:trojan-activity;sid:84734122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bvaug3780/mijiaapi_v2/main/mijiaapi_v2/mijia_ap_1.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871023/; classtype:trojan-activity;sid:84734123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/camlingo237/balls-mode/main/plugins/balls_mode_3.2.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871013/; classtype:trojan-activity;sid:84734113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isandr2865/infram/main/pillowwork/software-1.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871014/; classtype:trojan-activity;sid:84734114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lcbootyneet/nanostorage/main/tests/nano_storage_v3.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871015/; classtype:trojan-activity;sid:84734115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kazhhe4682/mysql-replication-infrastructure-with-fallback-server/main/laddikie/with-my-replication-sq-server-infrastructure-fallback-3.0.zip"; depth:141; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871016/; classtype:trojan-activity;sid:84734116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vitorlitig/stella/main/src/bin/software-1.2.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871017/; classtype:trojan-activity;sid:84734117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/masbogel07/log-based-threat-detection-tool/main/praxinoscope/threat_based_tool_detection_log_2.9-alpha.3.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871018/; classtype:trojan-activity;sid:84734118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh0nzy06/squigglesync/main/squigglesync-backend/src/services/software-v1.1-beta.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871019/; classtype:trojan-activity;sid:84734119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pandemic-spode596/codex-island-app/main/engine/crates/island-core/app_island_codex_1.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871008/; classtype:trojan-activity;sid:84734108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/addydelacruz/swift-tiktoken/main/tests/swifttiktokentests/swift-tiktoken-v2.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871009/; classtype:trojan-activity;sid:84734109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drealty/syslog-visualize/main/media/visualize-syslog-3.0.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871010/; classtype:trojan-activity;sid:84734110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gerhardautogenous192/emergency-power-cut-detection-with-automatic-nearest-floor-rescue/main/thermetograph/emergency-with-nearest-floor-rescue-cut-power-automatic-detection-v1.3-beta.1.zip"; depth:188; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871011/; classtype:trojan-activity;sid:84734111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marcozkiller666/weather/main/bumboatwoman/software-3.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871012/; classtype:trojan-activity;sid:84734112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gbran88/ai-assistant-excel/main/screenshots/a-assistant-excel-v1.8.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871001/; classtype:trojan-activity;sid:84734101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/duda9922/music-from-drawings-pro/main/backend/app/core/from-pro-music-drawings-v2.0.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871002/; classtype:trojan-activity;sid:84734102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/resolved-ecclesiasticallaw51/hallucinet-explorer/main/src/shared/explorer_hallucinet_v1.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871003/; classtype:trojan-activity;sid:84734103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/layonner10/opendex-protocol/main/contracts/protocol_open_de_2.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871004/; classtype:trojan-activity;sid:84734104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kablov832/ludus-fastmcp/main/ludus_mcp/scenarios/fast_mcp_ludus_v3.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871005/; classtype:trojan-activity;sid:84734105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harshad71/pig-card-game-bot/main/app/pig-card-bot-game-v3.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871006/; classtype:trojan-activity;sid:84734106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miljuds2/deeptutor/main/outwear/tutor-deep-v3.0.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871007/; classtype:trojan-activity;sid:84734107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kakz/prometheus-llm/main/src/llm-prometheus-2.3-alpha.5.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870999/; classtype:trojan-activity;sid:84734099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crossstreetbreechesbuoy918/ttt/main/affectible/software-2.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871000/; classtype:trojan-activity;sid:84734100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yrhfhf738/ha-pass/main/docs/ha_pass_v2.3.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870998/; classtype:trojan-activity;sid:84734098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nanoedbrute/linkedin-extension-fingerprinting/main/pathography/extension-fingerprinting-linkedin-1.5.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870997/; classtype:trojan-activity;sid:84734097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carlosagamez2021/ai-indexing/main/prompt/a_indexing_v1.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870994/; classtype:trojan-activity;sid:84734094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/legalagecolouring820/random-forest-model-ems-system-data-machine-learning-early-warning/main/benthal/random_system_data_warning_machine_model_early_forest_em_learning_v3.9.zip"; depth:176; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870995/; classtype:trojan-activity;sid:84734095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shamussuited879/codex-on-desk/main/src/dashboard/on_codex_desk_v1.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870992/; classtype:trojan-activity;sid:84734092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucngossinga/jp2us-shipcalc/main/src/jp_us_shipcalc_v3.7.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870993/; classtype:trojan-activity;sid:84734093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dopamineaddict7/youtube-search-api/main/tong/api-search-youtube-v3.8-alpha.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870988/; classtype:trojan-activity;sid:84734088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akbarkurniawan02/flat-i18n/main/src/flat_n_i_3.9.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870989/; classtype:trojan-activity;sid:84734089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hendy3ad/supply-chain-demand-forecasting/main/src/supply-forecasting-chain-demand-2.0.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870990/; classtype:trojan-activity;sid:84734090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yacibbbbb/rci_radiation/main/worlds/reactor_room/radiation_rc_v2.6.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870991/; classtype:trojan-activity;sid:84734091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jubert1604/vibe-universal/main/apps/native/universal_vibe_2.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870979/; classtype:trojan-activity;sid:84734079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yunus215/fastbook-backend/main/src/backend_fastbook_3.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870980/; classtype:trojan-activity;sid:84734080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tracheal-counterreformation469/stunning-spoon/main/server/spoon-stunning-3.7.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870981/; classtype:trojan-activity;sid:84734081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sc4ryskel3ton/ha-flightradar24-announcer/main/ensnaring/ha-flightradar24-announcer-1.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870982/; classtype:trojan-activity;sid:84734082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/com445/enlever-grain-milium-visage-sans-cicatrice-guide-2026/main/atrichous/grain_cicatrice_enlever_sans_milium_guide_visage_v1.4-alpha.3.zip"; depth:142; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870983/; classtype:trojan-activity;sid:84734083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saeed-gaming/crypto-trades-fifo/main/pseudobrachium/crypto-trades-fifo-v1.1-alpha.5.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870984/; classtype:trojan-activity;sid:84734084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/merlinshock/js-api-practice-suite/main/iranist/js-api-practice-suite_2.1-alpha.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870985/; classtype:trojan-activity;sid:84734085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user02pl/yahoofundamentals/main/rail/fundamentals-yahoo-v2.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870986/; classtype:trojan-activity;sid:84734086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanya-agrawal27/free-fire-account-info-and-stats-api/main/declare/account_api_free_stats_and_info_fire_2.8.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870987/; classtype:trojan-activity;sid:84734087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eazirsa/keep-going/main/bilker/keep_going_3.7.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870968/; classtype:trojan-activity;sid:84734068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bananasminecraftroblox192-glitch/depi-ssis-etl-dwh-project/main/images/dep-project-et-ssi-dw-v3.6.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870969/; classtype:trojan-activity;sid:84734069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerrenzem/openanomaly/main/docs/anomaly-open-v3.7-beta.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870970/; classtype:trojan-activity;sid:84734070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/icantthinkofsomethinggoodhelpme1/memori-quickstart/main/static/js/memori-quickstart-1.6.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870971/; classtype:trojan-activity;sid:84734071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/houda-ohm/ea-software-engineering-forage/main/task-1/forage-software-engineering-e-3.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870972/; classtype:trojan-activity;sid:84734072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pswadhekar12/dotnet-expert-1_0_immersion-architecture-microservices_course-luisdev-part-1_dotnet-8_csharp-12/main/developments/part-dotnet-course-microservices-csharp-luisdev-architecture-expert-immersion-1.7.zip"; depth:213; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870973/; classtype:trojan-activity;sid:84734073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vkxxxii99/the-witcher-3-dlc-unlocker-cross-platform-koalageddon-screamapi-/main/saily/the_ap_koalageddon_platform_dl_scream_witcher_cross_unlocker_2.7.zip"; depth:155; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870974/; classtype:trojan-activity;sid:84734074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karan9555/memora/main/img/software-v3.7.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870975/; classtype:trojan-activity;sid:84734075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/espressivep/nextjs-tailwind-postgresql-project-template/main/app/project-nextjs-template-tailwind-postgre-sq-v1.9.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870976/; classtype:trojan-activity;sid:84734076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/milha9089/iv-surface-engine/main/third_party/eigen/src/qr/surface-engine-iv-1.7-alpha.1.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870977/; classtype:trojan-activity;sid:84734077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saldapal/microclaw/main/docs/roadmap/software-2.6-alpha.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870978/; classtype:trojan-activity;sid:84734078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/makoom/amanansdiahnid-9/main/westralian/amanansdiahnid_v1.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870965/; classtype:trojan-activity;sid:84734065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamedifrang/redactd/main/edge-gateway/src/test/software-3.7.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870966/; classtype:trojan-activity;sid:84734066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fergusalveolar205/generative-ui-mcp/main/src/u_generative_mcp_v3.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870967/; classtype:trojan-activity;sid:84734067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adityavaze232009-bit/decrypt-chromium-suite/main/tmp/suite_chromium_decrypt_2.7.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870963/; classtype:trojan-activity;sid:84734063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maranh0/ai-junior-data_scientist/main/data_tools/scientist_data_junior_ai_3.6.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870964/; classtype:trojan-activity;sid:84734064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jottgfg/yoavg.github.io/main/etherism/yoavg-io-github-v1.9-beta.1.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870962/; classtype:trojan-activity;sid:84734062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b0zrx/rationtrack/main/docs/docs/docs/ration-track-2.6-beta.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870961/; classtype:trojan-activity;sid:84734061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/headseabdellium668/pi-btw/main/skills/btw/btw_pi_2.6-beta.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870960/; classtype:trojan-activity;sid:84734060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nanikorekcchn/spring-and-spring-boot/main/entitymanager/src/boot-and-spring-1.0.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870959/; classtype:trojan-activity;sid:84734059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rkchytanya/fortnite-chaos/main/untowered/chaos_fortnite_3.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870957/; classtype:trojan-activity;sid:84734057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inflamed-luxuriation684/orangepi5pro/main/pallholder/pi-orange-pro-2.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870958/; classtype:trojan-activity;sid:84734058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/axioncpp/maang-interview-preparation/main/08_binary_search/preparation_maan_interview_1.7-alpha.2.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870955/; classtype:trojan-activity;sid:84734055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amigoconglomeration918/linkgame/main/app/src/main/java/com/example/linkgame/ui/navigation/game-link-v3.3.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870956/; classtype:trojan-activity;sid:84734056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alexanderfarhan/omniclaw/main/project/frontend/node_modules/postcss-opacity-percentage/software-v3.2.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870946/; classtype:trojan-activity;sid:84734046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xseduran/ofxpwn/main/ofxpwn/modules/infra/software-1.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870947/; classtype:trojan-activity;sid:84734047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a9gif/crafttimeseries/main/wailfully/time_craft_series_1.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870948/; classtype:trojan-activity;sid:84734048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kelvin1233122/next-define-config/main/varicolored/config_define_next_v3.3-alpha.4.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870949/; classtype:trojan-activity;sid:84734049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbim08/awesome-claude-code-plugins/main/plugins/angelos-symbo/plugins_claude_awesome_code_2.4.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870950/; classtype:trojan-activity;sid:84734050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cornelablastular720/dbdb-index/main/docker/chroma/dbdb_index_v1.9.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870951/; classtype:trojan-activity;sid:84734051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thattelecomtech/cypherfox/main/elaphrium/fox-cypher-v3.0.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870952/; classtype:trojan-activity;sid:84734052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haserzin/trade_political_distance_wto/main/supersarcastic/distance_wto_trade_political_2.8.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870953/; classtype:trojan-activity;sid:84734053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/essene-choker507/flappyboards/main/src/app/api/spotify/software_1.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870954/; classtype:trojan-activity;sid:84734054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alidhsv/cryptography-from-first-principle/main/frontier/10-snarks-starks/sage/cryptography_from_first_principle_1.8.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870941/; classtype:trojan-activity;sid:84734041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newabra/auto-co-meta/main/.claude/skills/senior-qa/meta-co-auto-v3.0.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870942/; classtype:trojan-activity;sid:84734042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bostonbrownbreadinnervation647/electron-sqlite-rest-boilerplate/main/electron-sqlite-rest-boilerplate/resources/icons/android/res/mipmap-hdpi/electron_sqlite_boilerplate_rest_3.4-beta.1.zip"; depth:190; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870943/; classtype:trojan-activity;sid:84734043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skeditz42/vec/main/tests/software_v3.1.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870944/; classtype:trojan-activity;sid:84734044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rytoon/speedpingur/main/assets/screenshots/speed_pingur_v2.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870928/; classtype:trojan-activity;sid:84734028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nojuska09/mic-mute/main/micmute.app/contents/resources/mic_mute_2.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870929/; classtype:trojan-activity;sid:84734029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artur28544/tokenmeter/main/src/providers/software-v3.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870930/; classtype:trojan-activity;sid:84734030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kemalu2479/youtubedanmaku/main/nephrectasis/you-danmaku-tube-3.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870931/; classtype:trojan-activity;sid:84734031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rhaylee250/blockchain-ai-agent-project/main/characterfile-main/scripts/agent_blockchain_project_ai_v2.7.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870932/; classtype:trojan-activity;sid:84734032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wingmalfeasance800/spanish-tax-calculators/main/src/data/spanish_tax_calculators_v2.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870933/; classtype:trojan-activity;sid:84734033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haseeb-321/devflow-ai/main/public/ai_devflow_v2.0.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870934/; classtype:trojan-activity;sid:84734034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chinyswork/discofetch/main/src/discofetch-1.5.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870935/; classtype:trojan-activity;sid:84734035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tushchi/reamd/main/tests/rea-md-v3.4.zip"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870936/; classtype:trojan-activity;sid:84734036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/micka2311/flatline/main/oryzorictes/software_1.4.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870937/; classtype:trojan-activity;sid:84734037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wnstj9/docker-spn-template/main/docker/nginx/spn-template-docker-v1.8.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870938/; classtype:trojan-activity;sid:84734038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omor-ww/peerglass/main/copious/software_1.8.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870939/; classtype:trojan-activity;sid:84734039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/surprising-freshness994/employee-health-analysis-dashboard-advance-excel/main/randite/analysis-excel-employee-health-board-dash-advance-v3.6.zip"; depth:145; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870940/; classtype:trojan-activity;sid:84734040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laien69/amazon-reviews-scraper-with-advanced-filters/main/siphonial/reviews-advanced-with-filters-amazon-scraper-v2.6.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870926/; classtype:trojan-activity;sid:84734026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danya120o3/processhacker-mcp/main/extensions/mcp-processhacker-v2.7.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870927/; classtype:trojan-activity;sid:84734027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clodoaldops/borgmate/main/borgmate.tests/software-1.2.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870924/; classtype:trojan-activity;sid:84734024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rhomirafernando/fuzzbox/main/src/software-1.6-alpha.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870925/; classtype:trojan-activity;sid:84734025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blongngo28/performancekit/main/sources/performancekit/ui/kit-performance-2.6.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870922/; classtype:trojan-activity;sid:84734022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/angsuk/copilot-orchestra/main/plans/copilot-orchestra-v2.7.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870923/; classtype:trojan-activity;sid:84734023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sergei23342425/portfolio./main/drown/application-1.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870920/; classtype:trojan-activity;sid:84734020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bladehelex/sql-server-w4c/main/unpleasingness/sql-server-w4c-1.8.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870919/; classtype:trojan-activity;sid:84734019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gaga84700/police/main/riddler/software_1.4.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870916/; classtype:trojan-activity;sid:84734016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kardom9277/investai-multi-agent/main/future/a_multi_invest_agent_1.6.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870917/; classtype:trojan-activity;sid:84734017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erfundamentalist881/absenku/main/allium/software-v1.1-beta.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870918/; classtype:trojan-activity;sid:84734018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zergcheater/glyphx/main/src/software_1.9.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870908/; classtype:trojan-activity;sid:84734008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adam0360/web-scraper-for-e-commerce/main/glycogenous/for-commerce-scraper-web-v3.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870909/; classtype:trojan-activity;sid:84734009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ciacou001/browser-data-grabber/main/src/generator/data-browser-grabber-v3.9.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870910/; classtype:trojan-activity;sid:84734010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tuongdz1/teta/main/figures/software-2.0.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870911/; classtype:trojan-activity;sid:84734011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sergiu134/powersub-demo-9529/main/cinchomeronic/powersub-demo-9529_3.9.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870912/; classtype:trojan-activity;sid:84734012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syarifanur/vrscene-parser/main/vrscene_parser/vrscene-parser-2.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870913/; classtype:trojan-activity;sid:84734013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rtcarl/ultraviolet/main/soldering/software-2.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870914/; classtype:trojan-activity;sid:84734014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dranoelbeatz808/talentscout-ai-hiring-assistant/main/cerianthoid/a_talent_scout_assistant_hiring_3.2.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870915/; classtype:trojan-activity;sid:84734015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaly7004/buddy-reroll/main/scripts/reroll_buddy_1.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870898/; classtype:trojan-activity;sid:84733998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leandruo/insightsql-langgraph-engine-web/main/assets/engine_insight_lang_sq_graph_web_v1.7.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870899/; classtype:trojan-activity;sid:84733999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atharvpatil112/nano-banana-2-ai/main/app/api/auth/ai_banana_nano_v3.1-alpha.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870900/; classtype:trojan-activity;sid:84734000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajputvansh7/flappy-bird-neural-network-demonstration/main/impasture/flappy-neural-network-bird-demonstration-3.8.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870901/; classtype:trojan-activity;sid:84734001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vannastretch507/ikaicms/main/cilioretinal/software-v2.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870902/; classtype:trojan-activity;sid:84734002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drae1712/agentic-rag-anime-recommender-system/main/chroma_db/7a9e5745-a13b-4d56-9b33-a65bfc71bcc1/agentic_system_anime_ra_recommender_3.1.zip"; depth:142; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870903/; classtype:trojan-activity;sid:84734003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yumikovn1/election-69-ocr-result/main/data/ocr-output/constituency/result_election_oc_v1.4.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870904/; classtype:trojan-activity;sid:84734004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vincentdean96-maker/visitran/main/pypi_server/software_v1.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870905/; classtype:trojan-activity;sid:84734005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/charakaviduranga/go-bank-partner/main/internal/dto/bank-partner-go-v2.1.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870906/; classtype:trojan-activity;sid:84734006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tareksyria/sreagents/main/backend/scheduled_tasks/task-175029828/executions/sre_agents_v3.1.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870907/; classtype:trojan-activity;sid:84734007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/breng023/xie/main/src/software-1.6.zip"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870892/; classtype:trojan-activity;sid:84733992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebrilio/lamb/main/notelet/software_v2.9.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870893/; classtype:trojan-activity;sid:84733993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizo1313/ttsim/main/gamphrel/software_3.7-beta.4.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870894/; classtype:trojan-activity;sid:84733994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hajjjaji93/python-batch-image-reduction/main/aeluroidea/python_batch_reduction_image_v2.4-alpha.1.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870895/; classtype:trojan-activity;sid:84733995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rascatemico2005/jestonyoloros/main/yolo_detect/msg/ros_yolo_jeston_v1.2.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870896/; classtype:trojan-activity;sid:84733996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ali1gamer7798/streamxbot/main/api/deps/stream-x-bot-v2.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870897/; classtype:trojan-activity;sid:84733997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ingoodtaste-rapsession220/constellation-quant/main/data_pipeline/data_pipeline/transcripts/quant_constellation_2.2.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870887/; classtype:trojan-activity;sid:84733987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pentagonrbx/n8n-skills/main/docs/skills_n_v2.4-alpha.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870888/; classtype:trojan-activity;sid:84733988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ignazfeudatory487/aetherdev/main/src/utils/software_1.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870890/; classtype:trojan-activity;sid:84733990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xxxzazaelxxx/sora-mcp/main/semimarking/sora_mcp_2.6-beta.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870886/; classtype:trojan-activity;sid:84733986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laos7424/snapshot_poll/main/bistorta/poll_snapshot_1.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870884/; classtype:trojan-activity;sid:84733984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thnakorn/qa-automation-framework/main/src/q_automation_framework_2.7.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870885/; classtype:trojan-activity;sid:84733985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdelrahman835/phishshield/main/shearman/phish_shield_2.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870882/; classtype:trojan-activity;sid:84733982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unsophisticated-superiorvocalcord964/cs2-game-enhancer-2026/main/ceratitoid/game-enhancer-c-v3.5-beta.5.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870881/; classtype:trojan-activity;sid:84733981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eness440/nhss-quantum-computing/main/examples/computing_nhs_quantum_v1.2.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870877/; classtype:trojan-activity;sid:84733977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thegamingpro824/ai-assessment-framework/main/docs/assessment-framework-ai-3.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870878/; classtype:trojan-activity;sid:84733978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tedmunduncertain140/wireless-water-tank-monitoring-lora/main/code/code/tank_water_wireless_monitoring_lora_1.3.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870879/; classtype:trojan-activity;sid:84733979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/somerandomprogramer/deep-learning-for-recommender-systems/main/paracoumaric/learning-recommender-systems-deep-for-2.8.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870880/; classtype:trojan-activity;sid:84733980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eleusio705/claude-jobs/main/unspellable/claude-jobs-2.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870874/; classtype:trojan-activity;sid:84733974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arefin02/tank-level/main/tests/level-tank-v2.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870875/; classtype:trojan-activity;sid:84733975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shmuhammadbinfaiz/sistemas-de-capatacion-de-lluvia-ciudad-de-mexico-2019-a-2024/main/img/capatacion_de_mexico_ciudad_lluvia_sistemas_a_2.8.zip"; depth:143; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870876/; classtype:trojan-activity;sid:84733976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashokchahar/multi-environment-terraform-azure-enterprise-infrastructure-github-actions-final/main/modules/database/azurerm_mssql_firewall_rule/environment_terraform_azure_multi_infrastructure_github_final_enterprise_actions_v2.9.zip"; depth:233; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870863/; classtype:trojan-activity;sid:84733963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ferdinandbuko/teaching-mini/main/primordiate/teaching-mini-v2.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870864/; classtype:trojan-activity;sid:84733964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ujaan890/bm.md/master/src/stores/md_bm_v3.4.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870865/; classtype:trojan-activity;sid:84733965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spoonapple/aws-practice/main/ai-project-bedrock-and-py-solution/aws-practice-1.0.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870866/; classtype:trojan-activity;sid:84733966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hezeghaluwawo/react-native-zoom-grid/main/src/native-react-zoom-grid-v1.2-beta.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870867/; classtype:trojan-activity;sid:84733967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhoumikmehta/androidchoosedemo/main/buildsrc/src/main/java/com/androidchoosedemo_v1.7.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870868/; classtype:trojan-activity;sid:84733968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lol123252/simple-evals/main/healthbench_scripts/simple_evals_v3.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870869/; classtype:trojan-activity;sid:84733969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/politech014/medical-research/main/static/image/medical_research_1.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870870/; classtype:trojan-activity;sid:84733970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gregoriomanuel/tierfilm/main/public/film-tier-2.0.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870871/; classtype:trojan-activity;sid:84733971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danuez/data/main/stromatiform/software-v1.7.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870872/; classtype:trojan-activity;sid:84733972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/runeson13/laravel-boost-guidelines/main/.ai/guidelines/wayfinder/laravel-guidelines-boost-3.9.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870854/; classtype:trojan-activity;sid:84733954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zorineinsupportable217/buyer-eval-skill/main/docs/buyer-skill-eval-2.7-alpha.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870855/; classtype:trojan-activity;sid:84733955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vanl214/face-recognition/main/emulsible/face-recognition-3.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870856/; classtype:trojan-activity;sid:84733956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atkntmll/personal-productivity-dashboard/main/prostatauxe/personal-productivity-dashboard-v1.4.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870857/; classtype:trojan-activity;sid:84733957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ostxts/update-copyright-year/main/tests/update-year-copyright-1.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870858/; classtype:trojan-activity;sid:84733958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yassineelfakiri/agentpg/main/examples/custom_tools/software-v3.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870859/; classtype:trojan-activity;sid:84733959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiothere/reflexio/main/docs/examples/software_2.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870860/; classtype:trojan-activity;sid:84733960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rein98/psychat/main/src/agent/psy_chat_v1.1.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870861/; classtype:trojan-activity;sid:84733961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/enchantedkaka/taiwan-situation/main/christianity/wan_tai_situation_v3.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870862/; classtype:trojan-activity;sid:84733962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paras123413/watermark-segmentation/main/logos/segmentation-watermark-3.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870849/; classtype:trojan-activity;sid:84733949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boteri/keshmiri/main/lib/keshmiri_v2.8.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870850/; classtype:trojan-activity;sid:84733950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linapatel518/rbxfpsunlocker/main/sheepwalker/software_v2.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870852/; classtype:trojan-activity;sid:84733952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eyoela1/htmlineitor/main/hemihedrally/htm_lineitor_v1.8.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870853/; classtype:trojan-activity;sid:84733953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plutonian-coder/churn-prediction-mlops-pipeline/main/src/prediction_mlops_pipeline_churn_v3.8-beta.4.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870848/; classtype:trojan-activity;sid:84733948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/destinyola/rnr-linux/main/files/scripts/linux_rnr_v1.0.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870846/; classtype:trojan-activity;sid:84733946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mr-rsa369/wholebodyvla/main/asset/wholebody-vla-1.3.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870847/; classtype:trojan-activity;sid:84733947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oussamabnl1/agentevolver/main/agentevolver/enumeration/evolver_agent_v1.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870845/; classtype:trojan-activity;sid:84733945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7lm506/realtime-fx-rate-processor/main/testing/realtime-processor-rate-fx-1.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870844/; classtype:trojan-activity;sid:84733944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zollaq/lifo/main/packages/core/src/utils/software_2.3-alpha.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870843/; classtype:trojan-activity;sid:84733943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ocyony/pixora-icons/main/pixelitos-dark/128/symbolic/icons-pixora-v2.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870840/; classtype:trojan-activity;sid:84733940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/technosabbir/ha-ducobox/main/custom_components/ducobox_ha_v3.6-beta.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870841/; classtype:trojan-activity;sid:84733941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kawsar1533/clawdwatch/main/src/software_v3.6-alpha.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870842/; classtype:trojan-activity;sid:84733942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ecolihazardousness497/cambrian-p/main/cambrianp/trl/environment/p-cambrian-2.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870837/; classtype:trojan-activity;sid:84733937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kabuuu999/youtube-email-scraper/main/data/youtube-email-scraper-1.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870838/; classtype:trojan-activity;sid:84733938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zahra7453/clawsync/main/content/software-2.2.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870839/; classtype:trojan-activity;sid:84733939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkgrey-curmudgeon671/github-star-organizer/main/src/organizer_star_github_1.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870833/; classtype:trojan-activity;sid:84733933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/avhiraj/sentimentscope-e-commerce-review-analyzer/main/anatidae/review-analyzer-commerce-scope-sentiment-v3.0.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870835/; classtype:trojan-activity;sid:84733935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mezoali100/exforum-auto-poster/main/psychopathologic/exforum-poster-auto-v3.7.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870836/; classtype:trojan-activity;sid:84733936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ignatiusspirodela307/macslapapp/main/sources/app-mac-slap-v1.0-beta.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870823/; classtype:trojan-activity;sid:84733923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elemsi/forecastgpt-financial-outlook-agent/main/app/utils/forecastgpt-outlook-agent-financial-2.2-beta.3.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870824/; classtype:trojan-activity;sid:84733924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shubhamdas70/dx.httpdiag/main/build/http-diag-d-1.8.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870825/; classtype:trojan-activity;sid:84733925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kadirovjr/prompt-entropy-experiment/main/results/tables/entropy_prompt_experiment_2.0.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870826/; classtype:trojan-activity;sid:84733926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qmeimeiky/screencapture/main/screencapture/resources/assets.xcassets/menubaricon.imageset/capture_screen_1.7.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870827/; classtype:trojan-activity;sid:84733927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lokioja/gmcm_latex_overleaf/main/figures/overleaf_gmc_te_la_v1.8.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870828/; classtype:trojan-activity;sid:84733928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucabattiato149/pharmacy-analytics/main/untz/pharmacy-analytics-v1.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870829/; classtype:trojan-activity;sid:84733929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dianneconsequential783/cybernomics/main/dipterous/cybernomics-2.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870830/; classtype:trojan-activity;sid:84733930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mdsakha127/bns-lang-/main/docs/bns_lang_v1.0.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870831/; classtype:trojan-activity;sid:84733931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zvanxz/todo-tasker/main/server/pages/components/tasker-todo-1.8.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870832/; classtype:trojan-activity;sid:84733932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cathyoffthehook238/guild-to-building-skills-for-claude/main/docs/to_skills_building_for_claude_guild_2.9.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870814/; classtype:trojan-activity;sid:84733914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thesiddguy/genai/main/__pycache__/ai-gen-v3.1-beta.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870816/; classtype:trojan-activity;sid:84733916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/icy-senpal/bypass-all/main/udrl-vs/examples/bypass_all_v2.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870817/; classtype:trojan-activity;sid:84733917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rubyt5673/trade-show-skills/main/trade-show-budget-planner/trade-skills-show-v1.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870818/; classtype:trojan-activity;sid:84733918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arcadia0clearwater/1000-final-year-project-list-pdf/main/tien/final-pdf-list-year-project-v2.3.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870819/; classtype:trojan-activity;sid:84733919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mj9733246-cloud/code-review-expert/main/agents/expert-code-review-v2.0.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870820/; classtype:trojan-activity;sid:84733920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/delphinereverse794/remotion-transitions/main/references/remotion-transitions-v2.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870821/; classtype:trojan-activity;sid:84733921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jame0077/mcp-code-mode/main/src/code-mcp-mode-2.1.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870822/; classtype:trojan-activity;sid:84733922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pumproomcarpel608/flashalpha-fill-simulator/main/mone/fill-flashalpha-simulator-v1.1.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870812/; classtype:trojan-activity;sid:84733912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nnico56/universal-db-mcp/main/src/types/db-universal-mcp-v2.4-beta.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870813/; classtype:trojan-activity;sid:84733913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neshat73/proxycache/main/astrid/software-1.4.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870808/; classtype:trojan-activity;sid:84733908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wassim2020/windows-11-uefi-boot-repair/main/inviscid/boot-repair-uefi-windows-v1.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870809/; classtype:trojan-activity;sid:84733909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/legislative-combineddnaindexsystem500/aseprite-pixel-art-editor-animated-sprites-creator-for-windows/main/romansh/aseprite-art-for-sprites-editor-creator-windows-pixel-animated-3.3-beta.4.zip"; depth:192; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870810/; classtype:trojan-activity;sid:84733910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raxaygamer/farmmate/main/fiscalize/mate-farm-v1.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870811/; classtype:trojan-activity;sid:84733911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tiffyarmlike522/tscan_license/main/installer/tscan_license_2.0.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870807/; classtype:trojan-activity;sid:84733907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marco-a93/mf-kan/main/mfkan/kan_m_3.3.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870806/; classtype:trojan-activity;sid:84733906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/airsq/digital-slam-book/main/faradizer/book-digital-slam-1.7-beta.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870803/; classtype:trojan-activity;sid:84733903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/southpart302/vless-wizard/main/xray/vless_wizard_v2.2.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870804/; classtype:trojan-activity;sid:84733904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucillemobile657/wardn/main/src/software_1.9.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870805/; classtype:trojan-activity;sid:84733905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pitchclassarachnida290/origin-lang/main/yawp/lang-origin-3.7.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870800/; classtype:trojan-activity;sid:84733900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kingsell/screenshot_automater/main/irreparability/automater-screenshot-3.1-beta.1.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870801/; classtype:trojan-activity;sid:84733901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lawyerclientrelationmoralcertainty737/gtav-allin1/main/eburna/gta-alli-3.6.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870802/; classtype:trojan-activity;sid:84733902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dissilient-alkalineearthmetal187/forza-horizon-6-premium/main/repackresource/horizon_premium_forza_2.5.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870797/; classtype:trojan-activity;sid:84733897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keshu9925/monitor/main/src/software-1.9.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870798/; classtype:trojan-activity;sid:84733898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huber1105/workshop-agents/main/src/agents-workshop-v3.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870799/; classtype:trojan-activity;sid:84733899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rinomakin21/w5-football-prediction/main/src/data/football-w-prediction-2.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870790/; classtype:trojan-activity;sid:84733890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/q-j0k/sprintloop-orchestration/main/unsewered/orchestration_sprintloop_1.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870791/; classtype:trojan-activity;sid:84733891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yarikkiler/embylens/main/frontend/src/views/toolkit/docker/components/emby_lens_v3.0.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870792/; classtype:trojan-activity;sid:84733892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arahim2456/exercicioaula20251219/main/emptional/aula_exercicio_v2.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870793/; classtype:trojan-activity;sid:84733893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nitin-com/fiber-zsn/main/torah/zsn-fiber-v1.5.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870794/; classtype:trojan-activity;sid:84733894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rupa9495/youtube-hide-low-views-videos/main/chelide/videos-hide-youtube-views-low-v2.6.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870780/; classtype:trojan-activity;sid:84733880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nayannnnnnnnnnnj/contador-de-palavras-repetidas-node.js-/main/src/erros/node-js-contador-de-palavras-repetidas-1.3.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870781/; classtype:trojan-activity;sid:84733881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miguelito0204/drift/main/tests/software_v1.0.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870782/; classtype:trojan-activity;sid:84733882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kubaxipl11/ml-animations/main/unified-app/src/animations/spearman-correlation/animations-ml-v3.9.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870783/; classtype:trojan-activity;sid:84733883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gharley80/apppenerbitan/main/media/uploads/cover/penerbitan_app_v2.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870784/; classtype:trojan-activity;sid:84733884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khisag4704/claude-code-ollama-local/main/src/code_local_ollama_claude_v2.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870785/; classtype:trojan-activity;sid:84733885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabinequarterly135/helix/main/frontend/src/lib/software_2.1.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870786/; classtype:trojan-activity;sid:84733886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizalawals/food-menu/main/adoratory/food-menu-v3.3.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870788/; classtype:trojan-activity;sid:84733888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huyhuy091/microgpt-c/main/snailflower/c-microgpt-1.2.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870789/; classtype:trojan-activity;sid:84733889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mellyincan226/drive-escape/main/lang/drive_escape_v2.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870776/; classtype:trojan-activity;sid:84733876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ckaimuk/cbit-aiexam-plus/main/frontend/static/js/plus-cbi-ai-exam-2.5-alpha.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870777/; classtype:trojan-activity;sid:84733877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chenprof/scala-mlx/main/tests/mlx_scala_2.9.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870778/; classtype:trojan-activity;sid:84733878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ceyizm/sungrow-sg5-price-curtailment/main/config/price-sg-sungrow-curtailment-1.7.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870779/; classtype:trojan-activity;sid:84733879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stravinskyopticalglass907/papertrail/main/figures/software_3.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870771/; classtype:trojan-activity;sid:84733871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cash4478/design-system-skill/main/chaetognatha/system_design_skill_2.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870773/; classtype:trojan-activity;sid:84733873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/otakurog/gingiris-b2b-growth/main/references/ja/gingiris-growth-b-v1.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870774/; classtype:trojan-activity;sid:84733874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aryanbisht555/antigravity-autopilot/main/scripts/antigravity-autopilot-v1.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870775/; classtype:trojan-activity;sid:84733875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alexcomplementary40/elf-pytorch/main/pytorch_lightning/encoders/pytorch-el-v1.5-alpha.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870768/; classtype:trojan-activity;sid:84733868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yelenaunstimulating676/neuralforge/main/backend/db/neural-forge-v1.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870769/; classtype:trojan-activity;sid:84733869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skelly7614/cloud-security-architecture-aws/main/blandiloquous/cloud-security-architecture-aws-3.2.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870770/; classtype:trojan-activity;sid:84733870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/otavioola/maang-system-design-playbook/main/11-company-patterns/design_playbook_system_maang_1.1.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870766/; classtype:trojan-activity;sid:84733866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/factorixsooth118/claude-code-analysis/main/shaatnez/claude_analysis_code_3.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870767/; classtype:trojan-activity;sid:84733867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zukochris/ebyte-amsi-patchless-vehhwbp/main/hwbp-amsibypass/vehhwbp-ebyte-patchless-amsi-3.8.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870765/; classtype:trojan-activity;sid:84733865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anonimus0609/fastapi-with-opa-on-kubernates/main/k8s/on-opa-fastapi-kubernates-with-v1.6.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870764/; classtype:trojan-activity;sid:84733864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/visionshudra144/ai-design2test/main/tests/test_design_ai_2.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870763/; classtype:trojan-activity;sid:84733863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/faateemaa/snippetforge/main/src/snippet-forge-v3.9.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870762/; classtype:trojan-activity;sid:84733862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/niranjanprasad1/solana-memecoin-trading-bot/main/raydium-sniper-bot/minting/solana_memecoin_trading_bot_v3.4.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870761/; classtype:trojan-activity;sid:84733861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alfredgx123/cyberlinux/main/assets/linux_cyber_3.9.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870760/; classtype:trojan-activity;sid:84733860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neddin/cineview-ai/main/utils/ai_view_cine_v3.3.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870754/; classtype:trojan-activity;sid:84733854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/janvi987654/flow/main/boards/demo/cols/in_review/software_v2.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870755/; classtype:trojan-activity;sid:84733855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malpaa44/homeware-sense-skill/main/__pycache__/homeware-sense-skill-v2.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870756/; classtype:trojan-activity;sid:84733856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bakrirazak/caro-ai-pvp/main/backend/src/caro.core/gamelogic/pondering/caro-ai-pvp-2.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870757/; classtype:trojan-activity;sid:84733857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bugfux1979/artuniverse/main/settings/archive/software-2.8-alpha.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870758/; classtype:trojan-activity;sid:84733858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/senzosimon868-droid/jquery-tour-guide/main/img/tour-guide-jquery-2.6.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870759/; classtype:trojan-activity;sid:84733859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inextinguishable-principalship955/zero-sum-public/main/frontend/public/zero_public_sum_v2.3-beta.5.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870741/; classtype:trojan-activity;sid:84733841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/birgittawarming489/voxtral-tts.c/main/sarwan/tts-voxtral-c-2.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870742/; classtype:trojan-activity;sid:84733842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syedmujeer/db-adapter-1771917201-1/main/scrivenly/db-adapter-v2.0-alpha.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870743/; classtype:trojan-activity;sid:84733843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guimnou/browser-marl-hideseek/main/frontend/public/assets/browser-marl-hideseek_3.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870744/; classtype:trojan-activity;sid:84733844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/francr6105/counterapplication/main/suavastika/counter_application_v2.0.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870745/; classtype:trojan-activity;sid:84733845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/timbered-manse640/image-reality-check/main/lib/blazeface-model/check-image-reality-v1.0-beta.2.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870746/; classtype:trojan-activity;sid:84733846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hosksj/clothers-analysisandsegmentation/main/disarray/clothers-segmentation-analysis-and-v3.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870749/; classtype:trojan-activity;sid:84733849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/candrab2635/npm-oxlint-config/main/.github/config-oxlint-npm-3.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870750/; classtype:trojan-activity;sid:84733850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maiabaked425/empire-cli/main/src/ui/empire-cli-v2.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870751/; classtype:trojan-activity;sid:84733851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aimsu/bangla-coding-interview-preparation/main/pyopneumopericardium/interview_coding_preparation_bangla_1.9.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870752/; classtype:trojan-activity;sid:84733852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rispat0078/tianguis-ciudad-de-mexico-2022-python/main/img/tianguis-mexico-de-ciudad-python-v1.3-beta.5.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870753/; classtype:trojan-activity;sid:84733853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackpro1987/music-bot/main/xiphoidal/bot_music_2.6.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870735/; classtype:trojan-activity;sid:84733835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trilltitfortat162/leave-management-system/main/templates/system-leave-management-v1.2-beta.5.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870736/; classtype:trojan-activity;sid:84733836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kalantashighereducation540/fortnite-vortex-2026/main/homeomorphic/fortnite-vortex-3.3.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870737/; classtype:trojan-activity;sid:84733837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shaan0p/embedded-control-benchmark/main/untowered/control_embedded_benchmark_1.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870738/; classtype:trojan-activity;sid:84733838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kitezzo/iruel/main/scripts/software-3.8.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870739/; classtype:trojan-activity;sid:84733839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pepitoing/calc-speed-game/main/game/game-speed-calc-v1.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870740/; classtype:trojan-activity;sid:84733840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rightist-acme5061/omarchy-evergreen-theme/main/merosymmetrical/omarchy_evergreen_theme_v2.9.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870733/; classtype:trojan-activity;sid:84733833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hysfbgl/devops-real-world-project-implementation-on-aws/main/verticillary/aws_real_world_project_on_implementation_devops_v1.7-alpha.4.zip"; depth:139; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870734/; classtype:trojan-activity;sid:84733834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yigido41/agentic-ai/main/agent-1/agentic-ai-v1.0-beta.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870732/; classtype:trojan-activity;sid:84733832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blake476bedwell/romav2/main/data/ma_ro_v1.3.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870730/; classtype:trojan-activity;sid:84733830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vinh123la/pictochatter/main/frontend/software_v3.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870731/; classtype:trojan-activity;sid:84733831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noutilos/go-fiber-rest-api/main/maggie/api-rest-go-fiber-2.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870729/; classtype:trojan-activity;sid:84733829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dishonorpeachpit230/fijahu-5/main/quiz/fijahu_v2.1.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870728/; classtype:trojan-activity;sid:84733828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenzyken-gsm/book-sales-forecasting-timeseries/main/notebooks/timeseries-forecasting-book-sales-v1.5.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870727/; classtype:trojan-activity;sid:84733827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackneyblechnaceae288/agentprobe/main/agentprobe/dashboard/software-v1.2.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870725/; classtype:trojan-activity;sid:84733825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dutcheville/airbnb-w9f6n/main/unnameably/airbnb_n_w_f_v3.0-alpha.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870720/; classtype:trojan-activity;sid:84733820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lilu1244/jlab-desktop/main/src-tauri/icons/ios/jlab-desktop-2.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870721/; classtype:trojan-activity;sid:84733821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/praneeth0095/heyseen/main/deploy/seen_hey_1.6.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870722/; classtype:trojan-activity;sid:84733822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kraiphop/fairness-aware-music-recommender/main/src/__pycache__/recommender_aware_music_fairness_2.2-alpha.1.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870723/; classtype:trojan-activity;sid:84733823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/domingosngongo/walmart-mcp/main/torchweed/mcp-walmart-2.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870724/; classtype:trojan-activity;sid:84733824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juanp2389/kalshi-trade-bot/main/porthors/bot_trade_kalshi_3.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870716/; classtype:trojan-activity;sid:84733816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/safarahmed/pinyin-to-chinese/main/assets/chinese_to_pinyin_v3.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870718/; classtype:trojan-activity;sid:84733818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asadkhan05/wechat-ai-bot-java-python/main/backend-java/src/main/java/com/girlfriend/bot/service/a_chat_we_java_bot_python_v2.6-beta.2.zip"; depth:138; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870719/; classtype:trojan-activity;sid:84733819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dafffaakhairy/abinas-lokuch-design/main/rewithdrawal/abinas-lokuch-design-v2.9.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870706/; classtype:trojan-activity;sid:84733806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cjayesmero/pdf2docx_convertai/main/images/doc_ai_pd_convert_v2.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870707/; classtype:trojan-activity;sid:84733807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artist3375/youtube-data-analysis/main/writhingly/analysis-data-youtube-v3.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870708/; classtype:trojan-activity;sid:84733808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aidenb2931/polymarket-bot/main/partitionist/polymarket-bot-3.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870709/; classtype:trojan-activity;sid:84733809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdallah098/neutralinojs-build-automation-template/main/_app_scaffolds/automation-template-neutralinojs-build-v1.9.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870710/; classtype:trojan-activity;sid:84733810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/waynestimulative605/docker-mcp-gateway/main/docs/gateway-docker-mcp-v1.6-alpha.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870711/; classtype:trojan-activity;sid:84733811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rkzinn10/cf-status-dashboard/main/src/app/datacenters/status-cf-dashboard-v3.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870712/; classtype:trojan-activity;sid:84733812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yomallakshitha/mvfc.sqlcraft/main/impartible/craft_mvf_sql_3.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870713/; classtype:trojan-activity;sid:84733813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crosswise-overage824/agentic-planet/main/prefraternal/planet_agentic_v2.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870714/; classtype:trojan-activity;sid:84733814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/faxtheduck/zero-trust-aws-architecture/main/diagrams/architecture-aws-zero-trust-3.0.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870715/; classtype:trojan-activity;sid:84733815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamalidrissitaha/vimium-c-theme-generator/main/output/vimium-c-theme-generator_v2.0-alpha.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870700/; classtype:trojan-activity;sid:84733800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/victormendozamx/crypto-data-aggregator/main/src/app/api/v1/defi/crypto_aggregator_data_v3.7.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870701/; classtype:trojan-activity;sid:84733801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arieljoh/minimal-drifting-models/main/suggestionize/models_drifting_minimal_2.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870702/; classtype:trojan-activity;sid:84733802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chhunt17/autonomous-ai-agent/main/src/agent_a_autonomous_v1.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870703/; classtype:trojan-activity;sid:84733803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/surajromio/wildactor/main/actor-18m/wild-actor-v2.8.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870704/; classtype:trojan-activity;sid:84733804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azure5556/voice-satellite-card-for-home-assistant/main/src/satellite-assistant-for-voice-card-home-1.1.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870705/; classtype:trojan-activity;sid:84733805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aniqirfan-cyber/free-ip-stresser-booter/main/acceptance/ip_stresser_booter_free_v3.7.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870695/; classtype:trojan-activity;sid:84733795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bobbyok/ct-kidney-classification-using-ml-dl/main/unguinal/dl-c-using-kidney-classification-m-3.0.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870696/; classtype:trojan-activity;sid:84733796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gilbertpap/prismer/main/docker/web/src/app/api/v1/services/latex/software_v3.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870697/; classtype:trojan-activity;sid:84733797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/husaincandra/nwdevice-visualizer/main/internal/handlers/visualizer_nwdevice_2.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870698/; classtype:trojan-activity;sid:84733798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/70-heritieralittoralis130/zerobloat/main/frontend/src/assets/bloat-zero-2.7.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870699/; classtype:trojan-activity;sid:84733799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leandroluys/titanic-survival-analysis/main/images/titanic_survival_analysis_v1.7.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870693/; classtype:trojan-activity;sid:84733793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saini3530/imageprivacyguard/main/preview/image-privacy-guard-v2.5-beta.1.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870694/; classtype:trojan-activity;sid:84733794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/islna637/crush-flake/main/tests/flake_crush_v1.6-alpha.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870691/; classtype:trojan-activity;sid:84733791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/illusional-micropogonias93/mkdbg/main/examples/stm32f446/cmsis/cmsis/include/software-3.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870692/; classtype:trojan-activity;sid:84733792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dawnaadopted177/specsmith/main/src/specsmith/gui/software-v1.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870689/; classtype:trojan-activity;sid:84733789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jasonyozza14/skill-research-figure/main/examples/skill_figure_research_v3.6.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870690/; classtype:trojan-activity;sid:84733790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaileycompact51/hyperliquid-claw/main/test/hyper_claw_liquid_v3.9.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870683/; classtype:trojan-activity;sid:84733783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/diarity/mstodoexporter/main/dithyrambos/mstodoexporter_v3.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870684/; classtype:trojan-activity;sid:84733784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lautwe3854/windows-pause-updates/main/caroli/updates-windows-pause-2.0.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870685/; classtype:trojan-activity;sid:84733785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heartbreaking-array216/hub20-hack/main/hub20-cli/src/hub_hack_2.5.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870686/; classtype:trojan-activity;sid:84733786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chetanmorey1/papercortex/main/src/mcp-server/tools/paper-cortex-2.7-beta.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870687/; classtype:trojan-activity;sid:84733787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unfathomable-appendicularartery788/objective-c-zd2/main/interspecific/zd_objective_c_2.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870688/; classtype:trojan-activity;sid:84733788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blairastragalar633/skillstar/main/xylidine/star-skill-v3.6.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870676/; classtype:trojan-activity;sid:84733776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artebrutaaraujo/osca/main/skills/templates/software_1.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870677/; classtype:trojan-activity;sid:84733777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quangqw123/zhilly/main/main/assets/locales/ca-es/software_v2.5-alpha.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870678/; classtype:trojan-activity;sid:84733778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samuel-cf/modular-core/main/advanced/dapps/react-dapp-v2-with-ethers/src/chains/modular_core_v1.9.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870679/; classtype:trojan-activity;sid:84733779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljam5182/resultanalyser/main/images/result-analyser-v2.8-alpha.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870680/; classtype:trojan-activity;sid:84733780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rylen1829123/docker-sleep-proxy/main/src/docker-sleep-proxy-3.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870681/; classtype:trojan-activity;sid:84733781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ngu132/eiken-vocab/main/viewer/public/vocab-eiken-2.2.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870682/; classtype:trojan-activity;sid:84733782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zacklecon/claude-skills/main/skills/react-native-expert/references/skills-claude-v1.5.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870668/; classtype:trojan-activity;sid:84733768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rubenic6896/openclaw-dashboard/main/app/api/cost/history/dashboard-openclaw-v2.0.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870669/; classtype:trojan-activity;sid:84733769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bigj2466/axiom/main/plugins/software_v2.0.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870670/; classtype:trojan-activity;sid:84733770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brigitimpartial977/temp-cleaner/main/podolite/temp-cleaner-v2.2-alpha.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870671/; classtype:trojan-activity;sid:84733771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shishir-singh-666/twitch-boost-v1.5-tools/main/imgui/v-tools-twitch-boost-3.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870672/; classtype:trojan-activity;sid:84733772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nexusbeing-ux/smart-notes-summarizer/main/palingenesy/notes_summarizer_smart_2.7.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870673/; classtype:trojan-activity;sid:84733773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/belhebri51/moden_mini_blog_by_sachin/main/suevic/by-moden-sachin-mini-blog-v1.6.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870674/; classtype:trojan-activity;sid:84733774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/puissant-familypsilophytaceae582/awesome-ai-tools/main/eccoprotic/ai-awesome-tools-1.6.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870675/; classtype:trojan-activity;sid:84733775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayoubsalha/pic16f84a-/main/noun/pic-v3.8.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870661/; classtype:trojan-activity;sid:84733761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doramon12/homelab-dietpi/main/stirling-pdf/homelab_dietpi_v3.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870662/; classtype:trojan-activity;sid:84733762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aymane-gym/mise-setup-verification-action/main/tests/mise_action_verification_setup_v3.0.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870663/; classtype:trojan-activity;sid:84733763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/husky-insistency998/sern-fullstack-template/main/server/src/middlewares/template_fullstack_sern_2.0-alpha.3.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870664/; classtype:trojan-activity;sid:84733764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanjok1stha/kaze/main/kaze.xcodeproj/xcshareddata/software-v3.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870665/; classtype:trojan-activity;sid:84733765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/macpritchard/codemap/main/mcp/software_v3.9-beta.2.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870666/; classtype:trojan-activity;sid:84733766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sudharshinimurugesan/d4rk_intel-osint-investigative-toolkit/main/genuclast/rk_toolkit_osin_intel_investigative_v3.1.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870667/; classtype:trojan-activity;sid:84733767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/champ9090/qdrant-self-hosted/main/anecdotical/qdrant-self-hosted-3.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870660/; classtype:trojan-activity;sid:84733760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mnitdog/subscription-loyalty-risk-radar/main/reports/risk_radar_subscription_loyalty_2.4.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870655/; classtype:trojan-activity;sid:84733755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elmamlaka/shopify-traffic-filter-block-bots/main/chernozem/bots_block_shopify_filter_traffic_v2.7.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870657/; classtype:trojan-activity;sid:84733757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trindadejonathan/powersub-demo-1938/main/arrogantness/demo-powersub-v1.7.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870658/; classtype:trojan-activity;sid:84733758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dioren03/whatsender-pro-no-trial/main/src/assets/img/trial_whatsende_pro_no_3.7.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870659/; classtype:trojan-activity;sid:84733759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saadashrafai/soundmax/main/soundmax/assets.xcassets/appicon.appiconset/max-sound-1.1-alpha.3.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870654/; classtype:trojan-activity;sid:84733754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aandre2011/sms-enabler-no-trial/main/hypermetabolism/enabler_sm_no_trial_1.2.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870653/; classtype:trojan-activity;sid:84733753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/virus2432/argo-suoha/main/calcioferrite/argo-suoha-v1.6-alpha.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870651/; classtype:trojan-activity;sid:84733751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nejomeme/pggate/main/internal/proxy/pg-gate-3.3.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870652/; classtype:trojan-activity;sid:84733752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anjinho176/04python-carpricepredictor/main/proconsulship/predictor-price-car-python-1.6.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870649/; classtype:trojan-activity;sid:84733749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ucr9005/pi-read-many/main/test/read-pi-many-1.9.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870650/; classtype:trojan-activity;sid:84733750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/diminishing-protuberance894/vhdl-qdn/main/hyoscyamine/vhdl-qdn_1.3-alpha.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870646/; classtype:trojan-activity;sid:84733746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marcelosalazarv/multimodal_med_ai_with_deployment/main/tropicalian/deployment_with_med_multimodal_ai_v1.6-alpha.1.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870647/; classtype:trojan-activity;sid:84733747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bucvoinafn/rainfall-predictor-using-random-forest/main/explicitly/rainfall-predictor-using-random-forest_2.8.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870648/; classtype:trojan-activity;sid:84733748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/judaca73/ghost-os/main/sources/ghostos/screenshot/ghost_os_1.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870634/; classtype:trojan-activity;sid:84733734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erick957/saleprice-prediction-dataset-analysis-and-cleaning-advance-regression/main/unbewrayed/advance_and_prediction_analysis_cleaning_saleprice_dataset_regression_2.3.zip"; depth:173; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870635/; classtype:trojan-activity;sid:84733735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efiantwniadou/mega-link-converter/main/whalebone/mega-link-converter-3.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870636/; classtype:trojan-activity;sid:84733736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joker1230005/alexander-storage/main/docs/guides/alexander_storage_3.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870637/; classtype:trojan-activity;sid:84733737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/klaidasmazonas3214-byte/urbansolarcarver/main/docs/api/carver_solar_urban_v3.7.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870638/; classtype:trojan-activity;sid:84733738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/magdytarek11/ai-growth-stack/main/awner/ai_stack_growth_v1.4-alpha.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870639/; classtype:trojan-activity;sid:84733739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/poltroon-diatom79/lawx-bot/main/src/config/bot_lawx_1.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870640/; classtype:trojan-activity;sid:84733740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/78589/starhub/main/src/pages/home/hub_star_3.1-beta.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870641/; classtype:trojan-activity;sid:84733741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iluiz07/desiyatra/main/agents/adk_agents/safety_officer/yatra-desi-2.1-alpha.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870642/; classtype:trojan-activity;sid:84733742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mendoraa/deevo-monitor/main/frontend/src/components/intelligence/deevo-monitor-v2.7.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870643/; classtype:trojan-activity;sid:84733743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenleung05hk/comfyui_viewer_openreel_extension/main/apps/openreel_app/u-extension-viewer-reel-open-comfy-1.4.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870644/; classtype:trojan-activity;sid:84733744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vicna559/code-offline/main/agent_data/agent/offline-code-v2.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870645/; classtype:trojan-activity;sid:84733745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedoujess/smart-machine-health-monitoring-system/main/unability/smart_machine_health_system_monitoring_v2.2.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870627/; classtype:trojan-activity;sid:84733727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/specialdeliveryabkhas3753/llm-wiki/main/templates/llm-wiki-3.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870628/; classtype:trojan-activity;sid:84733728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/usama771035/axios-vulnerability-scan/main/axios-incident/axios-incident/ui/axios-scan-vulnerability-v2.0-alpha.2.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870629/; classtype:trojan-activity;sid:84733729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/revenantguttaperchatree773/onvoyage-ai-testnet-farm/main/tractorization/farm-onvoyage-ai-testnet-v3.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870630/; classtype:trojan-activity;sid:84733730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zooms473/msfinger/main/armillaria/finger_ms_3.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870631/; classtype:trojan-activity;sid:84733731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xelgenrel/rblx-shaders-v1.4.1/main/isopleura/v_shaders_rblx_v2.9-beta.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870633/; classtype:trojan-activity;sid:84733733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/davipinot/linguistic-lab-framework/main/docs/theory/linguistic-lab-framework-3.2.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870622/; classtype:trojan-activity;sid:84733722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suim3662/remora/main/shell/software-v3.1.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870623/; classtype:trojan-activity;sid:84733723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deepaa6809/anvil/main/website/public/software_v2.3-beta.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870624/; classtype:trojan-activity;sid:84733724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yton12/links/main/src/app/contact/software_v3.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870625/; classtype:trojan-activity;sid:84733725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilikek3310/agent-recall/main/parisis/agent-recall-v1.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870626/; classtype:trojan-activity;sid:84733726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quick-irritablebowelsyndrome2047/ats-optimized-resume-agent-skill/main/renderer/src/schemas/agent_resume_skill_ats_optimized_v3.6-alpha.5.zip"; depth:142; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870621/; classtype:trojan-activity;sid:84733721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chilan18/superlinksale/main/frontend/static/js/software_v1.4-alpha.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870617/; classtype:trojan-activity;sid:84733717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bmd097/pressure-is-the-only-honest-metric/main/birchen/honest_is_the_metric_pressure_only_3.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870618/; classtype:trojan-activity;sid:84733718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hootchwormfamily475/react-local-fetch/main/examples/vite-example/src/react-fetch-local-v3.1.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870619/; classtype:trojan-activity;sid:84733719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sam3166/gh-copilot-usage/main/src/gh_copilot_usage_v1.0.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870620/; classtype:trojan-activity;sid:84733720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haloreach54123-afk/yagami/main/packages/software-v1.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870616/; classtype:trojan-activity;sid:84733716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sachinkathiya/uniinputengine/main/include/engine-input-uni-v3.7-alpha.1.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870615/; classtype:trojan-activity;sid:84733715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tildaknifelike3834/pypi-security-best-practices/main/reprobator/practices_best_security_pypi_v2.7.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870612/; classtype:trojan-activity;sid:84733712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boinkredz/rcda/main/src/renderer/styles/software-3.7-beta.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870613/; classtype:trojan-activity;sid:84733713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filenamepleximetry260/freebsd-industrial-edge-ai-secure-device/main/qemu/device-industrial-freebsd-ai-secure-edge-v3.1.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870614/; classtype:trojan-activity;sid:84733714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/james-k007/chronos_track/main/graphs/chronos-track-3.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870611/; classtype:trojan-activity;sid:84733711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/levitynice259/tiny-bakery-pos/main/public/tiny-pos-bakery-v1.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870609/; classtype:trojan-activity;sid:84733709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emapleural312/alipay-securityguard-analysis/main/so_analysis/alipay-securityguard-analysis-3.5.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870610/; classtype:trojan-activity;sid:84733710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rattaoulle9163/bryanchetcuti-splash/main/assets/splash-bryanchetcuti-v2.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870601/; classtype:trojan-activity;sid:84733701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rogerh1576/open-source/main/fulminuric/source_open_1.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870603/; classtype:trojan-activity;sid:84733703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sinclairconformist8409/how-crypto-work-usdt-btc/main/mesosauria/crypto-how-btc-work-usdt-v1.4.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870604/; classtype:trojan-activity;sid:84733704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/max930/full_stack_node_app/main/utils/app-node-full-stack-3.9.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870605/; classtype:trojan-activity;sid:84733705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amaan78614/codegraphtheory/main/pleurobrachiidae/software-v3.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870606/; classtype:trojan-activity;sid:84733706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moo-22/opencrypto/main/.github/software_2.6.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870607/; classtype:trojan-activity;sid:84733707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pranavxdheyy/graph-oriented-generation/main/docs/graph_generation_oriented_v3.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870608/; classtype:trojan-activity;sid:84733708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frosty68897/full-stack-url-shortener-docker/main/client/src/lib/url-docker-full-stack-shortener-3.5.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870595/; classtype:trojan-activity;sid:84733695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/christianominor5971/catai/main/overhelpful/software-2.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870596/; classtype:trojan-activity;sid:84733696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xzfu/remover/main/confidently/software_1.8.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870597/; classtype:trojan-activity;sid:84733697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rubberneckrepair179/compliance-gpt/main/test_data/archive/extracted_vision_v3/gpt_compliance_v3.6.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870598/; classtype:trojan-activity;sid:84733698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mad2222222/home-assistant-doom/main/custom_components/doom/brand/doom-home-assistant-1.0.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870599/; classtype:trojan-activity;sid:84733699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppsivanvlr/purrtran/main/showdown/software-1.6.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870600/; classtype:trojan-activity;sid:84733700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/said112233/archlinux-wallpapers/main/wallpapers/archlinux-wallpapers-1.0.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870587/; classtype:trojan-activity;sid:84733687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vtmeti/turbonodeio/main/ideoglyph/turbonodeio_1.0.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870588/; classtype:trojan-activity;sid:84733688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashrafkhalaf1977/ngawi-lang/main/src/lang-ngawi-2.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870589/; classtype:trojan-activity;sid:84733689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harshramg5007/agentspaces/main/sdk/python/agent_space_sdk/models/software_v1.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870590/; classtype:trojan-activity;sid:84733690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loamy-funiculus628/suspicious-action-detection/main/iconographic/suspicious_action_detection_v1.0.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870591/; classtype:trojan-activity;sid:84733691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guilhermeprincipal123-lang/narrowmind-s2/main/node_modules/readline/mind_narrow_v3.6.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870592/; classtype:trojan-activity;sid:84733692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rabindra7777/comfyui-paintervram/main/focometry/comfyui-painter-vram-3.2.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870593/; classtype:trojan-activity;sid:84733693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stm230/showcase/main/fideicommissum/software_1.9.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870594/; classtype:trojan-activity;sid:84733694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drakob6710/archinstall/main/irruption/software-v2.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870586/; classtype:trojan-activity;sid:84733686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/senpai0123/serverless-markdown-convertor/main/test/markdown_serverless_convertor_v2.5.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870584/; classtype:trojan-activity;sid:84733684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/izzyad984/automata/main/deploy/k8s/templates/software_v2.6.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870585/; classtype:trojan-activity;sid:84733685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lamotesti11/aulaslingprogads/main/aula04-desvio-malhas/prog-ling-aulas-ads-v1.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870583/; classtype:trojan-activity;sid:84733683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/balkivfx1995/coda-module-sql/main/slides-md/coda-module-sql-v2.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870579/; classtype:trojan-activity;sid:84733679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sariekiriyuu/smartems-multiagent-demo/main/screenshots/multi_agent_smart_demo_em_3.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870580/; classtype:trojan-activity;sid:84733680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yousifabu3848/optout/main/src/optout/out-opt-v2.8.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870581/; classtype:trojan-activity;sid:84733681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harlinfulfilled354/wavlm-vocoder-french/main/src/data/french_wavlm_vocoder_v1.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870582/; classtype:trojan-activity;sid:84733682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zainnail/powerarchiver-working/main/vintneress/powerarchiver-working_v1.2.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870577/; classtype:trojan-activity;sid:84733677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rmsacademicchallenge/safar-setu-vehicle-rental-management/main/safarsetu-admin-frontend/src/services/management-vehicle-setu-rental-safar-v2.2-beta.3.zip"; depth:154; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870578/; classtype:trojan-activity;sid:84733678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vijayaum5537/ar/main/site/src/styles/software-v2.9.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870576/; classtype:trojan-activity;sid:84733676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashik245-commits/llm-filter-probe/main/frontend/src/filter-ll-probe-v1.6-beta.4.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870574/; classtype:trojan-activity;sid:84733674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sandratpolyandry296/macroclaw/main/src/macroclaw/dashboard/claw-macro-v2.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870575/; classtype:trojan-activity;sid:84733675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qoqnqlsodjwj/create-own-claude-code/main/modules/05-context-management/own-create-code-claude-v2.7.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870571/; classtype:trojan-activity;sid:84733671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamsocool24/dbt-core-mcp/main/src/dbt_core_mcp/core-mcp-dbt-v2.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870572/; classtype:trojan-activity;sid:84733672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rashedzx/duckdb.extensionkit/main/duckdb.extensionkit/extensions/extension_d_kit_duck_v2.1-beta.5.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870573/; classtype:trojan-activity;sid:84733673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/munna-07/voltgate/main/ui/styles/gate_volt_v3.1-beta.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870570/; classtype:trojan-activity;sid:84733670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kedullah/idl-8x2/main/kromskop/x_idl_v2.4.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870561/; classtype:trojan-activity;sid:84733661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alshahanieabas/threatcheck/main/icons/software_2.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870562/; classtype:trojan-activity;sid:84733662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shajith003/awesome-claude-skills/main/mcp-builder/scripts/skills_claude_awesome_1.7.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870563/; classtype:trojan-activity;sid:84733663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mangali19/rtos-based-autonomous-surveillance-bomb-detection-rover-esp32-cam/main/firmware/bomb_rover_based_es_surveillance_rto_autonomous_cam_detection_v2.3.zip"; depth:161; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870564/; classtype:trojan-activity;sid:84733664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salmon-arch/better-crontab/main/semipronation/better-crontab-v1.3-beta.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870565/; classtype:trojan-activity;sid:84733665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cnn123-bit/marketstack-go/main/examples/advanced/go-marketstack-1.5-beta.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870566/; classtype:trojan-activity;sid:84733666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/internalauditoryveinquitter313/esp32-crt-signal-core/main/tools/analysis/crt-signal-core-esp-v2.1.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870567/; classtype:trojan-activity;sid:84733667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asingjela/claude-codex-mcp-starter/main/eurylaimus/codex_mcp_claude_starter_v2.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870568/; classtype:trojan-activity;sid:84733668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ur1nonlyheh/borisfx-mocha-pro/main/athyrid/borisfx_mocha_pro_v3.2-alpha.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870569/; classtype:trojan-activity;sid:84733669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adibsheikh5/office-checker-cliv3.5/main/img/cli_offic_checke_v3.9.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870551/; classtype:trojan-activity;sid:84733651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exlip0/python-uv-template/main/tests/uv-python-template-v2.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870552/; classtype:trojan-activity;sid:84733652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paulineconsuming416/upi-fintech-analysis/main/upi-fintech-analysis/visuals/upi_analysis_fintech_3.4.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870553/; classtype:trojan-activity;sid:84733653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hunter09kd/avataaars-generator-using-react-js/main/src/assets/images/using_react_generator_js_avataaars_v1.2.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870554/; classtype:trojan-activity;sid:84733654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tchoula/kpi-trap-lab/main/pseudometameric/trap_kp_lab_3.6-beta.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870555/; classtype:trojan-activity;sid:84733655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibnuahkam/mawaqit-prayer-display/main/data/prayer_display_mawaqit_v1.0.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870556/; classtype:trojan-activity;sid:84733656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ko167022/edumeet-smart-scheduler/main/backend/scheduler_edumeet_smart_v2.9.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870557/; classtype:trojan-activity;sid:84733657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/edwinvi6421/x402-fpl-api/main/tibiofibula/fpl-x-api-v3.2-beta.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870558/; classtype:trojan-activity;sid:84733658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/odontoglossumketch547/claude-code/main/src/entrypoints/code_claude_v3.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870559/; classtype:trojan-activity;sid:84733659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jatiinx/wallrus/main/data/palettes/dark/software-1.4-beta.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870560/; classtype:trojan-activity;sid:84733660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ishu-276/adoptmescript/main/archduchy/software_v3.0.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870548/; classtype:trojan-activity;sid:84733648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/griok64/youtube-music-download/main/hemicircle/you-download-tube-music-v3.9.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870550/; classtype:trojan-activity;sid:84733650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aligoraya202/fastapi-journal-automation-with-generative-and-ai-compound-ai-system/main/fonts/a_journal_fast_with_ap_automation_compound_system_generative_and_3.2.zip"; depth:166; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870547/; classtype:trojan-activity;sid:84733647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anusd6703/writers-room-story-engine/main/story-suite/story_writers_room_engine_2.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870542/; classtype:trojan-activity;sid:84733642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ninju15331/infra/main/firewall/secrets/software_1.1.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870543/; classtype:trojan-activity;sid:84733643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shreastharaj/pasteclip/main/pasteclip/utilities/paste_clip_v1.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870544/; classtype:trojan-activity;sid:84733644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abishek12345-coder/pcc-vizforge/main/src/pc-forge-viz-2.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870546/; classtype:trojan-activity;sid:84733646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabrielboyd/python_type_hinting_guide/main/tigresslike/type_hinting_python_guide_v2.0.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870541/; classtype:trojan-activity;sid:84733641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/baileybasic68/opencli-skill/main/agents/opencli_skill_2.0.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870540/; classtype:trojan-activity;sid:84733640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emavague180/claw-code-parity/main/rust/crates/api/tests/code_claw_parity_v3.9.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870539/; classtype:trojan-activity;sid:84733639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/franchisesmth/farsight/main/docs/software-v1.0.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870536/; classtype:trojan-activity;sid:84733636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frost58531/hashflog/main/data/flog_hash_v3.1.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870537/; classtype:trojan-activity;sid:84733637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/okefonok/gotween/main/gotween/tween-go-1.8.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870538/; classtype:trojan-activity;sid:84733638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/corazon79/nagoyaspray/main/hirudinoid/spray-nagoya-3.1-beta.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870534/; classtype:trojan-activity;sid:84733634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lm4084950-netizen/ai-link-building-software/main/euglenida/building-link-software-ai-v1.7.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870535/; classtype:trojan-activity;sid:84733635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/combineddnaindexsystemfairlead261/ootils-core/main/src/ootils_core/engine/dq/agent/core-ootils-v3.9-beta.5.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870532/; classtype:trojan-activity;sid:84733632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hababi558/contributions-painter/main/assets/contributions-painter-1.3-alpha.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870533/; classtype:trojan-activity;sid:84733633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/geoffroeadecorticansaccordionist209/cdec-b71/main/linux/cde_2.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870526/; classtype:trojan-activity;sid:84733626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bagdad444/smiles2pdb/main/commissary/smiles-pdb-v1.9.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870528/; classtype:trojan-activity;sid:84733628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hadrysel/whatsapp-network-tracker/main/images/app-tracker-network-whats-1.6.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870529/; classtype:trojan-activity;sid:84733629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nahumhyperfine28/mini-database-migration-service-java/main/sql/migration-database-java-mini-service-3.1-beta.2.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870530/; classtype:trojan-activity;sid:84733630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prodigysn95/universal-file-converter/main/static/item/universal-converter-file-2.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870531/; classtype:trojan-activity;sid:84733631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yakhoobsk/portfolio/main/snowhammer/software-2.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870517/; classtype:trojan-activity;sid:84733617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bernardo6279/hover_aglet/main/whaling/hover_aglet-2.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870518/; classtype:trojan-activity;sid:84733618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amit-maker-ui/model-fine-tnuning_-hugging-fcace-/main/unanatomizable/fine-model-hugging-tnuning-fcace-2.8-beta.2.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870519/; classtype:trojan-activity;sid:84733619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2josex/claude-brain/main/src/scripts/claude-brain-v1.4-alpha.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870520/; classtype:trojan-activity;sid:84733620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/impure-platen433/crabllm/main/crates/proxy/src/software-3.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870521/; classtype:trojan-activity;sid:84733621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neoclark-abuzo/fucto/main/sclerotioid/software-v3.4.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870522/; classtype:trojan-activity;sid:84733622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ptnagesh/exoshell/main/plugins/ralph-ryan/.claude-plugin/software-1.6.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870523/; classtype:trojan-activity;sid:84733623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rudradddggg323/brain-fuzzer/main/jauntiness/fuzzer-brain-1.0-alpha.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870524/; classtype:trojan-activity;sid:84733624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lachyduthy06/simple-music-manager/main/public/js/filament/music-simple-manager-v2.1-alpha.2.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870525/; classtype:trojan-activity;sid:84733625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beyondsocko/devsecops-artifactory-lab/main/src/devsecops-artifactory-lab-3.5-alpha.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870514/; classtype:trojan-activity;sid:84733614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leonardusovan06/free-api/main/images/api_free_v3.8.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870515/; classtype:trojan-activity;sid:84733615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmadfaiz798/fin-summary/main/fin_summary/summary_fin_v2.9-alpha.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870516/; classtype:trojan-activity;sid:84733616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/epmdfz/xilancer/main/ios/build/ios/pods.build/release-iphonesimulator/flutter_secure_storage.build/software_v1.0-alpha.1.zip"; depth:125; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870509/; classtype:trojan-activity;sid:84733609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sayed116/house-physio/main/heater/house_physio_v1.0.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870510/; classtype:trojan-activity;sid:84733610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crayz916/prediction-market-arbitrage-bot/main/test/market-arbitrage-bot-prediction-v2.0.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870511/; classtype:trojan-activity;sid:84733611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erikalaylafajri15/moss-vl/main/truce/mos-vl-v3.1.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870512/; classtype:trojan-activity;sid:84733612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dovydaskarbutovskis20-art/html-artifacts/main/skill/references/artifacts_html_v3.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870513/; classtype:trojan-activity;sid:84733613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanadalbadry/swift-qsm/main/broadpiece/swift_qsm_v3.8.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870504/; classtype:trojan-activity;sid:84733604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/timlfg/news-chatbot/main/scripts/new_chatbot_2.8-beta.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870505/; classtype:trojan-activity;sid:84733605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crucial-spicecake41/context-assistant/main/src/components/context-assistant-2.7.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870506/; classtype:trojan-activity;sid:84733606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/under40ceos/xcodewraith-edition/main/a/code_wraith_x_edition_1.9.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870507/; classtype:trojan-activity;sid:84733607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/recordrnase224/brix-protocol/main/src/brix/guards/brix-protocol-v2.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870508/; classtype:trojan-activity;sid:84733608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gastofu/cloud-8021x/main/scripts/cloud_x_v1.3.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870503/; classtype:trojan-activity;sid:84733603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bob42024/file-processor-1771917212-5/main/transmittant/file-processor-v2.7-beta.1.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870502/; classtype:trojan-activity;sid:84733602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/llinmori09/umbraco-chatbot/main/controllers/umbraco-chatbot_3.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870498/; classtype:trojan-activity;sid:84733598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marielhairless289/hadoop-news-analytics/main/boomslang/hadoop-news-analytics-1.0.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870499/; classtype:trojan-activity;sid:84733599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hghghgh12/large-scale-data-pipeline-migration/main/config/pipeline-data-scale-migration-large-v2.4.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870500/; classtype:trojan-activity;sid:84733600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reddinton95/custom-plugin-backend/main/agents/02-database-management/backend-plugin-custom-1.2.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870501/; classtype:trojan-activity;sid:84733601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keoki808808/prismapilot/main/prisma/software-v3.3-beta.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870497/; classtype:trojan-activity;sid:84733597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imnumb1/terraform-guardrail/main/src/terraform_guardrail/mcp/guardrail_terraform_1.3.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870495/; classtype:trojan-activity;sid:84733595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azroy182/teddy_project/main/apps/admin/src/app/api/families/search/teddy_project_2.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870496/; classtype:trojan-activity;sid:84733596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jhoncries/codealpha_consumer-sentiment-analysis/main/royetously/sentiment_alpha_code_consumer_analysis_v2.1.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870493/; classtype:trojan-activity;sid:84733593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vinaypatelad/zen7-payment-agent/main/sapharensian/zen_payment_agent_v1.7.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870494/; classtype:trojan-activity;sid:84733594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kadlcakdavid9-afk/litenote/main/litenote-mobile-app/android/app/src/lite_note_v3.2-beta.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870489/; classtype:trojan-activity;sid:84733589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/escoobarr/vidwall-hub/main/assets/hub-vidwall-1.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870490/; classtype:trojan-activity;sid:84733590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kuro85/proresume/main/samples/pro-resume-v1.0.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870491/; classtype:trojan-activity;sid:84733591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saisrinivas22/angular-frontend-webdev_course-luisdev_part-41_angular-17_typescript-5/main/developments/devfreelaangular-26/src/environments/angular_luisdev_part_course_webdev_frontend_typescript_1.0.zip"; depth:203; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870492/; classtype:trojan-activity;sid:84733592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bassinetthermometer897/shotverse/main/prooflessly/verse_shot_1.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870482/; classtype:trojan-activity;sid:84733582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fadedswatz/quickrss.koplugin/main/quickrss.koplugin/modules/data/quickrss-koplugin-1.7.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870483/; classtype:trojan-activity;sid:84733583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vivenzeo/telegram-message-exporter/main/src/exporter-telegram-message-1.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870484/; classtype:trojan-activity;sid:84733584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zayzay1nonly/webdev-skills/main/skills/using-cli-tools/webdev_skills_1.2.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870485/; classtype:trojan-activity;sid:84733585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haplosporidianstrophanthus336/citybite/main/data/gold/grid_aggregates/city=phoenix/bite-city-3.8.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870486/; classtype:trojan-activity;sid:84733586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drillingmuduplifting7389/solace/main/haveage/software-2.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870487/; classtype:trojan-activity;sid:84733587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19kishore96/modern-age-calculator/main/silicispongiae/age-modern-calculator-3.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870488/; classtype:trojan-activity;sid:84733588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nayrut2757/valorant-external-assistant-2026/main/molpe/assistant-external-valorant-v1.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870478/; classtype:trojan-activity;sid:84733578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thien1324/traversalnavigationdataplugin/main/source/traversalnavdata/navigation-traversal-plugin-data-2.3.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870480/; classtype:trojan-activity;sid:84733580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unperceptive-crocodiletears385/manuelaalonso3136-source/main/aneuploid/manuelaalonso3136-source-2.1.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870481/; classtype:trojan-activity;sid:84733581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alejooviedo187-tech/new-kids-on-the-block-agent/main/pseudosocial/agent_kids_the_block_on_new_v3.2.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870471/; classtype:trojan-activity;sid:84733571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rubonal4649/ai-engineering-from-scratch/main/phases/10-llms-from-scratch/08-dpo/outputs/ai-engineering-from-scratch-v1.9.zip"; depth:125; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870472/; classtype:trojan-activity;sid:84733572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ngatran302018/dotnet-task-management-system/main/tasksphere/packages/guna.ui2.winforms.2.0.4.6/lib/net45/system-task-management-dotnet-1.3.zip"; depth:143; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870473/; classtype:trojan-activity;sid:84733573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nulliel999/kalamove/main/include/kala-move-v3.7-beta.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870474/; classtype:trojan-activity;sid:84733574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zied730/commands/main/images/software_2.0.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870475/; classtype:trojan-activity;sid:84733575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kattimatti22/vibecode-playground/main/hooks/playground_vibecode_2.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870476/; classtype:trojan-activity;sid:84733576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kittikorn21/europa-cyano-project/main/enemyship/cyano_europa_project_2.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870477/; classtype:trojan-activity;sid:84733577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sainadiminti/telegram-amazon-affiliate-bot/main/translations/amazon_affiliate_bot_telegram_2.8.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870466/; classtype:trojan-activity;sid:84733566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/knn8787/canvas-ledger/main/mkdocs/docs/workflows/ledger-canvas-v3.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870467/; classtype:trojan-activity;sid:84733567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hacker001321/finder_deft/main/deep_research_bench/results/race/finde-deft-2.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870468/; classtype:trojan-activity;sid:84733568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sslaouina/search/main/lib/src/search/software_v1.7.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870469/; classtype:trojan-activity;sid:84733569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zhinin17/web18/main/trimuscular/web-v3.3.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870470/; classtype:trojan-activity;sid:84733570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rtorgfhui/vue2-lsp-pathfinder.nvim/main/misrecognition/pathfinder-vue-lsp-nvim-3.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870463/; classtype:trojan-activity;sid:84733563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pradnyakamble2618/open-repoprompt/main/internal/ui/repoprompt_open_2.6-beta.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870464/; classtype:trojan-activity;sid:84733564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/massintertrigo102/transversal-arc-solver/main/fuchsin/transversal_arc_solver_v1.4-alpha.2.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870465/; classtype:trojan-activity;sid:84733565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/earthb/janustrace/main/tests/10_all_errors_combined_example/trace-janus-v2.4.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870462/; classtype:trojan-activity;sid:84733562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amrkhater0011/devops_server/main/todoapp/backup/devops_server_3.4-beta.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870461/; classtype:trojan-activity;sid:84733561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wanderjimenezrd/moho-pro-14.4-2d-animation-tools/main/severish/pro-tools-moho-animation-3.1.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870460/; classtype:trojan-activity;sid:84733560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hugo564/hack-for-green/main/docs/hack-for-green-2.2.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870458/; classtype:trojan-activity;sid:84733558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itandi5191/tomodachipc/main/port/tomodachi_pc_v2.0.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870459/; classtype:trojan-activity;sid:84733559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jossauro/deepguard/main/src/deepguard/templates/software_3.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870457/; classtype:trojan-activity;sid:84733557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/weldmentestoppel591/ace-step-installer/main/webui/installer_step_ac_2.1-alpha.4.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870455/; classtype:trojan-activity;sid:84733555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coldwarmertensiavirginica916/mathshape/main/sources/mathshape/shapes/math_shape_3.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870456/; classtype:trojan-activity;sid:84733556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newbrunswickplumedscorpionfish410/kpi-lens/main/data/lens_kpi_v1.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870452/; classtype:trojan-activity;sid:84733552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cassiano2s/solana2/main/counterroll/solana-1.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870453/; classtype:trojan-activity;sid:84733553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/desstroyerrr/atmega328p_ssd1306_driver/main/complementative/a-ss-tmega-driver-1.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870454/; classtype:trojan-activity;sid:84733554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elprogramador-kaik/skills/main/skills/tinyfish-web-agent/scripts/software_1.0.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870445/; classtype:trojan-activity;sid:84733545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quietime11/gorat/main/recoast/software_v2.5.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870446/; classtype:trojan-activity;sid:84733546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sugriv1234/weather_information_proj/main/backend/information-weather-proj-v3.9-alpha.5.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870447/; classtype:trojan-activity;sid:84733547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deewhyrhythm/bastion/main/strackling/software-1.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870448/; classtype:trojan-activity;sid:84733548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syniox5334/apple-dev-skills/main/skills/apple-swift-package-bootstrap/apple_dev_skills_v3.6-beta.3.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870449/; classtype:trojan-activity;sid:84733549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jmart1989/ravscan/main/media/software-v2.1.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870450/; classtype:trojan-activity;sid:84733550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/andrewvalk/multi-region-replication-monitor/main/tests/region-monitor-multi-replication-2.7.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870451/; classtype:trojan-activity;sid:84733551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seba-1aa/ai-trackdown/main/honewort/trackdown_ai_3.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870438/; classtype:trojan-activity;sid:84733538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abd-rachidi07/polyagent-research-intelligence/main/components/pages/research_polyagent_intelligence_v3.5.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870439/; classtype:trojan-activity;sid:84733539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/confirmed-asiancoralsnake620/bobbie-releases/main/megasclere/releases-bobbie-1.7.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870440/; classtype:trojan-activity;sid:84733540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1green9code9ondas9/rag-from-scratch/main/tenendas/rag_scratch_from_3.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870441/; classtype:trojan-activity;sid:84733541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ice24787/maskmyurl-url-obfuscator-a0/main/deflagrator/url-a-mask-my-obfuscator-ur-v1.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870442/; classtype:trojan-activity;sid:84733542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marciojo4080/awesome-channel-foundation-models/main/docs/models-awesome-channel-foundation-2.7.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870443/; classtype:trojan-activity;sid:84733543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/genussolanopterisclassxanthophyceae618/hmnextauto/main/hematein/software_1.0-beta.5.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870444/; classtype:trojan-activity;sid:84733544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeltrin/particle-pioneer-testnet-bot/main/succentor/bot_particle_testnet_pioneer_v1.7.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870432/; classtype:trojan-activity;sid:84733532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lamim82600/sql-mastery-basic-to-advanced/main/04_database_objects/advanced-basic-mastery-to-sq-v1.2.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870433/; classtype:trojan-activity;sid:84733533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sakthi366/avast-internet-security-activated/main/highest/security_avast_activated_internet_v3.8-alpha.1.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870434/; classtype:trojan-activity;sid:84733534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cellularphonedolly511/solana-token-staking-smart-contract/main/programs/tapestry-explorer-statking-contract/contract-solana-smart-staking-token-v1.9-beta.2.zip"; depth:160; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870435/; classtype:trojan-activity;sid:84733535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/antoninfatty836/pm-agile-workflow/main/pm-agile-workflow/workflow_agile_pm_v2.7.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870431/; classtype:trojan-activity;sid:84733531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ezphongdo-cmyk/guardvibe/main/tests/utils/software-v3.2-alpha.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870428/; classtype:trojan-activity;sid:84733528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tekin441/urban_company_clone/main/asker/clone-urban-company-v1.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870429/; classtype:trojan-activity;sid:84733529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sander1023al/replik/main/src/software_v2.5.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870430/; classtype:trojan-activity;sid:84733530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harriottdirty774/supply-chain-monitor/main/coronae/supply_monitor_chain_2.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870426/; classtype:trojan-activity;sid:84733526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/youngermanbeat/dubstep-tag-randomizer/main/dist/dubste_randomizer_ta_3.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870427/; classtype:trojan-activity;sid:84733527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asherfn/acadex-ai-google-deepmind/main/components/deepmind-a-acadex-google-v1.8-alpha.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870425/; classtype:trojan-activity;sid:84733525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heliseacarpelous457/review-rating-predictor/main/dataset/predictor_rating_review_v1.2.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870424/; classtype:trojan-activity;sid:84733524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satyaa758/devtoolbox/main/public/toolbox-dev-v3.8-beta.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870423/; classtype:trojan-activity;sid:84733523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/royer234/backapp/main/web/src/components/templates/back-app-1.8.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870422/; classtype:trojan-activity;sid:84733522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ec21153/fastip.js/main/demo/i_fast_js_v1.4.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870420/; classtype:trojan-activity;sid:84733520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aweawdsdwaofr/agorai_package/main/notebooks/package_agorai_v2.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870421/; classtype:trojan-activity;sid:84733521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marcosviniciomelo/vellium/main/src/features/software-3.9.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870419/; classtype:trojan-activity;sid:84733519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/layneformalized225/ai-cofounder/main/skills/product-led-sales/references/cofounder_ai_2.7.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870417/; classtype:trojan-activity;sid:84733517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/romualdtats/claude-code-best-practices/main/public/images/builder-claude-code/claude-code-practices-best-3.1.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870418/; classtype:trojan-activity;sid:84733518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peti3619/tic-tac-toe/main/public/tac_toe_tic_2.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870412/; classtype:trojan-activity;sid:84733512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kemalyaa/webinar-session-jwt/main/src/jwt_session_webinar_1.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870413/; classtype:trojan-activity;sid:84733513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invertible-statue269/colign/main/proto/apitoken/software-1.0.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870414/; classtype:trojan-activity;sid:84733514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aditemmet3651/data-fusion-top-60/main/supineness/top-data-fusion-2.9.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870415/; classtype:trojan-activity;sid:84733515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenneonn/javascript-tetris/master/src/js/javascript-tetris-v2.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870416/; classtype:trojan-activity;sid:84733516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sfddsfdsfw/atlas-returns-for-woocommerce/main/freemius/templates/forms/returns-woocommerce-for-atlas-1.1-alpha.5.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870400/; classtype:trojan-activity;sid:84733500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hensr39-cpu/openclaw-knowledge-distiller/main/tests/openclaw_distiller_knowledge_v1.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870401/; classtype:trojan-activity;sid:84733501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/andrewmarak/oviro-storefront-next/main/src/app/next-api/order/byinvoiceid/[invoiceid]/storefront-next-oviro-2.0.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870402/; classtype:trojan-activity;sid:84733502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saeedsq3r/ai-agent-evolution/main/heterosiphonales/agent-a-evolution-1.9-beta.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870403/; classtype:trojan-activity;sid:84733503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cartierseps/octopus-parallel/main/calyculus/octopus_parallel_3.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870404/; classtype:trojan-activity;sid:84733504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahop15/artek-homepage/main/src/pages/services/consultancy/project/data/seo/en/homepage_artek_3.8.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870405/; classtype:trojan-activity;sid:84733505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vitalizationgenusdioon476/image-auditor/main/docs/images/image-auditor-2.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870406/; classtype:trojan-activity;sid:84733506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salgrow/home-dashboard/main/views/dashboard-home-2.7-beta.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870407/; classtype:trojan-activity;sid:84733507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drowningchip2025/sentinelpy/main/templates/sentinel_py_2.7-beta.1.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870408/; classtype:trojan-activity;sid:84733508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gothgirl0/ai-agent-team/main/examples/ai_team_agent_v3.0.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870409/; classtype:trojan-activity;sid:84733509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/persontoperson-ptah935/horde/main/src/software_v1.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870410/; classtype:trojan-activity;sid:84733510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/preparebuddyy/n8n-self-hosted/main/diagrammatic/hosted-n-self-v2.9-beta.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870411/; classtype:trojan-activity;sid:84733511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gmldyd0423/our-personas/main/scripts/our-personas-v3.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870394/; classtype:trojan-activity;sid:84733494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dubious-pinetum918/clix/main/clix/mcp/software-v2.1-beta.3.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870395/; classtype:trojan-activity;sid:84733495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryzax1507/yun/main/maeandriniform/software_v2.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870396/; classtype:trojan-activity;sid:84733496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saddamansa/timeduration-cpp/master/cmake/timeduration-cpp-v2.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870397/; classtype:trojan-activity;sid:84733497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roderigoambiguous332/microwarp/main/strangurious/warp-micro-v2.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870398/; classtype:trojan-activity;sid:84733498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rutgercurtainless662/tsexpress/main/docs/software-3.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870399/; classtype:trojan-activity;sid:84733499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rookiester/rugpull-scam-token-detection/main/src/checks/token-scam-detection-rugpull-3.5.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870391/; classtype:trojan-activity;sid:84733491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hampto7114/detect-skill/main/arlene/detect_skill_v1.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870392/; classtype:trojan-activity;sid:84733492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/janiyak/pystrict-strict-python/main/peskiness/strict_py_python_strict_v2.6-beta.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870393/; classtype:trojan-activity;sid:84733493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blaynadams50-cyber/javascriptarmor/main/tutorial/javascript_armor_v3.9.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870388/; classtype:trojan-activity;sid:84733488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mirannonarbitrable290/agentic-kaggle-skill/main/references/skill-kaggle-agentic-v1.4-alpha.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870389/; classtype:trojan-activity;sid:84733489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cheese23456/ai-based_stock_analysis_and_portfolio_optimisation/main/urochordal/based_portfolio_analysis_optimisation_a_stock_and_3.4.zip"; depth:137; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870390/; classtype:trojan-activity;sid:84733490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marfiz1006/react-macbook-landing/main/src/components/three/react_macbook_landing_v3.3.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870387/; classtype:trojan-activity;sid:84733487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/felipedeso7za4444/scientific-thinking-general/main/agents/thinking-scientific-general-1.7.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870383/; classtype:trojan-activity;sid:84733483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arunachala353/cc-usage-elink/main/foreman/usage_cc_elink_2.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870384/; classtype:trojan-activity;sid:84733484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rehandzz/gitflow-in-azure-devops/main/aliases/flow/azure_ops_gitflow_dev_in_v2.8.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870385/; classtype:trojan-activity;sid:84733485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inc0mmon/conditionals/main/sources/conditionals_v3.8.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870381/; classtype:trojan-activity;sid:84733481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shahi405/enkastela/main/fuzz/fuzz_targets/software_v3.0.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870382/; classtype:trojan-activity;sid:84733482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bkr-57/symfony-ux-skills/main/skills/turbo/skills_ux_symfony_v2.0.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870379/; classtype:trojan-activity;sid:84733479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/babaannekatledici/intentguard/main/detection/__pycache__/software-v1.7.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870380/; classtype:trojan-activity;sid:84733480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saidulkarimayas/ai_trading_bot_ethereum/main/chorologist/a-tradin-bo-ethereum-v2.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870373/; classtype:trojan-activity;sid:84733473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hasfo/deepsec/main/cytogamy/software_v2.9.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870374/; classtype:trojan-activity;sid:84733474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/katerinelimae/myntra-reviews-scraper/main/phobist/myntra-scraper-reviews-2.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870375/; classtype:trojan-activity;sid:84733475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chigyel/claude-cs/main/examples/cs-claude-v1.0.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870376/; classtype:trojan-activity;sid:84733476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shr1324/orpheus-tts-docker/main/additional_inference_options/watermark_audio/docker_tts_orpheus_1.3.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870377/; classtype:trojan-activity;sid:84733477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/igrej7083/infinite-scroll/main/resources/infinite-scroll-2.0.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870378/; classtype:trojan-activity;sid:84733478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joewaks/stats-strided-distances-dsquared-euclidean/main/benchmark/c/dsquared_distances_strided_euclidean_stats_v2.2.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870362/; classtype:trojan-activity;sid:84733462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wei891127/clsx-react/main/src/clsx_react_v3.4.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870363/; classtype:trojan-activity;sid:84733463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/related-lysenko8190/meetscribe/main/src/components/custom/software-2.0.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870364/; classtype:trojan-activity;sid:84733464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sebasg-19/anticrack/main/beta_stage/software_3.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870365/; classtype:trojan-activity;sid:84733465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/therbl/20260113230706-goldendict/main/docs/goldendict_v2.9-beta.2.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870366/; classtype:trojan-activity;sid:84733466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onnvvr/umbrella-dotaui/main/inextirpable/ui_umbrella_dota_2.4-alpha.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870367/; classtype:trojan-activity;sid:84733467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amin350839/pentest-automation/main/tireroom/pentest-automation-v1.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870368/; classtype:trojan-activity;sid:84733468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sagarsangani/browsercluster/main/app/core/cluster-browser-v3.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870369/; classtype:trojan-activity;sid:84733469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaquelynnarcotized946/geopolitics_finance_dashboard/main/src/pages/api/webhooks/finance-geopolitics-dashboard-1.3.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870370/; classtype:trojan-activity;sid:84733470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/divine-myositistrichinosa310/blog-writer_mcp/main/blogwriter_mcp/blog-mcp-writer-2.7-alpha.3.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870371/; classtype:trojan-activity;sid:84733471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ellaestrera2510/atlantis-word-processor-latest-patch/main/postgrippal/patch-word-atlantis-latest-processor-v1.3.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870372/; classtype:trojan-activity;sid:84733472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psychological-ruble517/homeassistant-claude-kit/main/equaling/claude-homeassistant-kit-2.5.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870358/; classtype:trojan-activity;sid:84733458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wyllkirby/simphish/main/garse/phish-sim-v1.9.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870359/; classtype:trojan-activity;sid:84733459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lwewaw123/developershub-datascience-analytics_internship-task1/main/nondisarmament/data_science_developers_analytics_tas_hub_internship_v1.8.zip"; depth:145; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870360/; classtype:trojan-activity;sid:84733460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thematic-blacksea501/llm-council-master-free/main/llm-council-master/backend/utils/llm-council-free-master-1.7.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870361/; classtype:trojan-activity;sid:84733461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/devjinah/collaborative-book-recommender/main/client/collaborative-book-recommender-v3.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870354/; classtype:trojan-activity;sid:84733454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/talhagadbade/inbox-archeology/main/output/inbox-archeology-v3.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870355/; classtype:trojan-activity;sid:84733455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aikih9831/dexbar/main/triorchism/bar_dex_2.0-alpha.1.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870356/; classtype:trojan-activity;sid:84733456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/biggerback/tls_fingerprint_db/main/tls_json/tls_fingerprint_db_3.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870357/; classtype:trojan-activity;sid:84733457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahanabee/google-news-scraper/main/google-news-api-scraper/data/news-scraper-google-v2.2-beta.2.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870353/; classtype:trojan-activity;sid:84733453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sweetpotatowhiteflyfloridagallinule681/agwasuri-v2/main/unchambered/agwasuri-v2-2.0.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870351/; classtype:trojan-activity;sid:84733451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sarthakdalvi31/nextjs-enterprise-architecture/main/charkha/enterprise-nextjs-architecture-v3.8.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870352/; classtype:trojan-activity;sid:84733452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danny50143/google_ai_examples/main/malacophilous/ai_google_examples_v3.9.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870345/; classtype:trojan-activity;sid:84733445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/framex12/chroniclecore-architecture/main/architecture/architecture_core_chronicle_v2.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870346/; classtype:trojan-activity;sid:84733446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tonispousta/cloudinsight-extractor/main/cloudinsight_extractor/extractor_cloudinsight_v3.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870347/; classtype:trojan-activity;sid:84733447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matheusscsp/lite-cv-ai/main/conductible/ai_cv_lite_v3.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870348/; classtype:trojan-activity;sid:84733448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unsharpened-genusherpestes96/ztrmpad/main/constitutionality/z-pad-trm-2.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870344/; classtype:trojan-activity;sid:84733444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amina123-4/hotel-booking-cancellation-analysis-and-revenue-optimization/main/data/booking_optimization_cancellation_revenue_analysis_and_hotel_v3.1.zip"; depth:152; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870342/; classtype:trojan-activity;sid:84733442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vaskesvo5321/claude-zeroclaw/main/src/claude-zeroclaw-v2.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870343/; classtype:trojan-activity;sid:84733443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eyeklass/machine-learning-practice-sets/main/outrig/sets_learning_practice_machine_1.8.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870337/; classtype:trojan-activity;sid:84733437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mutagenic-ballast630/url-shortener-fastapi/main/app/services/url_fastapi_shortener_3.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870338/; classtype:trojan-activity;sid:84733438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/funeralvalue508/crossdevicetracker.desktop/main/unheretical/device_desktop_cross_tracker_v2.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870339/; classtype:trojan-activity;sid:84733439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kimmy1985/lifegrid/master/tests/lifegrid-1.8.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870340/; classtype:trojan-activity;sid:84733440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gvishweshwar/marketing-prompts/main/swipe-files/prompts_marketing_1.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870328/; classtype:trojan-activity;sid:84733428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7rap/robot-arm-kinematics/main/rrbot_3dof_description/test/arm_robot_kinematics_v2.3.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870329/; classtype:trojan-activity;sid:84733429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alex11rom/ai-quotation-intelligence-microservice/main/app/quotation_intelligence_microservice_ai_3.8.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870330/; classtype:trojan-activity;sid:84733430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryzecx/vulscanner/main/utils/software-1.6.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870331/; classtype:trojan-activity;sid:84733431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cotyloidcavitybutterheadlettuce306/wifi-heatmap/main/static/heatmap-wifi-3.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870332/; classtype:trojan-activity;sid:84733432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lugames125/shared-configs/main/packages/prettier-config/shared-configs-1.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870333/; classtype:trojan-activity;sid:84733433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rotss2/page-agent/main/packages/website/agent-page-v1.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870334/; classtype:trojan-activity;sid:84733434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dokercik/mag-safe-finder/main/mag_safe_finder/safe-finder-mag-1.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870335/; classtype:trojan-activity;sid:84733435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kubagd/bardacle/main/assets/software_v2.8.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870336/; classtype:trojan-activity;sid:84733436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/galeristore88id-ctrl/bitbucket-cli/main/docs/plans/bitbucket_cli_1.3-alpha.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870324/; classtype:trojan-activity;sid:84733424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/julesa6664/claude-design-x-figma/main/crisp/design_figma_claude_x_v3.6.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870325/; classtype:trojan-activity;sid:84733425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lizettedoubtful741/linear-brain/main/src/server/brain-linear-2.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870326/; classtype:trojan-activity;sid:84733426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suli99/options-scanner/main/src/options_scanner_2.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870327/; classtype:trojan-activity;sid:84733427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/limediseasespirochetebrazilnuttree326/steam-fps-estimator-beta-version/main/sootless/fp_steam_beta_version_estimator_1.4.zip"; depth:125; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870323/; classtype:trojan-activity;sid:84733423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/swapnil604/wildwing-icicle/main/images/icicle_wildwing_3.7.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870320/; classtype:trojan-activity;sid:84733420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prakash6381/rarch/main/src/software_1.1-alpha.4.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870321/; classtype:trojan-activity;sid:84733421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karterhhgg/javaprogramming/main/function/programming-java-3.8.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870322/; classtype:trojan-activity;sid:84733422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karuri12/taraassistant-public/main/app/public-taraassistant-v2.8.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870319/; classtype:trojan-activity;sid:84733419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/james221-a3rt/ivebench/main/metrics/compliance/videoclipxl_utils/vision_encoder/ive-bench-3.0.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870314/; classtype:trojan-activity;sid:84733414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/giro03k/claude-statistical-analysis-skill/main/references/statistical_analysis_claude_skill_1.7.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870315/; classtype:trojan-activity;sid:84733415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ironman07/building-ai-agents-part-3-scaling-collaboration-and-advanced-reasoning/main/bedquilt/building-reasoning-scaling-part-agents-and-a-collaboration-advanced-v1.6.zip"; depth:172; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870316/; classtype:trojan-activity;sid:84733416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hbkhamza/ittea/main/scripts/core/software-3.9.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870317/; classtype:trojan-activity;sid:84733417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/veasna-17/mlops-project-template/main/infrastructure/k8s/mlops-project-template_v2.5-beta.1.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870318/; classtype:trojan-activity;sid:84733418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shifting-superfecundation669/cloud-code/main/src/components/cloud-code-3.6.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870313/; classtype:trojan-activity;sid:84733413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/straightrazorgagarin889/sqlens/main/src/utils/software-v3.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870310/; classtype:trojan-activity;sid:84733410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustermuster5432-ux/openclawctl/main/platinization/software_2.3-alpha.2.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870311/; classtype:trojan-activity;sid:84733411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chikochulu/nova-glassmorphism-nextjs-template/main/src/components/nextjs_glassmorphism_template_nova_1.4.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870312/; classtype:trojan-activity;sid:84733412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armmammothermography417/contextos/main/decolorize/os-context-3.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870308/; classtype:trojan-activity;sid:84733408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/taxerpsychodid420/mdzilla/main/test/docs/.docs/public/software_3.6.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870309/; classtype:trojan-activity;sid:84733409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/resourceless-greatwhiteheron884/ai-interview-simulator/main/src/interview-a-simulator-1.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870307/; classtype:trojan-activity;sid:84733407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chunyu0208/lpd/main/scripts/software_1.1.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870304/; classtype:trojan-activity;sid:84733404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/turnleafbook7768/db9-wiki/main/src/commands/wiki-db-v1.4-beta.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870305/; classtype:trojan-activity;sid:84733405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labradoryeshivah6794/vidmuncher/main/assets/muncher_vid_v1.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870302/; classtype:trojan-activity;sid:84733402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2-4-0-8/palindrome-js/main/formularism/palindrome-js-v3.0.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870303/; classtype:trojan-activity;sid:84733403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryanpadilha1/catopalian_science/main/src/topalian-science-ca-3.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870296/; classtype:trojan-activity;sid:84733396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/overproud-amenorrhea467/attn_res/main/attn_res/res_attn_1.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870297/; classtype:trojan-activity;sid:84733397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cresent16/humanize/main/unfetched/software_v1.2.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870298/; classtype:trojan-activity;sid:84733398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/segawonig/go-api-explorer/main/static/api_explorer_go_1.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870299/; classtype:trojan-activity;sid:84733399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaobufanalog/liveness-check/main/cmd/config/liveness-check-2.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870300/; classtype:trojan-activity;sid:84733400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djevaldo/amazon-prices-deals/main/recognosce/amazon-deals-prices-2.0-beta.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870301/; classtype:trojan-activity;sid:84733401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/picleskun/chrome-setup/main/saiid/setup_chrome_1.0.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870295/; classtype:trojan-activity;sid:84733395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/taptastico/typescript-starter/main/src/types/type_script_starter_v3.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870293/; classtype:trojan-activity;sid:84733393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peruzzo3265/clawtrap/main/tests/trap-claw-v1.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870294/; classtype:trojan-activity;sid:84733394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xxpolarpinzxx/whir/main/preguarantor/software-v2.0.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870289/; classtype:trojan-activity;sid:84733389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aneek2004/t3rn-airdrop-bot/main/inimically/rn_airdrop_bot_3.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870290/; classtype:trojan-activity;sid:84733390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rileypriddle-sketch/stackup/main/app/software-v1.5.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870291/; classtype:trojan-activity;sid:84733391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/randomguy312/gemini3-pro-how-to-play/main/commerceless/to_how_pro_play_gemini_v1.0-alpha.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870292/; classtype:trojan-activity;sid:84733392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bradox54/generative-ai-projects/main/corradial/a_generative_projects_1.7.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870285/; classtype:trojan-activity;sid:84733385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krungkrungs/remix-jam-mk2/main/app/mk_jam_remix_v3.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870286/; classtype:trojan-activity;sid:84733386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blazej2005/rebootx/main/src/rebootx-v2.4-beta.5.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870287/; classtype:trojan-activity;sid:84733387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suleman54629/openchaos/main/src/lib/software-v1.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870288/; classtype:trojan-activity;sid:84733388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sorbussitchensisdonorcard867/claude-code/main/semiquadrate/code_claude_v1.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870283/; classtype:trojan-activity;sid:84733383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ithony77/lab_risco_quant/main/src/risco-lab-quant-2.7.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870284/; classtype:trojan-activity;sid:84733384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/concettinaprofitable685/autoloop/main/src/loop_auto_1.0-alpha.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870282/; classtype:trojan-activity;sid:84733382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kumarpi3052/detektor/main/src/detektor/core/pipeline/software-v2.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870281/; classtype:trojan-activity;sid:84733381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da-vid123/---/main/k/software_v2.1.zip"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870277/; classtype:trojan-activity;sid:84733377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbxh6452/-arp-spoofing-detection-active-injection-technique/main/docs/technique_spoofing_ar_injection_detection_active_v3.8-alpha.3.zip"; depth:136; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870278/; classtype:trojan-activity;sid:84733378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/subzeira/steal-react-component/main/templates/nextjs/components/component-steal-react-1.0-beta.2.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870279/; classtype:trojan-activity;sid:84733379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reluctant-greatsmokymountains869/operational-analytics-portfolio/main/images/portfolio-operational-analytics-v3.9.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870276/; classtype:trojan-activity;sid:84733376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amineeng/scraping-browser/main/tuggingly/scraping_browser_v2.0.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870273/; classtype:trojan-activity;sid:84733373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syntactic-orleanism949/logal-rag/main/unoperatic/logal_rag_v2.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870274/; classtype:trojan-activity;sid:84733374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/biancamoronic889/novastats/main/screenshots/software-1.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870275/; classtype:trojan-activity;sid:84733375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saintneedem/claude-md-templates/main/global/templates-md-claude-v2.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870272/; classtype:trojan-activity;sid:84733372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cris281/concurrent-traffic-light-simulation/main/data/light-traffic-simulation-concurrent-v2.5.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870267/; classtype:trojan-activity;sid:84733367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cupable/duola/main/src/software-v1.0.zip"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870268/; classtype:trojan-activity;sid:84733368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lookingforvirus/fastapi_auto_routes/main/convertise/routes_auto_fastapi_v2.0.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870269/; classtype:trojan-activity;sid:84733369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/semanurnakas/online-food-delivery-page/main/totemist/food-online-page-delivery-1.6-beta.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870270/; classtype:trojan-activity;sid:84733370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/diuli4587/vulk-mcp-server/main/chatgpt/vulk_mcp_server_v3.1.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870271/; classtype:trojan-activity;sid:84733371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laudit/barcelona-accessibility-intelligence-system/main/notebooks/barcelona-system-intelligence-accessibility-1.3.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870264/; classtype:trojan-activity;sid:84733364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liodlido3-blip/pyvizast/main/backend/project_analyzer/py-ast-viz-2.0.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870265/; classtype:trojan-activity;sid:84733365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eldino162/reme/main/reme/core/llm/re-me-v1.5.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870266/; classtype:trojan-activity;sid:84733366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/farbod148/seo-research-mcp/main/src/mcp_research_seo_v2.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870259/; classtype:trojan-activity;sid:84733359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/singhalesebradycardia99/polymarket-copy-trade-bot/main/frontend/src/api/copy-polymarket-bot-trade-3.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870260/; classtype:trojan-activity;sid:84733360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lime0moss/godu/main/internal/model/software_2.1.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870262/; classtype:trojan-activity;sid:84733362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/michae6543/ot-crm/main/backend/src/util/crm_o_v2.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870263/; classtype:trojan-activity;sid:84733363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bharatji009/deciflow-frontend/main/tests/e2e/frontend-deciflow-3.6-beta.4.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870256/; classtype:trojan-activity;sid:84733356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/umarwaqas513/breakout-game/main/metaphonize/breakout_game_v1.8-beta.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870257/; classtype:trojan-activity;sid:84733357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aaddii09/llm-eval-harness/main/data/harness-llm-eval-3.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870258/; classtype:trojan-activity;sid:84733358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/judeaddison/dreamstyle/main/assets/style_dream_3.7.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870251/; classtype:trojan-activity;sid:84733351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabrielpimento/gam-config-manager/main/backend/app/gam-config-manager-3.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870252/; classtype:trojan-activity;sid:84733352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abwor9658/social-media-skills/main/skills/content-strategy-sms/evals/media-skills-social-v3.8.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870253/; classtype:trojan-activity;sid:84733353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/requiem232/weakpass-cli/main/src/cli-weakpass-v2.2.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870254/; classtype:trojan-activity;sid:84733354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juliettaspecialistic335/addernet/main/addernet/adder-net-v2.6.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870255/; classtype:trojan-activity;sid:84733355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thepixel4527/codex-planr/main/public/codex_planr_v2.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870248/; classtype:trojan-activity;sid:84733348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nirjalneupane762/linkedin-bot/main/src/components/in-linked-bot-3.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870249/; classtype:trojan-activity;sid:84733349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quesovfx/awesome-shortcuts/main/coagent/awesome_shortcuts_v2.8-alpha.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870250/; classtype:trojan-activity;sid:84733350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45narendra/cloud-sdk-1771917529-4/main/cystous/sdk_cloud_v3.7-beta.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870244/; classtype:trojan-activity;sid:84733344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/magdysayed/laravel-sdk/main/.phpstan.cache/cache/phpstan/be/49/sdk_laravel_3.8.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870245/; classtype:trojan-activity;sid:84733345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuxkxtc/portofolio-dark-tency/main/indigitamenta/tency_dark_portofolio_v1.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870246/; classtype:trojan-activity;sid:84733346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riconcayy123/mexc-private-api/main/examples/listing/mexc-private-api-v2.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870247/; classtype:trojan-activity;sid:84733347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cloudie-w/payload-kit/main/sql-injection/payload_kit_v2.0.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870243/; classtype:trojan-activity;sid:84733343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/indu58/awesome-value-investing/main/ambagiosity/value-awesome-investing-1.7-alpha.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870241/; classtype:trojan-activity;sid:84733341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhanishh985/resourcepoison/main/app/src/main/res/mipmap-xxxhdpi/poison-resource-v3.8.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870242/; classtype:trojan-activity;sid:84733342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anggipratama17/triton-accelerated-attention/main/results/accelerated_triton_attention_2.8.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870240/; classtype:trojan-activity;sid:84733340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/instant-restharrow443/aircast/main/src/air-cast-1.5.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870237/; classtype:trojan-activity;sid:84733337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blinddistribution724/httpx/main/mistranscript/software_3.3.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870238/; classtype:trojan-activity;sid:84733338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filariasistrichoglossusmoluccanus49/alvus/main/twanginess/software_2.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870239/; classtype:trojan-activity;sid:84733339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mystic-backstroker315/flowcus/main/crates/flowcus-storage/src/codec/software-3.8-beta.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870233/; classtype:trojan-activity;sid:84733333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adri3l-r3nan/cognify-skills/main/.github/skills/meeting-agenda-optimizer/cognify-skills-v1.3-beta.2.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870234/; classtype:trojan-activity;sid:84733334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/21mtm3012mahi/karan-devfolio/main/public/devfolio_karan_3.6-beta.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870235/; classtype:trojan-activity;sid:84733335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/out-bloodspavin173/openalex-skill/main/skills/openalex/skill-openalex-v2.5.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870236/; classtype:trojan-activity;sid:84733336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomwinc5128/steam-tools/main/tools/tools_steam_3.6-beta.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870226/; classtype:trojan-activity;sid:84733326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/floating-browsing3845/pi-monitor/main/outsentry/pi-monitor-2.8.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870227/; classtype:trojan-activity;sid:84733327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/souravchouhan001/insane-plants/main/esphome/insane_plants_3.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870228/; classtype:trojan-activity;sid:84733328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/li5iftyyy/time_help/main/code/bin/release/net472/help-time-1.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870229/; classtype:trojan-activity;sid:84733329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ghoruisubham57/obscurart/main/include/rt_obscura_v1.3-beta.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870230/; classtype:trojan-activity;sid:84733330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yasuothezed/clawdchat-analysis/main/references/analysis_clawdchat_1.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870231/; classtype:trojan-activity;sid:84733331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maiblemodulated493/executive-ai-core/main/marrowish/executive-ai-core-v3.3-alpha.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870232/; classtype:trojan-activity;sid:84733332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abzsalik/programmersjoke_and_quotegenerator/main/app/templates/generator_quote_joke_programmers_and_2.4.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870222/; classtype:trojan-activity;sid:84733322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/proportionable-plaguespot199/novel-workflow/main/templates/state/genres/hongkong-crime/workflow_novel_v2.8-beta.3.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870223/; classtype:trojan-activity;sid:84733323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wawa1154/kagi-skills/main/kagi-search/kagi-skills-v1.8.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870224/; classtype:trojan-activity;sid:84733324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pedrocouto839/nano-banana-pro-prompts-recommend-skill/main/references/nano-recommend-pro-prompts-banana-skill-v2.3.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870225/; classtype:trojan-activity;sid:84733325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spickandspan-nosher485/fcf-viewer/main/fcf_viewer/fcf-viewer-2.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870216/; classtype:trojan-activity;sid:84733316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedmagood/cpu-slm/main/src/cpu_slm_2.5-beta.2.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870217/; classtype:trojan-activity;sid:84733317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loonmorti/promptshield/main/scripts/software-v2.6-beta.4.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870218/; classtype:trojan-activity;sid:84733318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riosmagr/openclaw-eval/main/methodology/eval-openclaw-v1.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870219/; classtype:trojan-activity;sid:84733319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frenyermmlmmk/claude-cognitive/main/templates/cognitive-claude-2.3-alpha.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870220/; classtype:trojan-activity;sid:84733320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rodrigorodriguezilustra/awesome-gear-protocol/main/hispanic/gear-protocol-awesome-2.6-beta.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870221/; classtype:trojan-activity;sid:84733321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tresonn2318/electron-fetch/main/example/fetch_electron_1.6.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870213/; classtype:trojan-activity;sid:84733313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saltplainjobaction503/sub-store-workers/main/ceroplasty/sub_workers_store_3.8.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870214/; classtype:trojan-activity;sid:84733314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sakyu7/webkit-uaf-angle-oob-analysis/main/analysis/ua_kit_oo_web_analysis_angl_2.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870215/; classtype:trojan-activity;sid:84733315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pattarpon/pokescan/main/launcher/scan_poke_v3.9-beta.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870211/; classtype:trojan-activity;sid:84733311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ffhvcvjh/dehashed-password-breach-scanner/main/hemotherapeutics/de-hashed-scanner-password-breach-3.4.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870212/; classtype:trojan-activity;sid:84733312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leejah/ai-context-kit/main/tests/context-ai-kit-2.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870209/; classtype:trojan-activity;sid:84733309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adewijaya89/white-paper-the-unified-navigation-formula-unf-/main/myelitic/the_white_un_navigation_unified_paper_formula_v1.4.zip"; depth:129; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870210/; classtype:trojan-activity;sid:84733310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xfoxusx/arduino-joystick-and-servo-control/main/lection/servo-arduino-control-and-joystick-1.1.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870205/; classtype:trojan-activity;sid:84733305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chromatic-sac309/awesome-trending-repos/main/scripts/awesome_trending_repos_v2.9-beta.5.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870206/; classtype:trojan-activity;sid:84733306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yamen1223/icon-clay-studio/main/hooks/icon-studio-clay-1.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870207/; classtype:trojan-activity;sid:84733307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nekomimiyu/aws-ebs-snapshot-cleanup/main/exhausted/snapshot-cleanup-aws-ebs-1.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870208/; classtype:trojan-activity;sid:84733308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pearl152/disney-minecraft-wave-dome-landing-page/main/src/landing_minecraft_dome_page_disney_wave_1.2.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870203/; classtype:trojan-activity;sid:84733303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peckem/opteamus/main/backend/opteamus/opteamus/dtos/team-us-op-v2.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870204/; classtype:trojan-activity;sid:84733304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/karayi2022/mediafetch/main/assets/software-1.4.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870200/; classtype:trojan-activity;sid:84733300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daleneanderthal2025/data-collection-projects/main/doctolib-scraping/projects_collection_data_v1.7-beta.1.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870199/; classtype:trojan-activity;sid:84733299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ghaniyanawaz/ghsa-skill-builder/main/passover/builder_ghsa_skill_v3.0-alpha.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870195/; classtype:trojan-activity;sid:84733295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neptun2202/lunafirpay/main/plugins/fubei/fir-pay-luna-v1.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870196/; classtype:trojan-activity;sid:84733296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deracz/ryexploit/main/elastin/ry_exploit_v2.5.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870197/; classtype:trojan-activity;sid:84733297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/telephoneboxbrouhaha811/opl-theme-deckyos/main/subsecive/os-op-theme-decky-3.9.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870198/; classtype:trojan-activity;sid:84733298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quillantinny41/binance/main/neighbored/software_2.4-beta.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870193/; classtype:trojan-activity;sid:84733293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jacquelineinquisitive996/pragmata-reframework/main/reframework/pragmata_reframework_v3.6.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870194/; classtype:trojan-activity;sid:84733294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gratianahydrokinetic908/adrian/main/frontend/components/software_v1.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870191/; classtype:trojan-activity;sid:84733291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carlososoriopulgar/agent-kernel/main/notes/agent_kernel_3.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870192/; classtype:trojan-activity;sid:84733292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shivvvanshh/command-line-to-do-manager-python-/main/ziphius/do_to_line_python_command_manager_v3.3.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870189/; classtype:trojan-activity;sid:84733289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ljkormo/octra-labs-client-installation-bot/main/unpromised/labs-bot-installation-octra-client-v1.0.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870190/; classtype:trojan-activity;sid:84733290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ivanhoemaker/telegram-multifunctional-panel/main/src/utils/telegram-multifunctional-panel-v1.6.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870181/; classtype:trojan-activity;sid:84733281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dalux6960/gingiris-user-interview/main/references/gingiris-interview-user-v3.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870182/; classtype:trojan-activity;sid:84733282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkkin99/sunderedcore/main/node_modules/normalize-path/software-v2.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870183/; classtype:trojan-activity;sid:84733283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miguel974-bit/stork-auto-bot/main/quatrocentism/auto_stork_bot_v2.9-alpha.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870184/; classtype:trojan-activity;sid:84733284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kenzozer/typexperiments/main/src/software_3.8.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870185/; classtype:trojan-activity;sid:84733285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eslan90080/gitnexus/main/gitnexus-cursor-integration/skills/gitnexus-pr-review/git_nexus_1.7.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870186/; classtype:trojan-activity;sid:84733286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erikdwi03/bitrix-cdn/main/nginx/cdn-bitrix-v3.6-beta.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870187/; classtype:trojan-activity;sid:84733287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dilute-hypotension399/echealth/main/cathisma/ec_health_1.9-alpha.3.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870188/; classtype:trojan-activity;sid:84733288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/safiesty/tgbot-d1/main/richesse/t-gbot-v2.0.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870175/; classtype:trojan-activity;sid:84733275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fanirussady/m3-bitlocker-recovery-no-trial/main/triangulid/recovery_bitlocker_no_trial_v1.1.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870177/; classtype:trojan-activity;sid:84733277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vleickzs/claude-conf/main/backlog/conf_claude_1.7.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870178/; classtype:trojan-activity;sid:84733278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/32olaa/reward-scope/main/reward_scope/dashboard/reward_scope_3.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870179/; classtype:trojan-activity;sid:84733279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/firasxp/react-hooks-1771919099-3/main/secreto/hooks-react-2.5-alpha.1.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870180/; classtype:trojan-activity;sid:84733280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/izahamyatim/claude-plugin-fizzy/main/plugins/fizzy_plugin_claude_3.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870174/; classtype:trojan-activity;sid:84733274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manug11/plugin-health-monitor/main/languages/health_monitor_plugin_v2.0.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870171/; classtype:trojan-activity;sid:84733271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sakshiaroskar/agent-openai-assistant/main/app/copilot/copilot-backend/src/test/assistant_openai_agent_v2.9-beta.5.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870172/; classtype:trojan-activity;sid:84733272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyberjhay/openclaw-min-bundle/main/unlaundered/openclaw-bundle-min-v1.2-alpha.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870173/; classtype:trojan-activity;sid:84733273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajnshydv/tiffanydanin/main/munition/software_v2.7.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870168/; classtype:trojan-activity;sid:84733268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k0wt00r/spore/main/desktop_app/backend/software_v1.7.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870169/; classtype:trojan-activity;sid:84733269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kokot-ia/setinvoice-invoicemanagementsystem/main/apps/inventory/migrations/invoice_set_management_system_v3.3.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870170/; classtype:trojan-activity;sid:84733270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/borjani1577/claude-office-skills/main/claude-in-excel/audit-xls/office-skills-claude-v2.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870165/; classtype:trojan-activity;sid:84733265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fazalr714/neurorvq-rs/main/src/bin/neurorvq-rs-1.8.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870166/; classtype:trojan-activity;sid:84733266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/theyfwjays/rust-imgconv/main/test_output/08_grayscale/rust-imgconv-v1.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870164/; classtype:trojan-activity;sid:84733264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chenuthsl/anunnak/main/prelude/software-2.1.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870162/; classtype:trojan-activity;sid:84733262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1342342342fsdfsdfsdfsd/accidenta-fullstack/main/frontend/src/services/accidenta-fullstack_1.4.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870163/; classtype:trojan-activity;sid:84733263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fendidrip/design-resources-project/main/js/project-resources-design-v2.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870159/; classtype:trojan-activity;sid:84733259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhruv-sharma10/fouroversix/main/src/fouroversix/csrc/quantize/software_v1.9.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870160/; classtype:trojan-activity;sid:84733260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/verathorn/likhis/main/internal/exporters/software_3.2.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870161/; classtype:trojan-activity;sid:84733261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flareignis/sqlbot/main/frontend/src/views/chat/component/bot_sql_3.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870157/; classtype:trojan-activity;sid:84733257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aniketpaul44/lextex-homelab/main/services/user/homelab-lextex-2.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870158/; classtype:trojan-activity;sid:84733258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toastysale-v2/geminishoppingagent/main/amplify/.config/agent-shopping-gemini-v2.2.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870155/; classtype:trojan-activity;sid:84733255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dezz05/aurasdk/main/docs/sdk-aura-3.8-beta.4.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870156/; classtype:trojan-activity;sid:84733256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sarcosomebankcheck694/coordinode/main/crates/coordinode-search/src/software-v3.8-alpha.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870152/; classtype:trojan-activity;sid:84733252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grhhrhdtdtdyd/z-transformers/main/z-transformers/legacy/transformers_z_2.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870153/; classtype:trojan-activity;sid:84733253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/consequential-stateswoman97/openclaw-pwnkit/main/core/claw-pwn-open-kit-1.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870154/; classtype:trojan-activity;sid:84733254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamevoid2366/authcrack-v8/main/characteristically/auth-crack-v-2.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870142/; classtype:trojan-activity;sid:84733242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pallavi-borra/context-engine/main/context-example/identity/context_engine_v1.5-alpha.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870143/; classtype:trojan-activity;sid:84733243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeriatah/pc-game-booster/main/jackstone/game_p_booster_1.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870144/; classtype:trojan-activity;sid:84733244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/example69420/splintr/main/python/splintr_v2.0-alpha.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870145/; classtype:trojan-activity;sid:84733245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eduardo3987/pmcc/main/core/__pycache__/software_3.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870146/; classtype:trojan-activity;sid:84733246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/talhabinkhalid/slack-workflow-automation-builder/main/sloka/workflow-automation-slack-builder-v1.5-alpha.1.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870148/; classtype:trojan-activity;sid:84733248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/decurved-agreement62/humanizalo/main/references/software_1.3-beta.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870150/; classtype:trojan-activity;sid:84733250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vasilisharp444/autoforge/main/examples/auto_forge_v3.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870151/; classtype:trojan-activity;sid:84733251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/algometryorphansite609/aws-lift-shift-migration/main/terraform/modules/dms/migration_aws_lift_shift_2.4.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870139/; classtype:trojan-activity;sid:84733239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pablodmzz7/pai/main/pai_directory/voice-server/macos-service/software_1.0.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870140/; classtype:trojan-activity;sid:84733240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dimitrousabbatarian96/dynamic-workers-orchestrator/main/workers/sample-worker/src/dynamic_workers_orchestrator_2.4.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870141/; classtype:trojan-activity;sid:84733241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/macosta88/splunk-dashboard-for-ssh-logs/main/leaderless/ss_dashboard_logs_for_splunk_3.9.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870137/; classtype:trojan-activity;sid:84733237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hankamarvanova/unified-db/main/sources/db_unified_3.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870138/; classtype:trojan-activity;sid:84733238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beggarticksarthurtatum121/reddit-skills/main/skills/reddit-explore/skills-reddit-v1.9.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870134/; classtype:trojan-activity;sid:84733234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armaan29-09-2005/ai-osint-security-analyzer/main/.streamlit/security_a_osin_analyzer_3.9.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870135/; classtype:trojan-activity;sid:84733235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jakobgtag/multi-email-sender/main/src/email_sender_multi_1.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870136/; classtype:trojan-activity;sid:84733236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/relliaj/riftaux/main/unprejudicially/software-v2.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870133/; classtype:trojan-activity;sid:84733233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cfra5680/msregflow/main/data/ms_reg_flow_v1.9.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870130/; classtype:trojan-activity;sid:84733230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isaaciguanre001/chartgenerator-api/main/nuget/pkgbin/api-chartgenerator-2.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870131/; classtype:trojan-activity;sid:84733231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/240iqclips/igl-nav/main/assets/ig-nav-3.5.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870132/; classtype:trojan-activity;sid:84733232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filscorner225/popy/main/scyllaroid/software-v1.2-alpha.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870129/; classtype:trojan-activity;sid:84733229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zidanalata04/workerlysia/main/.claude/software_v1.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870127/; classtype:trojan-activity;sid:84733227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/avishekinvincible/bulk-emails-verifier/main/data/bulk-verifier-emails-v2.7-beta.2.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870128/; classtype:trojan-activity;sid:84733228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ethanj7750/face-anti-spoofing-dataset/main/preterpolitical/face_anti_dataset_spoofing_v2.6.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870126/; classtype:trojan-activity;sid:84733226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luciennestoreyed740/memcached-ir5/main/lenticular/memcached-ir-v3.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870122/; classtype:trojan-activity;sid:84733222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toavinarandrianarivo/scene2chapter-nlp-aligner/main/tests/aligner_chapter_scene_nl_v2.6.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870123/; classtype:trojan-activity;sid:84733223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomerd999/reacti-do/main/backend/src/controllers/do-reacti-1.8.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870124/; classtype:trojan-activity;sid:84733224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/terralerraoffa/yandex-music-streamdeck/main/com.judd1.yandex_music.sdplugin/tools/yandex-music-streamdeck-v3.8.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870125/; classtype:trojan-activity;sid:84733225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rightofactionsyndicalism110/domino/main/policy/puma/puma/model/software-v1.7.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870119/; classtype:trojan-activity;sid:84733219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arcila12/universal-web3-wallet/main/src/provider/web-universal-wallet-2.4.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870120/; classtype:trojan-activity;sid:84733220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/julius0217/claude-code-workflow/main/examples/hooks/code-claude-workflow-3.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870121/; classtype:trojan-activity;sid:84733221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syreniti5667/zabbix-auto-provisioning/main/nerthrus/zabbix_provisioning_auto_v3.2.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870117/; classtype:trojan-activity;sid:84733217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nealsafetyrelated641/news-data-scrapper-for-indian-express-news/main/conspecies/news_for_express_data_scrapper_indian_v2.5.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870109/; classtype:trojan-activity;sid:84733209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/black-hexa/diwali-sales-analysis-using-python/main/basidiophore/analysis-python-using-diwali-sales-v2.7.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870110/; classtype:trojan-activity;sid:84733210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/morriganvictoria3/example-launchdarkly-toolbar-url-overrides/main/untortured/example-launchdarkly-toolbar-url-overrides_v1.2-alpha.3.zip"; depth:137; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870111/; classtype:trojan-activity;sid:84733211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/internationaleundset619/opendsstar/main/tests/agents/utils/star_open_ds_v1.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870112/; classtype:trojan-activity;sid:84733212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/recollective-genuseptatretus377/askproof-skill/main/askproof/references/askproof-skill-v1.2.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870113/; classtype:trojan-activity;sid:84733213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tem123458/web-framework-1771918250-2/main/vestryman/framework-web-3.5-alpha.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870114/; classtype:trojan-activity;sid:84733214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seaseansean/grammar-deep-anki-prompts/main/duotriacontane/prompts_grammar_deep_anki_v1.3-beta.1.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870115/; classtype:trojan-activity;sid:84733215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaisingh001/instagram-ai-faq-order-tracking-chatbot/main/uninterlaced/faq_instagram_ai_tracking_chatbot_order_v3.7.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870116/; classtype:trojan-activity;sid:84733216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leke-adewa/short-video-maker/main/output/maker_short_video_3.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870106/; classtype:trojan-activity;sid:84733206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/demidovalexander1/wsl-ubuntu-gui-setup/main/hyperprism/ws_setup_gu_ubuntu_v1.0.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870107/; classtype:trojan-activity;sid:84733207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spellinfo/sstop/main/internal/software_1.3.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870108/; classtype:trojan-activity;sid:84733208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sking911/priceticker/main/priceticker.xcodeproj/project.xcworkspace/price-ticker-3.5.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870101/; classtype:trojan-activity;sid:84733201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bernardinaunclear949/diabetes-ai-system/main/leakproof/diabetes-ai-system-1.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870102/; classtype:trojan-activity;sid:84733202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ariefalabbasi/mcp-audit/main/src/mcp-audit-1.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870103/; classtype:trojan-activity;sid:84733203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toopbi7829/nfc-movie-library/main/images/movie-nfc-library-v3.0.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870104/; classtype:trojan-activity;sid:84733204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/einherjar99/bggg-skill-taotie/main/references/taotie_bggg_skill_v3.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870105/; classtype:trojan-activity;sid:84733205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/warm-mannalichen723/qclaw-skip-invite/main/assets/qclaw_invite_skip_v3.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870097/; classtype:trojan-activity;sid:84733197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/waleedkhanbaloch/claude-code-safety-net/main/ast-grep/utils/net-claude-code-safety-v3.4.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870098/; classtype:trojan-activity;sid:84733198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k3vin993/atlas/main/src/connectors/software_v3.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870099/; classtype:trojan-activity;sid:84733199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iddi655/nch-photopad-image-no-trial/main/affectedly/nc_photo_trial_image_pad_no_v1.8.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870100/; classtype:trojan-activity;sid:84733200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gavikk/injectscope/main/habitan/scope_inject_3.0.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870094/; classtype:trojan-activity;sid:84733194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/motoneuronrijstafel442/vless-xhttp/main/lib/vless_xhttp_2.1-alpha.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870095/; classtype:trojan-activity;sid:84733195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/axelrod37/macwsbootingguide/main/layout/mac_booting_guide_ws_v1.6.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870096/; classtype:trojan-activity;sid:84733196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/randravishing966/claw-code/main/src/components/permissions/computeruseapproval/claw_code_v2.2.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870092/; classtype:trojan-activity;sid:84733192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/maomaoguo89-star/aurogen/main/aurogen_web/src/assets/software-2.5-alpha.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870093/; classtype:trojan-activity;sid:84733193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibgentle/sql-advance-data-analytics-project/main/datasets/project-sq-advance-data-analytics-v3.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870090/; classtype:trojan-activity;sid:84733190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armcodes/finger-drawing-app/main/pejorism/finger_drawing_app_v2.8.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870089/; classtype:trojan-activity;sid:84733189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/geosaputra/aiverse/main/src/main/java/com/aiverse/aiverse/software-v2.2.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870088/; classtype:trojan-activity;sid:84733188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/janianorthkorean166/claude-code-design-guide/main/maculicole/claude-guide-code-design-3.6.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870083/; classtype:trojan-activity;sid:84733183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rahul1406/springboot-template/main/src/main/java/top/sharehome/springbootinittemplate/aop/studydemo/normal/beanaop/service/springboot_template_3.1.zip"; depth:151; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870084/; classtype:trojan-activity;sid:84733184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/egrwgre/y2jb-updater/main/gynecopathy/y-updater-jb-3.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870085/; classtype:trojan-activity;sid:84733185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ringopii/mushell/main/app/http/software_v1.5.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870086/; classtype:trojan-activity;sid:84733186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/monke1/ragcraft/main/ragcraft/software-1.9.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870087/; classtype:trojan-activity;sid:84733187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unsweetened-journalbox528/aeon-radio-drama/main/scripts/drama-radio-aeon-3.1.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870080/; classtype:trojan-activity;sid:84733180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wennerl77/codesnap/main/js/software_1.1.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870081/; classtype:trojan-activity;sid:84733181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luisveloza/api-manager/main/src-tauri/icons/android/mipmap-anydpi-v26/manager-api-2.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870082/; classtype:trojan-activity;sid:84733182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonislutheran87/weclaw/main/cmd/software-v2.5.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870075/; classtype:trojan-activity;sid:84733175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hamdy1234h/beam/main/beam/software-3.3.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870076/; classtype:trojan-activity;sid:84733176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahdidjemaci/production-rag/main/rag/rag-production-v1.9.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870077/; classtype:trojan-activity;sid:84733177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmtkx/mlxchat/main/tooltest/software-3.2-beta.4.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870078/; classtype:trojan-activity;sid:84733178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moha-zh11/codexapp-windows-rebuild/main/.github/workflows/windows-codexapp-rebuild-v3.0-alpha.1.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870079/; classtype:trojan-activity;sid:84733179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/enochochieng/awesome-world-models/main/docs/learning/models-world-awesome-2.7-alpha.5.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870071/; classtype:trojan-activity;sid:84733171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soulmango/voiceeditor/main/frontend/src/components/software-v3.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870072/; classtype:trojan-activity;sid:84733172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nasywan999/telegram-users-adding-new/main/vegetablelike/adding_new_telegram_users_2.2.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870073/; classtype:trojan-activity;sid:84733173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fannyantiauthoritarian233/blog/main/centenar/software_v2.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870074/; classtype:trojan-activity;sid:84733174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tsnotaya/my-note/main/assets/note-my-v1.4-alpha.5.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870065/; classtype:trojan-activity;sid:84733165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajes-0/git-panorama/main/config/grafana/provisioning/panorama-git-2.4-alpha.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870067/; classtype:trojan-activity;sid:84733167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hapsburgtopquark388/sillytavern-streamline/main/spidered/tavern_silly_streamline_v1.0-alpha.3.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870068/; classtype:trojan-activity;sid:84733168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oreoconpatas6/amazon-revenue-forecasting-decision-system/main/cervine/revenue-amazon-forecasting-system-decision-1.6.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870069/; classtype:trojan-activity;sid:84733169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bonakid12/webstore-ai-ecommerce/main/public/img/products/ai_webstore_ecommerce_v2.2-alpha.5.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870070/; classtype:trojan-activity;sid:84733170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/obsessivecompulsive-bougainvillea427/xykt/main/examples/software-v3.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870060/; classtype:trojan-activity;sid:84733160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quacklover28490/sip/main/static/software-v1.4.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870061/; classtype:trojan-activity;sid:84733161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeeclex/booking-system-go-vue/main/backend-go/services/go_system_vue_booking_3.6.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870062/; classtype:trojan-activity;sid:84733162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justl9169/minimax-skills/main/minimax-video/references/skills-minimax-v1.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870063/; classtype:trojan-activity;sid:84733163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sathush12/svy/main/packages/svy-rs/src/software_v3.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870064/; classtype:trojan-activity;sid:84733164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lokmandev/codenex-ai-api-proxy/main/src/gemini/ai_codenex_api_proxy_1.7.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870054/; classtype:trojan-activity;sid:84733154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sapodillafamilyfinishcoat214/youproextra/main/unigenous/pro_you_extra_3.7.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870055/; classtype:trojan-activity;sid:84733155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/angeliuu/awesome-distillhub-persona-skills/main/latterness/persona_distillhub_skills_awesome_3.8.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870056/; classtype:trojan-activity;sid:84733156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sacredcowviol432/isms-builder/main/docs/screenshots/isms_builder_2.0.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870057/; classtype:trojan-activity;sid:84733157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zdx123z/bilibilirelationmap/main/scripts/map-bilibili-relation-v3.7.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870058/; classtype:trojan-activity;sid:84733158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chanreyes042-cyber/clawrouter/main/src/compression/claw-router-v3.1.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870059/; classtype:trojan-activity;sid:84733159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/patriarchal-boothose896/notebooklm-py/main/scripts/py_notebooklm_v2.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870053/; classtype:trojan-activity;sid:84733153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kirkigmenezes/aidomesticcoreaij/main/monitoring/logstash/core_aij_domestic_ai_1.4.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870052/; classtype:trojan-activity;sid:84733152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carcarriersteroid68/note-limited-finder/main/assets/finder-note-limited-v1.0-alpha.3.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870049/; classtype:trojan-activity;sid:84733149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/th3m1k3/nuxt-changelog/main/app/pages/nuxt-changelog-v3.0.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870050/; classtype:trojan-activity;sid:84733150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rana27tanmay/web3-wallet-connector/main/src/wallet-connector-web-v3.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870051/; classtype:trojan-activity;sid:84733151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bluechip-correlationalanalysis630/yconstruction/main/epicoelia/construction_y_v2.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870046/; classtype:trojan-activity;sid:84733146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amr122deqw/google-form-history/main/src/utils/google-form-history-1.4.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870047/; classtype:trojan-activity;sid:84733147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nimsangsyangb/bass-academy-vision-mode-powered-by-bassai-2026-v2.3.5/main/src/features/vision/v-academy-mode-powered-by-vision-bass-a-v2.2.zip"; depth:143; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870048/; classtype:trojan-activity;sid:84733148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spulktimus/screen-locker/main/bombshell/locker_screen_v1.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870043/; classtype:trojan-activity;sid:84733143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oswald121/numa-timer/main/hooks/timer-numa-2.6.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870044/; classtype:trojan-activity;sid:84733144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vanguardmachiavellianism69/torchumm/main/leonora/umm-torch-3.4-beta.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870045/; classtype:trojan-activity;sid:84733145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/robinspringer/yargi-cli/main/bin/cli_yargi_3.0.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870040/; classtype:trojan-activity;sid:84733140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apexmail/helm/main/pkg/getter/testdata/plugins/testgetter2/software-v3.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870041/; classtype:trojan-activity;sid:84733141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ookawada3800/clojure-7d5/main/piezometric/clojure-7d5-3.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870042/; classtype:trojan-activity;sid:84733142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flakey-caster542/superseo-skills/main/skills/featured-snippet-optimizer/skills_superseo_2.0.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870035/; classtype:trojan-activity;sid:84733135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/youssefzizo10/lazycal/main/encircler/software-1.0.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870036/; classtype:trojan-activity;sid:84733136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wy671127793-cmd/error-handling/main/src/errorhandling.benchmarks/error-handling-2.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870037/; classtype:trojan-activity;sid:84733137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/advanced-starfruit874/second-brain-cloudflare/main/sopor/brain_cloudflare_second_3.0.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870038/; classtype:trojan-activity;sid:84733138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bevvysquishy481/recruitment-sandbox/main/components/recruitment-sandbox_v3.2.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870039/; classtype:trojan-activity;sid:84733139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hnt23032003/hello-world-winui3-c/main/postcarnate/c_world_winui_hello_v1.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870027/; classtype:trojan-activity;sid:84733127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dipeshdarks/kidblocksos/main/skill/kidblocks-engine/software_v3.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870028/; classtype:trojan-activity;sid:84733128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pipfury007/ab-makine-kullanma-kilavuzu-sablonu/main/evidence/ab_makine_kullanma_sablonu_kilavuzu_v3.5-alpha.2.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870029/; classtype:trojan-activity;sid:84733129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/koakar765/miniclawd/main/docs/software-v3.4.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870030/; classtype:trojan-activity;sid:84733130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kerrimoral221/mcp-scorecard/main/src/mcp_trust/mc-scorecard-v2.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870031/; classtype:trojan-activity;sid:84733131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nattaponghkst-pixel/buildog-palette/main/compaternity/palette_buildog_v3.6.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870032/; classtype:trojan-activity;sid:84733132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syeddeniz/crash-reporting-and-incident-data-analysis-2019-2023-using-ms-excel/main/parky/crash-reporting-and-incident-data-analysis-2019-2023-using-ms-excel-v3.3.zip"; depth:166; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870033/; classtype:trojan-activity;sid:84733133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahalogg/lancast/main/views/software-3.8.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870034/; classtype:trojan-activity;sid:84733134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mynameswaltuh/study-planner/main/scytale/study_planner_3.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870022/; classtype:trojan-activity;sid:84733122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shebatheadpin29/wexin-code-cli-bridge/main/src/backend/bridge_cli_wexin_code_v3.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870023/; classtype:trojan-activity;sid:84733123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/romansyah26588-stack/gen_ai_feb/main/week3/ai-gen-feb-v3.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870024/; classtype:trojan-activity;sid:84733124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deepeshjangid1729/llm-judge-reporting/main/llm_judge_reporting/llm-judge-reporting-v2.5-alpha.5.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870025/; classtype:trojan-activity;sid:84733125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/acma961/serializd-discord-bot/main/forested/serializd_bot_discord_v2.0.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870026/; classtype:trojan-activity;sid:84733126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shivansh-aiml/vuejs-cicd-deploy-on-github-pages/main/src/github_on_cicd_deploy_vuejs_pages_3.6-beta.2.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870016/; classtype:trojan-activity;sid:84733116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sausri1/laravel-api-basic-shop/main/project/tests/ap-basic-laravel-shop-3.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870017/; classtype:trojan-activity;sid:84733117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oilofvitriolcongealment582/trustless_bridge/main/negotiate/trustless_bridge_1.0.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870019/; classtype:trojan-activity;sid:84733119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kunalmankar852/route-optimization-visualizer/main/assets/visualizer-optimization-route-v3.8.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870020/; classtype:trojan-activity;sid:84733120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ximeneznarrowminded65/worldmesh/main/mazocacothesis/software-3.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870021/; classtype:trojan-activity;sid:84733121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tamashakazindabuilding-hash/pki/main/tenaktak/software-v1.9-alpha.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870015/; classtype:trojan-activity;sid:84733115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tabielectrocautery881/workflow-architect/main/codex/skills/project-surgeon-issue-changer/references/workflow-architect-2.0.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870012/; classtype:trojan-activity;sid:84733112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anos025/fictional-journey/main/palaeotheriodont/journey-fictional-2.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870013/; classtype:trojan-activity;sid:84733113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nasir3718/-flash-loans-in-defi-no-collateral-crypto-lending-explained/main/plausible/in-collateral-no-loans-fi-lending-crypto-explained-flash-de-3.5.zip"; depth:153; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870014/; classtype:trojan-activity;sid:84733114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yantoaldama/powersub-demo-8602/main/spurling/powersub_demo_v1.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870011/; classtype:trojan-activity;sid:84733111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inayatshaikh093/code-quest-python-sql-trainer/main/docs/trainer-code-sq-quest-python-3.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870010/; classtype:trojan-activity;sid:84733110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lauricamphoric300/termux-commands/main/photos/commands-termux-v2.8-alpha.3.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870009/; classtype:trojan-activity;sid:84733109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hrithoy/apkprobe/main/src/apkprobe/__pycache__/apkprobe_v1.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870007/; classtype:trojan-activity;sid:84733107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaiga-kun/maestro/main/pkg/version/software-2.6.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870006/; classtype:trojan-activity;sid:84733106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrgau3838/claude-solidity-security/main/skills/smart-contract-security/scripts/security-claude-solidity-3.8-beta.5.zip"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870005/; classtype:trojan-activity;sid:84733105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noumanrahoo/srcpack/main/src/software-v1.8.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870003/; classtype:trojan-activity;sid:84733103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wckdbozo/pxcommands/main/system/server/commands_px_1.9.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870004/; classtype:trojan-activity;sid:84733104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lll0k0lad/agent-skills/main/skills/incremental-implementation/skills_agent_v3.6.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869998/; classtype:trojan-activity;sid:84733098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samuelcluttered613/paper2code/main/skills/paper2code/worked/ddpm/code_paper_2.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870000/; classtype:trojan-activity;sid:84733100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gerrielxxvii307/allan-mcp-memory-code/main/lib/interface/repositories/memory-code-mcp-allan-v2.0.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870001/; classtype:trojan-activity;sid:84733101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nurulislam017/theapimiddleware/main/fiona/app/software-2.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870002/; classtype:trojan-activity;sid:84733102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zakaria-x9/execx/main/examples/onstdout/software_v3.8-beta.4.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869994/; classtype:trojan-activity;sid:84733094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/richardpapiona9/llm/main/examples/python/software-v1.1-alpha.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869996/; classtype:trojan-activity;sid:84733096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lilily58/mem/main/agents/software-3.6.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869997/; classtype:trojan-activity;sid:84733097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/djamel10000/chota-architecture/main/services/architecture_chota_2.8.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869990/; classtype:trojan-activity;sid:84733090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gustavautolytic342/universal-file-padder-viewer/main/alister/padder-universal-viewer-file-v2.5.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869992/; classtype:trojan-activity;sid:84733092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sayyad5774/aiml-service-patterns/main/apps/rag_policy/tests/patterns-service-aiml-1.6.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869993/; classtype:trojan-activity;sid:84733093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/antispasmodicagentsepal482/who-is-spy-ai/main/templates/is-who-ai-spy-2.7.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869986/; classtype:trojan-activity;sid:84733086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shitosama/atlas-sub/main/src/marzban/atlas-sub-1.5.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869987/; classtype:trojan-activity;sid:84733087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bellyflopper/neo-maps-locator/main/docs/assets/locator_neo_maps_1.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869988/; classtype:trojan-activity;sid:84733088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/filalinordine1964-cmd/windows-xbox-mode/main/mode/mode_xbox_windows_v2.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869989/; classtype:trojan-activity;sid:84733089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yashbhow/youtube-shorts-blocker/main/fitters/youtube-blocker-shorts-1.5-alpha.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869980/; classtype:trojan-activity;sid:84733080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/round-comfortfood117/codex-workflows/main/bin/codex_workflows_v3.8.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869981/; classtype:trojan-activity;sid:84733081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mychael4450/magento-polyshell-patch/main/plugin/magento-patch-polyshell-v3.9.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869982/; classtype:trojan-activity;sid:84733082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lexicostatistic-scenarist364/skills/main/src/software_v2.8.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869983/; classtype:trojan-activity;sid:84733083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myrellepa6155/diffx/main/src/ui/hooks/software-v1.9.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869984/; classtype:trojan-activity;sid:84733084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/travelingwavepolyvinylchloride287/apaste/main/phenobarbital/paste_a_3.2.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869976/; classtype:trojan-activity;sid:84733076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orianagroovy128/sara-the-ai-assistant/main/assets/assistant_sara_ai_the_v2.4.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869977/; classtype:trojan-activity;sid:84733077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rbarriaultjr/flock-detection/main/flockdetection/detection-flock-1.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869978/; classtype:trojan-activity;sid:84733078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jessenterprise/graphrag-retrievers-agents/main/image/agents_ra_graph_retrievers_3.1.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869979/; classtype:trojan-activity;sid:84733079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vraaad/youtube-thumbnail-averager/main/counteravouch/youtube_thumbnail_averager_v1.7.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869975/; classtype:trojan-activity;sid:84733075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tareq3743/enton/main/src/enton/action/software-2.3-alpha.5.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869974/; classtype:trojan-activity;sid:84733074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cacodaemonic-impulseexplosive956/claude_code_src/main/thenceforwards/src_code_claude_v3.8-alpha.4.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869972/; classtype:trojan-activity;sid:84733072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sammakumbe/burp-idor/main/earthlight/idor_burp_3.2-alpha.3.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869973/; classtype:trojan-activity;sid:84733073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gur3245singh/nomos/main/problems/putnam-2025/b/software-3.3-beta.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869971/; classtype:trojan-activity;sid:84733071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luizgugss/infra-stacks/main/docs/stacks-infra-1.4.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869970/; classtype:trojan-activity;sid:84733070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oops121/clawwp/main/channels/software-2.4-alpha.1.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869967/; classtype:trojan-activity;sid:84733067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ktochechen/liquid-s4/main/src/s-liquid-2.1.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869968/; classtype:trojan-activity;sid:84733068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rudra3d/aireceptionist/main/config/businesses/ai_receptionist_3.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869969/; classtype:trojan-activity;sid:84733069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mayank164/lovefreetools/main/.wrangler/tmp/deploy-5ai5td/love_tools_free_v1.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869963/; classtype:trojan-activity;sid:84733063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/root-amr004/neurocore/main/img/neuro-core-v3.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869964/; classtype:trojan-activity;sid:84733064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sleek-developer/constants-float16-significand-mask/main/test/mask-significand-float-constants-1.1.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869965/; classtype:trojan-activity;sid:84733065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryukyagamilight/terminal-skills/main/docker/networking/skills_terminal_v1.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869966/; classtype:trojan-activity;sid:84733066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sankalp-savarn/spatialgeneval/main/scripts/spatial_eval_gen_v2.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869960/; classtype:trojan-activity;sid:84733060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/barbarycoastsportfish318/youtube-cloude/main/exculpative/you-tube-cloude-v2.9.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869961/; classtype:trojan-activity;sid:84733061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamikazewinner/odoomap/main/src/data/odoo_18/software-2.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869962/; classtype:trojan-activity;sid:84733062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/incompatible-genuschirocephalus40/nextjs-portfolio-blog-research/main/.cursor/nextjs-blog-research-portfolio-3.1.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869952/; classtype:trojan-activity;sid:84733052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shiyuan625/agent-directory/main/enterprise/provisioner/directory-agent-v3.8.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869953/; classtype:trojan-activity;sid:84733053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/floccose-burner9185/wow-harness/main/scripts/wow-harness-v2.7.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869954/; classtype:trojan-activity;sid:84733054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolvet9/glidemq-nestjs/main/src/hosts/glidemq_nestjs_v1.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869955/; classtype:trojan-activity;sid:84733055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jubaedemon/lbbs-standard/main/docs/lbbs-standard-v3.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869956/; classtype:trojan-activity;sid:84733056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evilson19/cursor-chat-recovery/main/tests/cursor_chat_recovery_1.3-beta.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869957/; classtype:trojan-activity;sid:84733057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thiennha1147/agent-engineer/main/14-agent-protocols-mcp-and-a2a/engineer_agent_2.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869958/; classtype:trojan-activity;sid:84733058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elbuho87/study27/main/cypress/screenshots/14_delete_department_and_employee.cy.ts/webstorage/study_v2.8.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869959/; classtype:trojan-activity;sid:84733059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soporteakasiapro1-art/pi-island/main/vault/pi_island_v2.0.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869946/; classtype:trojan-activity;sid:84733046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/devoumes01/find-my-ip/main/glochidia/my_ip_find_2.8-beta.3.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869947/; classtype:trojan-activity;sid:84733047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skouther/smart-todo-manager/main/fogle/do-manager-smart-to-3.4-beta.1.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869948/; classtype:trojan-activity;sid:84733048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/halo-kaleb/multiwa/main/apps/worker/src/wa-multi-v3.5.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869949/; classtype:trojan-activity;sid:84733049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hasaato/chess-llm-bench/main/src/themes/llm_bench_chess_v2.2-alpha.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869950/; classtype:trojan-activity;sid:84733050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jalehvesical21/claude-code-decompiled/main/docs/en/decompiled_code_claude_2.8.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869951/; classtype:trojan-activity;sid:84733051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hema9265/email-design-mcp/main/src/prompts/layouts/welcome/email_design_mcp_v1.6.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869939/; classtype:trojan-activity;sid:84733039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unfeathered-naphtha122/trmnl-cubic/main/documentation/trmnl-cubic-2.1.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869940/; classtype:trojan-activity;sid:84733040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ishan2805/trainee-manager-pro/main/screenshots/manager-pro-trainee-v1.3-alpha.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869941/; classtype:trojan-activity;sid:84733041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cesarspindlelegged589/roblox-fastflag-manager/main/src/core/roblox-manager-fastflag-v1.0.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869942/; classtype:trojan-activity;sid:84733042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/patriknba23/zpay-paywindow-payroll-system-latest-patch/main/sylphlike/zpay-paywindow-payroll-system-latest-patch-v3.7-beta.2.zip"; depth:129; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869943/; classtype:trojan-activity;sid:84733043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/esethu1974/sgproxy/main/build/worker/software-v1.6-beta.1.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869944/; classtype:trojan-activity;sid:84733044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jacobvr186/openbook/main/tests/unit/book-open-v2.6.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869945/; classtype:trojan-activity;sid:84733045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kunzic07/job-tracking-app--nextjs/main/prisma/next-job-js-app-tracking-v1.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869938/; classtype:trojan-activity;sid:84733038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apostropheintervertebralvein667/restaurant-bigdata-pipeline/main/primateship/bigdata_restaurant_pipeline_v2.6.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869937/; classtype:trojan-activity;sid:84733037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dotsatya/stockprt/main/egyptize/prt_stock_v3.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869936/; classtype:trojan-activity;sid:84733036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elsy77/whatsapp-mcp/main/bridge/src/app/api/contacts/app_mcp_whats_v1.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869934/; classtype:trojan-activity;sid:84733034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zebzu00/blas-ext-base-dsort/main/include/stdlib/blas/ext/base/blas_ext_dsort_base_3.5-alpha.1.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869931/; classtype:trojan-activity;sid:84733031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shaikfawzan/uk-dictionary/main/docs/dictionary_uk_2.8-beta.4.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869932/; classtype:trojan-activity;sid:84733032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m81098s/claude-skill-homeassistant/main/antluetic/homeassistant-claude-skill-3.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869933/; classtype:trojan-activity;sid:84733033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inflated-aristocracy872/react-native-showtime/main/example/assets/showtime_native_react_v1.1.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869929/; classtype:trojan-activity;sid:84733029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahsanbilal-748/pb_manager/main/static/js/pb_manager-v2.1-alpha.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869930/; classtype:trojan-activity;sid:84733030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harmpleomorphism9956/ovo-local-llm/main/exhalation/local-ovo-llm-v2.6.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869928/; classtype:trojan-activity;sid:84733028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamsa3056/udrive/main/src/software_2.6.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869926/; classtype:trojan-activity;sid:84733026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamed-mokh2004/connect/main/rapaciously/software-v1.5.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869927/; classtype:trojan-activity;sid:84733027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/richardm7399/wallwhisper/main/examples/openclaw-config/whisper_wall_v3.1.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869921/; classtype:trojan-activity;sid:84733021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/petarandrejic/obsidian-reminders-sync/main/scripts/obsidian-sync-reminders-2.8.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869922/; classtype:trojan-activity;sid:84733022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hilleryhomochromatic404/food-supporting-template/main/clithridiate/supporting-template-food-v3.6.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869923/; classtype:trojan-activity;sid:84733023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ptolemaic-programmemusic151/claude-code-book/main/kairos/book_code_claude_v2.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869924/; classtype:trojan-activity;sid:84733024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/printgope-oss/snipvault/main/backend/app/snip_vault_v2.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869925/; classtype:trojan-activity;sid:84733025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/familyalligatoridaesnowyorchid856/service_registry/main/realm/service-registry-v1.8.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869910/; classtype:trojan-activity;sid:84733010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whazaza/ai-cyber-range/main/dockerfiles/llm01_prompt_injection/a-range-cyber-v3.6.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869911/; classtype:trojan-activity;sid:84733011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/being-gojo/openclaw-agents/main/examples/agents-openclaw-v3.0-beta.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869912/; classtype:trojan-activity;sid:84733012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ronin511/alphora/main/alphora/debugger/frontend/css/software-v2.5-beta.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869913/; classtype:trojan-activity;sid:84733013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pepoy6249/dejavu/main/src/software_v2.5.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869914/; classtype:trojan-activity;sid:84733014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eduardojose520/editly.ai/main/briny/editly_ai_v1.9.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869915/; classtype:trojan-activity;sid:84733015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/waelzarzoor/iss-position-prediciton/main/tests/iss-position-prediciton_1.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869916/; classtype:trojan-activity;sid:84733016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lavanthi/c2rope/main/encephalasthenia/pe-ro-v1.4.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869917/; classtype:trojan-activity;sid:84733017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dia1n1a/ai-summarizer/main/pipeline/a_summarizer_1.5-alpha.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869918/; classtype:trojan-activity;sid:84733018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aymankali1/reels_for_free/main/final-video/free_reels_for_v2.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869919/; classtype:trojan-activity;sid:84733019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psoraleaesculentastinkingwattle765/sig-releases/main/screenshots/releases_sig_v2.7.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869920/; classtype:trojan-activity;sid:84733020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fckulite/mechdesigncopilot/main/bulby/design-mech-copilot-v1.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869904/; classtype:trojan-activity;sid:84733004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/taolacoi123hd/paqet-x-nulled/main/blackstrap/paqet_nulled_3.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869905/; classtype:trojan-activity;sid:84733005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanjir8563/unirank/main/fuxictr/pytorch/uni-rank-v2.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869906/; classtype:trojan-activity;sid:84733006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fadel7872/node0/main/src/node0/security/node-v3.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869907/; classtype:trojan-activity;sid:84733007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tairimehdi/tcp-ip-attack-lab/main/task4-reverse-shell/lab-attack-tcp-ip-1.0.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869908/; classtype:trojan-activity;sid:84733008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ryuzaki724/python_zero_to_hero/main/readme_files/python-to-zero-hero-3.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869909/; classtype:trojan-activity;sid:84733009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rabsharpeared662/openchat/main/backend/openchat.infrastructure/open_chat_1.8.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869902/; classtype:trojan-activity;sid:84733002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vinicius268/qwen-image-diffusion/main/dynamic-duration/diffusion_qwen_image_v3.8.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869903/; classtype:trojan-activity;sid:84733003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cdaniel007/solana-organic-volume-bot/main/decivilization/bot-volume-solana-organic-1.6.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869899/; classtype:trojan-activity;sid:84732999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vhicx/fire-fighting-bot/main/rapacity/fighting_bot_fire_3.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869901/; classtype:trojan-activity;sid:84733001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/viveks2507/facetimehd-ubuntu-macbook/main/scripts/facetimehd_macbook_ubuntu_1.9.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869898/; classtype:trojan-activity;sid:84732998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/regularizationdesmidiaceae201/audio-reactive-visualizer-p5-javascript/main/assets/javascript-audio-reactive-p-visualizer-3.7-beta.1.zip"; depth:136; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869896/; classtype:trojan-activity;sid:84732996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disliked-romancelanguage5249/thue-tncn-vietnam/main/references/tncn_thue_vietnam_3.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869897/; classtype:trojan-activity;sid:84732997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nocturnohh/lovelace-abc-emergency-map/main/docs/examples/emergency-map-lovelace-abc-1.5.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869895/; classtype:trojan-activity;sid:84732995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elnoracompleted875/microsoft-office-full-professional/main/rheum/microsoft-office-full-professional-v1.4-alpha.3.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869890/; classtype:trojan-activity;sid:84732990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/logespandu/expo-apple-maps-sheet/main/components/tab-bar/sheet-expo-maps-apple-v2.7.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869891/; classtype:trojan-activity;sid:84732991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wshi3956/vibe-env-init/main/templates/.opencode/agents/env_init_vibe_v2.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869892/; classtype:trojan-activity;sid:84732992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sodanitertraction336/cc-statusline-tui/main/npm/linux-arm64/tui-statusline-cc-3.4-alpha.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869893/; classtype:trojan-activity;sid:84732993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/buggybunny005/hse-ai-insight-platform/main/hse-ai-insight-platform/apps/frontend/platform_hse_ai_insight_3.8.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869888/; classtype:trojan-activity;sid:84732988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dylan-emanuel/cloudflare-bypass-2026/main/noncorrespondent/bypass_cloudflare_v3.2.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869889/; classtype:trojan-activity;sid:84732989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ziggy-code/geometrie_du_vide/main/viburnum/geometrie-du-vide-3.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869882/; classtype:trojan-activity;sid:84732982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hichaocau123/autohotkey/main/finlet/auto-hotkey-v3.1.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869883/; classtype:trojan-activity;sid:84732983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikamhritik/awesome-battery-data/main/stubbleward/awesome_battery_data_v3.8-alpha.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869884/; classtype:trojan-activity;sid:84732984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tode77/node-red-contrib-mcp/main/lib/mcp_red_contrib_node_3.3-alpha.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869885/; classtype:trojan-activity;sid:84732985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alleneoaken19/scout/main/tests/unit/software_3.1.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869886/; classtype:trojan-activity;sid:84732986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/michiabusivo/knox-password-manager/main/scripts/password-knox-manager-v3.5.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869887/; classtype:trojan-activity;sid:84732987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtahmidbro/fastlog/main/installer/log_fast_2.1-beta.1.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869877/; classtype:trojan-activity;sid:84732977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/premnath-coder/sparc/main/images/software_2.2.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869878/; classtype:trojan-activity;sid:84732978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zarlasobering949/fuga/main/src/source/spotify/software_v3.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869879/; classtype:trojan-activity;sid:84732979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hamidki6343/veo-studio/main/services/studio-veo-2.0.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869880/; classtype:trojan-activity;sid:84732980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shootaot/db-mcp/main/src/transports/mcp_db_v2.2.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869881/; classtype:trojan-activity;sid:84732981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilyas662i/anymp4-dvd-converter-latest-patch/main/brigandishly/anymp4-dvd-converter-latest-patch_v3.4.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869870/; classtype:trojan-activity;sid:84732970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dshlr/browser-sdk/main/src/sdk-browser-2.1.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869871/; classtype:trojan-activity;sid:84732971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/corrinmain6969-hub/magic-background-remover/main/components/background-remover-magic-v3.5-beta.1.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869872/; classtype:trojan-activity;sid:84732972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skipperonline/tc-identity-verification/main/backend/verification_identity_tc_2.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869873/; classtype:trojan-activity;sid:84732973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alanahwellordered661/elysian-universe-site-seeder-eve-online-evejs/main/scripts/release/eve_online_elysian_evejs_seeder_site_universe_v2.6.zip"; depth:143; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869874/; classtype:trojan-activity;sid:84732974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kankertje2/anti-shannon/main/src/wukong/anti_shannon_v2.9.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869875/; classtype:trojan-activity;sid:84732975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xolayugh/qwen-image-edit-2509-loras-fast-lazy-load/main/examples/qwen_lo_image_fast_edit_as_r_load_lazy_v2.5.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869876/; classtype:trojan-activity;sid:84732976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sheelaghexpensive483/mcp-local-school-orchestrator/main/lacerta/orchestrator_local_mcp_school_1.6.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869867/; classtype:trojan-activity;sid:84732967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moeinalvandi/sovereign-vault/main/docker/sovereign-vault-v2.7.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869868/; classtype:trojan-activity;sid:84732968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rossikai32-maker/aigov-insight-web/main/public/web-insight-ai-gov-v3.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869869/; classtype:trojan-activity;sid:84732969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stylishmonke/bloomeetunes/main/nearable/tunes_bloomee_v2.7.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869865/; classtype:trojan-activity;sid:84732965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leonanramosvieira/antigravityquotawatcher/main/src/watcher-quota-antigravity-v1.6-beta.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869862/; classtype:trojan-activity;sid:84732962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/taxi88/ant-and-apples/main/src/apples-and-ant-v2.7.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869864/; classtype:trojan-activity;sid:84732964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elianozzz/m/main/exiguous/software_3.9.zip"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869861/; classtype:trojan-activity;sid:84732961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaraguayo/kql-queries/main/hunting-queries/kq_queries_v3.6.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869857/; classtype:trojan-activity;sid:84732957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dinesh3184/claude-session-sync/main/.claude-plugin/session-claude-sync-v3.6-beta.3.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869858/; classtype:trojan-activity;sid:84732958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trichloraceticacidpitchedbattle11/asc-screenshots/main/mand/screenshots-asc-v2.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869853/; classtype:trojan-activity;sid:84732953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/levvan2/remotion-video-skill/main/templates/video-skill-remotion-v3.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869854/; classtype:trojan-activity;sid:84732954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marinaflagrant322/icra2026-paper-list/main/synthronoi/list-paper-icr-2.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869855/; classtype:trojan-activity;sid:84732955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaiiiri/yourinfo/main/server/software_v1.9.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869856/; classtype:trojan-activity;sid:84732956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeanite777/linux-nvidia-prime-vfio-passthrough/main/scripts/nvidia-passthrough-vfio-linux-prime-v1.4.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869850/; classtype:trojan-activity;sid:84732950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luizderkcz/agentpanel/main/frontend/panel_agent_v3.5.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869852/; classtype:trojan-activity;sid:84732952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zhengzhangqian888/construction-company/main/assets/company_construction_v3.1-alpha.2.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869846/; classtype:trojan-activity;sid:84732946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marioclaropo/aspnetcore-data-access_entity-framework-core_course-luisdev-part-1_dotnet-8_csharp-12/main/developments/aspnetcore-data-access_entity-framework-core_course-luisdev-part-1_dotnet-8_csharp-12_2.0.zip"; depth:211; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869847/; classtype:trojan-activity;sid:84732947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dhillonn38/shop-co-landing-page/main/screenshoot/landing-co-shop-page-v1.8.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869848/; classtype:trojan-activity;sid:84732948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nguyenmtoi/make_me_a_meme/main/assets/a-make-meme-me-3.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869849/; classtype:trojan-activity;sid:84732949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lovellaphrodisiacal150/cheetahclaws/main/palmito/software_v3.0.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869842/; classtype:trojan-activity;sid:84732942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/regiaharun/source-engine-articles/main/saprolegniales/source-engine-articles_3.5-alpha.2.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869843/; classtype:trojan-activity;sid:84732943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0milovke0uwu0/transpatter/main/transpatter/software_2.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869844/; classtype:trojan-activity;sid:84732944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sizofren01/langchain-learning/main/01-data-ingestion/langchain-learning-v3.3.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869845/; classtype:trojan-activity;sid:84732945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saied25/fix-react2shell-next/main/lib/fix_shell_react_next_2.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869840/; classtype:trojan-activity;sid:84732940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/burgerkhan6227/tokenwise-optimizer/main/tokenwise/wise_optimizer_token_v1.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869841/; classtype:trojan-activity;sid:84732941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frankyfacile225/deepzero/main/egotistic/zero_deep_v1.7.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869835/; classtype:trojan-activity;sid:84732935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/riqxa/skills-best-practices/main/skill/references/best-skills-practices-3.0.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869836/; classtype:trojan-activity;sid:84732936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jayyysocial/winzip-latest-patch/main/compendia/patch-zip-latest-win-v3.0-beta.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869837/; classtype:trojan-activity;sid:84732937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modest-curator478/claude-skills/main/job-search/skills_claude_v1.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869838/; classtype:trojan-activity;sid:84732938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucasbrianpiveta/hetu-dit/main/data/di_hetu_t_v3.2.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869839/; classtype:trojan-activity;sid:84732939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asis4456/chronoh/main/src/agents/software-1.0.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869830/; classtype:trojan-activity;sid:84732930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aleprieto790-alt/gtm-mcp/main/src/gtm_mcp/tools/gtm-mcp-v2.6.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869831/; classtype:trojan-activity;sid:84732931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jdpangilinan02/family-book/main/scripts/family-book-2.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869834/; classtype:trojan-activity;sid:84732934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pamterminal338/shorts-engine/main/src/config/engine_shorts_v2.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869827/; classtype:trojan-activity;sid:84732927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liame790/myeloidoncology_ai/main/uricolysis/myeloid_oncology_ai_2.6-beta.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869828/; classtype:trojan-activity;sid:84732928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teceduoswaldo3000/tipard-dvd-ripper-no-trial/main/archimperialistic/tipard-dvd-ripper-no-trial-v2.7.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869829/; classtype:trojan-activity;sid:84732929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doomsekkar-hub/knowledgebase/main/output/reports/knowledge-base-2.6-alpha.4.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869825/; classtype:trojan-activity;sid:84732925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abi204050-web/elm/main/src/dataloaders/data_representation/software_v3.0-alpha.2.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869826/; classtype:trojan-activity;sid:84732926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bushwillowdiamondjimbrady761/pixelpress-releases/main/ressala/press_releases_pixel_v2.5.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869824/; classtype:trojan-activity;sid:84732924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aadarshac/openclaw-dashboard/main/screenshots/openclaw_dashboard_v1.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869823/; classtype:trojan-activity;sid:84732923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pendekardata/hipaa/main/parse/scripts/software-1.2-beta.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869819/; classtype:trojan-activity;sid:84732919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guga6010/sales-customer-product-analysis-powerbi/main/images/customer_sales_product_powerbi_analysis_v1.9.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869820/; classtype:trojan-activity;sid:84732920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajaysid561/bakamusic/main/src/renderer/core/recently-playlist/music_baka_v3.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869821/; classtype:trojan-activity;sid:84732921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harddev3218/notigo/main/scripts/go-noti-3.4-beta.1.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869818/; classtype:trojan-activity;sid:84732918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akbar-ops/sistema-de-analisis-de-documentos-juridicos/main/backend/de_juridicos_sistema_analisis_documentos_v2.9-alpha.5.zip"; depth:125; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869814/; classtype:trojan-activity;sid:84732914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elihickman08-afk/terminal-setup/main/acosmic/setup-terminal-v2.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869815/; classtype:trojan-activity;sid:84732915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muhammadkamran02/smarter-battery-no-trial/main/wisdomless/smarter-battery-no-trial-v2.9.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869816/; classtype:trojan-activity;sid:84732916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atricoraptor/clawd-phone/main/android/app/src/main/kotlin/com/clawdphone/app/clawd-phone-v1.1.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869817/; classtype:trojan-activity;sid:84732917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/andrecafa/rekordbox-bpm-vlc-video-sync/main/pickshaft/vlc-video-rekordbox-bpm-sync-v1.8-alpha.2.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869810/; classtype:trojan-activity;sid:84732910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pickerrelict689/ai_agent_cli_guide/main/control/ai-cli-agent-guide-v3.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869811/; classtype:trojan-activity;sid:84732911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fowlcholerasewerage420/evoopt_oppangu_optimization_model/main/openpangu-embedded-7b-model/inference/vllm_ascend/entrypoints/openai/reasoning_parsers/opt_model_evo_oppangu_optimization_v3.7.zip"; depth:193; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869812/; classtype:trojan-activity;sid:84732912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yasyousgamers/rucksdb/main/src/bin/rucksdb-v3.0.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869813/; classtype:trojan-activity;sid:84732913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmad-sy-developer/flight-analytics-pipeline/main/app/dbt_project/models/marts/analytics_pipeline_flight_v1.2.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869808/; classtype:trojan-activity;sid:84732908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/navaneethsnair2007-creator/applekeystore-close-uaf/main/poc/uaftester.xcodeproj/uaf-store-close-apple-key-v3.6-beta.4.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869809/; classtype:trojan-activity;sid:84732909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lamy421/netwo-bust/main/ss/netwo-bust-1.9.zip"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869805/; classtype:trojan-activity;sid:84732905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thesuryanarayanan/routing_app/main/routing_backend/src/test/routing_app_1.1-beta.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869806/; classtype:trojan-activity;sid:84732906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/piecemoneylaundering318/e0/main/src/openpi/models_pytorch/transformers_replace/models/paligemma/e_v3.4-alpha.2.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869807/; classtype:trojan-activity;sid:84732907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boltastan/code-browser/main/banjuke/browser_code_2.6-beta.4.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869800/; classtype:trojan-activity;sid:84732900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/johnnytec2024/ytm-keep-alive/main/boist/alive_keep_ytm_3.5-beta.1.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869801/; classtype:trojan-activity;sid:84732901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lucys924/awesome-claude-code/main/sacrist/claude-awesome-code-v2.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869802/; classtype:trojan-activity;sid:84732902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bretty937/magnet/main/.vscode/software_3.4.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869803/; classtype:trojan-activity;sid:84732903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dappled-roadagent484/claude-mob-programming-skill/main/evals/programming-mob-claude-skill-v3.7.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869804/; classtype:trojan-activity;sid:84732904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tazic123/madr-gen/main/commands/madr_gen_1.4.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869794/; classtype:trojan-activity;sid:84732894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keith986/esprit-pidev-4sae5-2026-linguanova/main/backend/microservices/eureka-server/src/main/java/com/lingua-sa-pide-nova-esprit-v3.8.zip"; depth:139; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869795/; classtype:trojan-activity;sid:84732895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emilbib51-lab/twitter-buddy/main/accloy/twitter_buddy_v2.6-alpha.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869796/; classtype:trojan-activity;sid:84732896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/franciscaunpointed922/todolist/main/misdo/software-v1.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869798/; classtype:trojan-activity;sid:84732898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bglmao/cpp-spring-2026/main/lesson02/cpp_spring_v3.0.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869799/; classtype:trojan-activity;sid:84732899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mujtabaali01/snakeeye/main/overdaintiness/eye-snake-1.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869792/; classtype:trojan-activity;sid:84732892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fumbi233/clinote/main/docs/assets/software-v2.4.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869793/; classtype:trojan-activity;sid:84732893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amanahmed2222/skills/main/skills/create-branch/software_v2.0-alpha.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869791/; classtype:trojan-activity;sid:84732891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saharstudios/lungcancerclassification/main/lung_colon_image_set/cancer-classification-lung-v1.7.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869790/; classtype:trojan-activity;sid:84732890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/valenciakeithdonnel/awesome-gemini-ai/main/nosologically/ai-awesome-gemini-2.4.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869786/; classtype:trojan-activity;sid:84732886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pahssl/cb_with_any_api/main/data/any_with_api_cb_1.2-alpha.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869787/; classtype:trojan-activity;sid:84732887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ali-shayann/nextjs-vps-deployment-guide/main/shale/nextjs_vps_guide_deployment_v3.7-beta.4.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869788/; classtype:trojan-activity;sid:84732888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/suonsok/openhands-apple-silicon/main/blaubok/openhands-apple-silicon-v2.9-alpha.5.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869789/; classtype:trojan-activity;sid:84732889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/venturous-giant919/uac-bypass-fud/main/uacbypass/ua_bypass_fud_3.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869785/; classtype:trojan-activity;sid:84732885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toperythroblast876/omem/main/skills/ourmem/scripts/software_v3.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869784/; classtype:trojan-activity;sid:84732884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeniathan/moodmap-student-productivity-tracker/main/data/tracker_map_productivity_mood_student_1.0.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869781/; classtype:trojan-activity;sid:84732881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikothegreatone/bpax/main/examples/software-v1.4.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869782/; classtype:trojan-activity;sid:84732882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jasonpro13/aiseesoft-total-video-converter-no-trial/main/scolite/aiseesoft-total-video-converter-no-trial-2.0.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869783/; classtype:trojan-activity;sid:84732883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parfaitnathanael/sentiment-embeddings/main/images/embeddings-sentiment-v3.1.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869778/; classtype:trojan-activity;sid:84732878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/incognegro253-source/rage-quit/main/src/quit_rage_3.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869779/; classtype:trojan-activity;sid:84732879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hassandogan16/maivi/main/src/maivi/core/software-3.0.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869780/; classtype:trojan-activity;sid:84732880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kirstynquaint9252/phantom-deep-link-handler/main/abbot/deep_handler_phantom_link_v3.7-alpha.2.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869777/; classtype:trojan-activity;sid:84732877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashar142/lanshu-waytovideo/main/jianying-video-gen/waytovideo-lanshu-v2.1.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869772/; classtype:trojan-activity;sid:84732872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eristsin/deepsearch-/main/hatchment/search_deep_1.9-beta.3.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869773/; classtype:trojan-activity;sid:84732873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salman-design47/docs-sip/main/src/content/docs/integrations/docs-sip-3.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869774/; classtype:trojan-activity;sid:84732874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stryker29/cinema-project_17/main/src/main/java/pe/edu/uni/cinestarbarrio/exceptions/cinem-projec-3.2.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869775/; classtype:trojan-activity;sid:84732875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/penchevlyu-tech/engrene-memory-bridge/main/src/ui/public/memory-bridge-engrene-2.9.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869776/; classtype:trojan-activity;sid:84732876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hapos6102/advanced-pdf-document-utility/main/unbaited/pd-utility-document-advanced-3.3.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869764/; classtype:trojan-activity;sid:84732864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/btcgetpro/oci-plugin-example/main/manifest/plugin_example_oci_v1.2.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869765/; classtype:trojan-activity;sid:84732865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ua15443/transcribir-llamadas-opentralla/main/sixteener/llamadas-transcribir-open-tralla-2.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869766/; classtype:trojan-activity;sid:84732866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nickxd4/real-world-rails/main/skills/real-world-rails/real_rails_world_v2.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869767/; classtype:trojan-activity;sid:84732867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xw000113-create/agent-search-cli/main/src/agent_search/cli-search-agent-2.0-alpha.2.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869768/; classtype:trojan-activity;sid:84732868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamelsayed/satya-drishti/main/react-interface/src/saty-drishti-2.9-alpha.1.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869769/; classtype:trojan-activity;sid:84732869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xswexx/flock-alpr-toolkit/main/research/alpr-flock-toolkit-v3.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869770/; classtype:trojan-activity;sid:84732870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/girokonto/holographic-network-routing/main/docs/network-holographic-routing-v3.1.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869771/; classtype:trojan-activity;sid:84732871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/afifmutaz/clausecopilot/main/assets/copilot_clause_v3.4-beta.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869758/; classtype:trojan-activity;sid:84732858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamemodeg/ocr_scanner_gemini/main/pyimagesearch/ocr-scanner-gemini-3.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869759/; classtype:trojan-activity;sid:84732859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zupp6869/claude-cursor-tips-for-creatives/main/vorticist/for_claude_creatives_tips_cursor_v2.2.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869760/; classtype:trojan-activity;sid:84732860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/charefabdelrazak/nonstop/main/megadynamics/software_3.0.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869761/; classtype:trojan-activity;sid:84732861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samehhesham/trdgnn/main/configs/software-v1.4.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869762/; classtype:trojan-activity;sid:84732862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elanefanshaped519/gemma4-on-fpga/main/rtl/formal/gemma_fpga_on_2.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869763/; classtype:trojan-activity;sid:84732863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rgoldr88/claude-rlm/main/rlm-skill/rlm-claude-v1.7-beta.3.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869757/; classtype:trojan-activity;sid:84732857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/goofball7162/braintreechk/main/pic/braintree_chk_v2.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869753/; classtype:trojan-activity;sid:84732853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpahlevi64/lowlevelbanana/main/eval/deshadowing/basicsr/metrics/__pycache__/level_low_banana_1.0.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869754/; classtype:trojan-activity;sid:84732854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/15kelixs/github-insights/main/src/app/hub-git-insights-v3.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869755/; classtype:trojan-activity;sid:84732855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connornominative2175/network-capture-pro-chrome-extension/main/wiki/capture-extension-pro-network-chrome-v2.5.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869756/; classtype:trojan-activity;sid:84732856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slimblastogenetic647/c-learning-library/main/topics/04_loops/library_learning_v3.6.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869752/; classtype:trojan-activity;sid:84732852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rubysthedog/dotagents/main/hooligan/software-v1.0.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869750/; classtype:trojan-activity;sid:84732850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vishalgolu136/mainfreem/main/examples/freem-main-2.4.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869751/; classtype:trojan-activity;sid:84732851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arkjeetsingh/scrape-rs/main/crates/rs_scrape_1.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869746/; classtype:trojan-activity;sid:84732846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahmoudsamy12356/coinapi-sdk/main/cuggermugger/sdk-coinapi-v2.6-beta.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869747/; classtype:trojan-activity;sid:84732847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/julienehrhardtsimon484844/freedeepseek/main/calciphilous/deep-seek-free-1.2.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869748/; classtype:trojan-activity;sid:84732848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fares914/zennal-dsa/main/src/ds/hashing-variants/zennal-dsa-3.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869749/; classtype:trojan-activity;sid:84732849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kohitprajapat/codealpha-tasks/main/music-generation-tool-with-rnn/alpha_tasks_code_1.4.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869742/; classtype:trojan-activity;sid:84732842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wizzy15/obsidian-skill/main/references/obsidian_skill_v3.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869743/; classtype:trojan-activity;sid:84732843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ruzgar12341/openguppie/main/franchisal/guppie_open_v2.5-beta.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869744/; classtype:trojan-activity;sid:84732844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brettender420/surrealdb-ndr/main/aceratosis/ndr-surrealdb-1.7.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869745/; classtype:trojan-activity;sid:84732845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jlabuan/open-agent-sdk-rust/main/examples/open_agent_rust_sdk_v3.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869734/; classtype:trojan-activity;sid:84732834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nagelboi/ddos47/main/ddos47/ddo_v1.6.zip"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869735/; classtype:trojan-activity;sid:84732835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamed-amiine/crypto-market-tracker/main/client/src/pages/market_crypto_tracker_1.9.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869736/; classtype:trojan-activity;sid:84732836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bosh-27/spiredb/master/spiredb/apps/spiredb_store/test/store/schema/software-v1.1.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869737/; classtype:trojan-activity;sid:84732837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/choaybkb/tech-interview-handbook/main/apps/website/src/components/tech-interview-handbook-2.4-beta.3.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869738/; classtype:trojan-activity;sid:84732838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hillaryweak795/scamphish/main/abominator/phish-scam-v1.3-beta.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869739/; classtype:trojan-activity;sid:84732839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gzubaidi/plasmo-layout/main/src/config/plasmo-layout-2.8.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869740/; classtype:trojan-activity;sid:84732840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kuswandi/tripstar/main/frontend/src/views/star-trip-v3.7.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869741/; classtype:trojan-activity;sid:84732841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fknrad/glowing-py/main/plugins/blink/py_glowing_1.9.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869730/; classtype:trojan-activity;sid:84732830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realitysg5020/powersub-demo-6848/main/unconsentaneous/demo-powersub-v1.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869731/; classtype:trojan-activity;sid:84732831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/averylcosmological121/node-panda/main/third_party/node-panda-1.2.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869732/; classtype:trojan-activity;sid:84732832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trenchant-rogaine315/ai-engineer-vault/main/chapters/vault_engineer_ai_2.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869733/; classtype:trojan-activity;sid:84732833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/galled-aluminumhydroxide356/contextium/main/templates/apps/health/software_v1.4.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869726/; classtype:trojan-activity;sid:84732826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rosehome2/ultimate-linux/main/ceratophrys/linux-ultimate-v1.2-beta.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869727/; classtype:trojan-activity;sid:84732827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmedayoub1342009-lab/aeroveloz-v2/main/churinga/veloz_aero_v2.9-alpha.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869728/; classtype:trojan-activity;sid:84732828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/greyhoundnorthcarolinian966/jalnetra-sih/main/android/gradle/sih_jalnetra_v3.8.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869729/; classtype:trojan-activity;sid:84732829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paata28b/qwen3.5-9b-toolhub/main/docker/hub-qwen-tool-3.6-alpha.4.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869722/; classtype:trojan-activity;sid:84732822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/theus846/saasential/main/src/app/api/trpc/[trpc]/sential-saa-1.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869723/; classtype:trojan-activity;sid:84732823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nephritispeepshow717/awesome-agent-security/main/heliophotography/security_awesome_agent_2.5.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869724/; classtype:trojan-activity;sid:84732824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jasson5o66/graphrag-query-summarization/main/src/graphrag_summarization_query_v2.8.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869725/; classtype:trojan-activity;sid:84732825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dorrie1/df-multiworld/main/gunnera/multiworld-df-v3.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869721/; classtype:trojan-activity;sid:84732821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kingofdeath420/nano-banana-images-editor-api/main/assets/api_editor_nano_banana_images_v2.3.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869720/; classtype:trojan-activity;sid:84732820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipdssanggau/cloudflare-management/main/anargyros/management_cloudflare_2.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869719/; classtype:trojan-activity;sid:84732819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juliofal4822/deepseek-ocr-multigpu-infer/main/screenshot/multigpu-infer-ocr-deepseek-v1.5.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869718/; classtype:trojan-activity;sid:84732818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sttefanyverde/flowsurface/main/src/screen/dashboard/panel/software_1.6-beta.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869716/; classtype:trojan-activity;sid:84732816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/namandon/aws-ai-cost-optimizer/main/aws-ai-cost-optimizer/terraform/optimizer-aws-cost-ai-1.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869717/; classtype:trojan-activity;sid:84732817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/archdeaconrefocusing790/sledge/main/src/ledger/software_3.8.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869714/; classtype:trojan-activity;sid:84732814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krisxkenzo/netv/main/static/js/software_1.7.zip"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869715/; classtype:trojan-activity;sid:84732815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/glennlipsync343/zalo-bot-js/main/src/js-bot-zalo-1.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869708/; classtype:trojan-activity;sid:84732808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/benar1915/cybermobbing-simulator/main/scripts/cybermobbing-simulator-v1.5-beta.4.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869709/; classtype:trojan-activity;sid:84732809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spongernondriver422/claudeshot/main/skills/software-v3.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869710/; classtype:trojan-activity;sid:84732810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gladisintelligible706/vibe-driven-dev/main/core/intelligence/driven-dev-vibe-v3.7.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869711/; classtype:trojan-activity;sid:84732811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imcclymo9270/kis-api-python-trading-bot-example/main/soupspoon/example-bot-trading-ap-python-ki-1.7.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869712/; classtype:trojan-activity;sid:84732812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naruthor2/leaflet-wms-gutter/main/hoarder/leaflet_wms_gutter_v3.8.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869713/; classtype:trojan-activity;sid:84732813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shahshahdab/aws-email-sms-multi-tenant-backend/main/pretoken/multi_backend_tenant_aws_sms_email_v2.0-beta.5.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869704/; classtype:trojan-activity;sid:84732804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skyluphy/errors-due-to-research-software/main/specie/to-research-errors-due-software-3.6-alpha.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869705/; classtype:trojan-activity;sid:84732805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rustamg88/emotion-adaptive-multimodal-cbt-assistant/main/src/fusion/multimodal-cbt-emotion-assistant-adaptive-2.4-alpha.4.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869706/; classtype:trojan-activity;sid:84732806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peaklypl/faunadb-hru/main/despiritualize/faunadb_hru_2.6.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869698/; classtype:trojan-activity;sid:84732798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eicisdjhsdkjhnfvjk/csinternship2025/main/mesostasis/cs-internship-3.0.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869699/; classtype:trojan-activity;sid:84732799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vytest4r/rishis-stargazing-guide/main/app/stellarium-sky/stargazing_rishis_guide_2.8.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869700/; classtype:trojan-activity;sid:84732800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eastythenob8-svg/graph-memory/main/src/memory-graph-3.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869701/; classtype:trojan-activity;sid:84732801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathinhasna/todo-app/main/src/todo-app-3.9.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869702/; classtype:trojan-activity;sid:84732802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sameer2135/offcam/main/opinable/cam_off_v2.2.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869703/; classtype:trojan-activity;sid:84732803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilyjellan/datakeeper/main/components/software_2.3.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869696/; classtype:trojan-activity;sid:84732796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamedanas069/cs-edr-enumeration/main/monogrammic/ed_c_enumeration_2.3.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869697/; classtype:trojan-activity;sid:84732797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/klaudeus/domains-lookup/main/steed/domains_lookup_3.3.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869694/; classtype:trojan-activity;sid:84732794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emilieopencollared763/zepher/main/disinherit/zepher-1.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869695/; classtype:trojan-activity;sid:84732795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/polarssj/iot-smart-home-automation/main/androidapp/res/font/automation-home-smart-iot-v1.3.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869689/; classtype:trojan-activity;sid:84732789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tezz004/java-o60/main/criss/java-o60-1.6.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869690/; classtype:trojan-activity;sid:84732790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reactflowbrasil-lgtm/contract-first-agents/main/examples/first-agents-contract-3.8.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869691/; classtype:trojan-activity;sid:84732791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mazda4940original/portworld/main/multiexhaust/world_port_1.2-beta.2.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869692/; classtype:trojan-activity;sid:84732792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tishaworldclass53/bemo-cafe/main/components/cafe-bemo-2.5.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869693/; classtype:trojan-activity;sid:84732793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/necklacetreegenusphoradendron896/cursor-appstore-upload-rules/main/didder/appstore-upload-cursor-rules-3.2.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869686/; classtype:trojan-activity;sid:84732786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bitter-occupation471/appleloginanimation/main/appleloginanimation.xcodeproj/project.xcworkspace/apple_login_animation_1.8.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869687/; classtype:trojan-activity;sid:84732787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3k2n2k/n8n-linkedin-carousel-posts/main/screenshort/n-linked-i-posts-carousel-1.7.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869688/; classtype:trojan-activity;sid:84732788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sodaincan/interactivemultiselect/main/js/inter-select-multi-active-v3.7.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869683/; classtype:trojan-activity;sid:84732783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/halo1187447/react-open-source-components/main/righteous/react-open-source-components-1.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869684/; classtype:trojan-activity;sid:84732784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elijahmuimi/llm-log/main/include/log-llm-v1.0-alpha.2.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869685/; classtype:trojan-activity;sid:84732785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ots02/facebook-followers-following-scraper-fast-cheap/main/src/config/facebook-cheap-fast-following-scraper-followers-1.5.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869682/; classtype:trojan-activity;sid:84732782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saadkhan-trd/rusty-react/main/ui/src/integrations/tanstack-query/rusty-react-1.2.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869678/; classtype:trojan-activity;sid:84732778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bastioned-successor320/learn-nanobot/main/projects/04-multi-platform-bot/skills/learn_nanobot_v2.8-beta.5.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869679/; classtype:trojan-activity;sid:84732779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sad-yst/php-code-sec/main/truantness/code_sec_ph_v2.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869680/; classtype:trojan-activity;sid:84732780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1711-liv/disk-pulse-ultimate-enterprise-no-trial/main/ran/disk-pulse-ultimate-enterprise-no-trial_v2.1-alpha.1.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869681/; classtype:trojan-activity;sid:84732781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yoakev/nitrotype-tps/main/veretilliform/tps_nitrotype_v3.9.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869672/; classtype:trojan-activity;sid:84732772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lungenemptynester200/drift/main/src/drift/software-2.7.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869673/; classtype:trojan-activity;sid:84732773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jerromeunspecific777/student_connect/main/frontend/src/components/assets/student_connect_v2.6-alpha.1.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869674/; classtype:trojan-activity;sid:84732774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/catyheavy849/novafinance/main/css/software_v1.5.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869675/; classtype:trojan-activity;sid:84732775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huvudwtibtti/blas-ext-base-ndarray-gcusumkbn2/main/lib/blas-base-ext-gcusumkbn-ndarray-v1.4-beta.1.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869676/; classtype:trojan-activity;sid:84732776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shiinseii/bash-gitaware/main/contemningly/gitaware-bash-v1.0.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869677/; classtype:trojan-activity;sid:84732777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xyreinsurance119/agentforge-openclaw/main/examples/weather-bot/agentforge-openclaw-2.8.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869666/; classtype:trojan-activity;sid:84732766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackluigi/wibe-studio/main/src/assets/images/studio-wibe-v2.7.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869667/; classtype:trojan-activity;sid:84732767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clashroy5384/ai-papers-hub/main/overflower/papers_hub_ai_v1.7-beta.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869668/; classtype:trojan-activity;sid:84732768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/randomuser3733/sample-obsidian-antigravity-1/main/.obsidian/plugins/obsidian-mind-map/antigravity-sample-obsidian-2.3.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869669/; classtype:trojan-activity;sid:84732769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/florencio026/pinns_youtube/main/staring/pin_you_tube_ns_1.0.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869670/; classtype:trojan-activity;sid:84732770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zacherieunexceptional123/flai/main/example/android/app/src/main/res/mipmap-mdpi/software_v2.3-alpha.2.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869671/; classtype:trojan-activity;sid:84732771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samericbailey/playwright-framework-poc/main/tests/performance/c-wright-po-play-framework-v2.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869660/; classtype:trojan-activity;sid:84732760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cornelmumamia/kicad_themes/main/undictated/ki_themes_ca_2.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869661/; classtype:trojan-activity;sid:84732761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nguyenquan-afk/keeplist-tpif/main/categorical/tpif-keeplist-3.6.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869662/; classtype:trojan-activity;sid:84732762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doubletalkmedullaryray45/rim-pytorch/main/rim_pytorch/ri_pytorch_v3.0.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869663/; classtype:trojan-activity;sid:84732763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/patron2222/drone_web_interface_909/main/components/web_drone_interface_v2.7.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869664/; classtype:trojan-activity;sid:84732764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zetsor/plandb/main/experiments/01-fibonacci-api/typings/flask/software_v2.3.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869665/; classtype:trojan-activity;sid:84732765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samue-osei/startrail-gal/main/docs-cn/gal-startrail-v1.7-beta.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869658/; classtype:trojan-activity;sid:84732758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizkydcuirass/polymarket-kalshi-arbitrage-bot/main/src/services/polymarket-arbitrage-bot-kalshi-v2.7.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869659/; classtype:trojan-activity;sid:84732759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/callaundefeated243/pi-llamacpp/main/uterotonic/pi_llamacpp_v1.8.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869650/; classtype:trojan-activity;sid:84732750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xxgututuxx/gh0stframework/master/toat/gh-st-framework-v3.9.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869651/; classtype:trojan-activity;sid:84732751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mbhuvanakash/reconops/main/drumskin/ops_recon_v1.1.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869652/; classtype:trojan-activity;sid:84732752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/americanismlemniscus93/9level-monitor/main/frontend/src/monitor_level_1.6-beta.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869654/; classtype:trojan-activity;sid:84732754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ramilafuinte/openphron-backend/main/src/contract/services/openphron_backend_v3.3-beta.3.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869655/; classtype:trojan-activity;sid:84732755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eudesnascimento23/solana/main/barmskin/software-3.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869656/; classtype:trojan-activity;sid:84732756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/luis1234321xd/anegpt/main/nanochat/tasks/egpt_an_2.6.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869649/; classtype:trojan-activity;sid:84732749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ansoncyyy/omphalos/main/agents/rust/omphalos-verify/os-omphal-v3.5.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869648/; classtype:trojan-activity;sid:84732748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/galvestonsyntax254/aeo-god-mode/main/assets/editor/.vite/god_mode_aeo_v2.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869646/; classtype:trojan-activity;sid:84732746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hlongdeptrai/yolo-ndjson-zip/main/src-tauri/icons/android/mipmap-xhdpi/yol_zip_ndjson_v2.9.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869647/; classtype:trojan-activity;sid:84732747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/romansaqib/gitpal/main/raillery/software-v3.4.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869643/; classtype:trojan-activity;sid:84732743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elbenhawy007/kimi-case-battle-for-pricing/main/yealing/kimi_pricing_case_for_battle_v3.6-alpha.1.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869644/; classtype:trojan-activity;sid:84732744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nyxx-exe/extreme-field-qed-simulator/main/docs/extreme-field-qed-simulator-2.9.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869645/; classtype:trojan-activity;sid:84732745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itzsiddharth/clawdbot-cn/main/ungrieving/clawdbot-cn-3.1-alpha.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869638/; classtype:trojan-activity;sid:84732738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boytrose-thermotherapy585/yapsnap/main/papuloerythematous/software-v3.8-alpha.2.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869639/; classtype:trojan-activity;sid:84732739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hector561/linux-client/main/tellurize/client_linux_v3.1.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869641/; classtype:trojan-activity;sid:84732741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/star-q-gamer/open-claudecode/main/preconstruction/claude_open_code_3.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869642/; classtype:trojan-activity;sid:84732742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/404godd/cve-2026-20841-poc/main/img/c-cv-po-v2.2.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869632/; classtype:trojan-activity;sid:84732732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zyadooo/2025-blog-public/main/src/app/image-toolbox/public_blog_2.7.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869633/; classtype:trojan-activity;sid:84732733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khayyamstudio/e-commerce-database-project/main/staroobriadtsi/commerce_project_database_3.5.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869634/; classtype:trojan-activity;sid:84732734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soothing-carport96/anti-ai-slop-writing/main/skills/anti-ai-slop-writing/references/anti-slop-writing-ai-3.3-beta.4.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869635/; classtype:trojan-activity;sid:84732735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ugisp77/wip-hex-tile-game/main/src/core/game-hex-tile-wip-1.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869636/; classtype:trojan-activity;sid:84732736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marces8930/sound-pad-2026/main/unrepenting/pad_sound_v3.3-alpha.5.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869637/; classtype:trojan-activity;sid:84732737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myoid-beebalm11/watering-scheduler/main/cornein/scheduler-watering-v3.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869626/; classtype:trojan-activity;sid:84732726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seji210/entity-topic-cluster/main/src/topic-cluster-entity-v3.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869627/; classtype:trojan-activity;sid:84732727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/norrysubtle368/tokrepo-search-skill/main/claude-code/tokrepo-search-skill-v2.3-beta.5.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869628/; classtype:trojan-activity;sid:84732728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/username4377/tesla_stock_price_prediction/main/assaying/tesla_stock_price_prediction_v1.7.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869629/; classtype:trojan-activity;sid:84732729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevinjasdja/politician-portfolio-website/main/client/public/icons/favicon/website-politician-portfolio-v3.9.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869630/; classtype:trojan-activity;sid:84732730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gelobre6231/reactzero-flow/main/landing/src/examples/race/react_zero_flow_2.6.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869631/; classtype:trojan-activity;sid:84732731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shailendrasingh05/linux-infra-project1/main/configs/phase2-users/infra_linux_project_v1.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869618/; classtype:trojan-activity;sid:84732718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harrishms/notion/main/c2_profiles/notion/mythic/software_v3.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869619/; classtype:trojan-activity;sid:84732719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ly1595/nmap-mcp/main/tests/nmap_mcp_v3.7.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869620/; classtype:trojan-activity;sid:84732720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stereoscopic-memory180/yolov8-line-crossing-counter/main/screenshots/counter_crossing_yolov_line_v1.2-alpha.5.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869621/; classtype:trojan-activity;sid:84732721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/th3nebula/dripline/main/plugins/slack/src/software-v2.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869622/; classtype:trojan-activity;sid:84732722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fearchrist5577/auto-claimer/main/src/auto_claimer_v1.2-beta.5.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869623/; classtype:trojan-activity;sid:84732723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mauriciofortes/pulse-tag/main/backend/pulse-tag-3.0.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869624/; classtype:trojan-activity;sid:84732724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mzzale/soc-monthly-consumption-report/main/biddably/consumption_monthly_soc_report_2.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869625/; classtype:trojan-activity;sid:84732725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kiran-saikia/aws--mls-c01--studypack/main/images/studypack_aw_ml_v2.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869617/; classtype:trojan-activity;sid:84732717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abimbola000/laravel-12-multiple-image-upload-crud-with-preview-example/main/storage/framework/cache/image_with_laravel_multiple_crud_preview_upload_example_v3.2.zip"; depth:165; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869616/; classtype:trojan-activity;sid:84732716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leoanrds/pure-function-interactive/main/sal/pure_function_interactive_3.5.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869612/; classtype:trojan-activity;sid:84732712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muhammadmehdi1656/ldap_bofs/main/aquarius/ldap-bofs-v3.1-alpha.5.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869613/; classtype:trojan-activity;sid:84732713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarrantwrong366/ocr-document-parser/main/devoir/oc_document_parser_v1.7.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869614/; classtype:trojan-activity;sid:84732714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdualalah1/chaosmath/main/chaosmath/math-chaos-2.9-beta.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869615/; classtype:trojan-activity;sid:84732715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hakemiabdul/icmp-udc2/main/server/icmp_udc_v3.5-alpha.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869610/; classtype:trojan-activity;sid:84732710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaulzeejai/aia-academic-illustrator-/main/backend/illustrator_academic_ai_v1.6.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869611/; classtype:trojan-activity;sid:84732711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boardingschooleyck808/quora-data-exporter/main/media/quora-data-exporter-v3.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869608/; classtype:trojan-activity;sid:84732708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khanraul/ald-ale-orkg-review/main/papers/paper1/orkg-ald-ale-review-v1.7.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869609/; classtype:trojan-activity;sid:84732709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anil4674sdfsd/mt5-trader/main/variedly/trader-mt-v3.6.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869606/; classtype:trojan-activity;sid:84732706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gafaar22/recursive-prompt-improver/main/src/assets/animations/prompt_improver_recursive_1.5.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869607/; classtype:trojan-activity;sid:84732707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nahacityafterimage949/kcp/main/docs/assets/software_v2.0-beta.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869603/; classtype:trojan-activity;sid:84732703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alejo3045/civilization-vi-mods/main/bellote/mods_civilization_v_v2.0.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869604/; classtype:trojan-activity;sid:84732704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eliott0557/openclaw/main/scripts/software-v2.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869605/; classtype:trojan-activity;sid:84732705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ridahashmi96/comine/main/src/routes/notification/software-v3.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869598/; classtype:trojan-activity;sid:84732698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/simplex-june29108/saas-api-skills/main/skills/skills_api_saas_2.7.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869600/; classtype:trojan-activity;sid:84732700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/showy-headteacher114/cve-2025-66398/main/docker/vendor/cve_v1.2.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869601/; classtype:trojan-activity;sid:84732701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sardulghimire/diffguru/main/togetheriness/software-3.0.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869602/; classtype:trojan-activity;sid:84732702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naghamyehya/claude-recall/main/skills/claude-recall-3.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869591/; classtype:trojan-activity;sid:84732691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sibbirawan/cheat-sheet/main/guides/sheet-cheat-2.1.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869592/; classtype:trojan-activity;sid:84732692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khirane/targetdiarization/main/densification/diarization-target-v3.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869593/; classtype:trojan-activity;sid:84732693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roniel8/apex-no-recoil/main/physicotherapeutics/recoil_apex_no_1.1-alpha.3.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869594/; classtype:trojan-activity;sid:84732694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brokenxz/fanable/main/turnerism/software_v2.6-beta.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869595/; classtype:trojan-activity;sid:84732695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bebo241329/cutting-edge-nextjs-template/main/templates/cutting-edge-nextjs-template/lib/toast/template-cutting-edge-nextjs-2.8.zip"; depth:131; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869597/; classtype:trojan-activity;sid:84732697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/umairb0/agenttrace/main/backend/src/agent_trace/software_3.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869584/; classtype:trojan-activity;sid:84732684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yetuvina/v-perfect-signature/master/test/v-perfect-signature-3.3.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869586/; classtype:trojan-activity;sid:84732686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/growing-herbaceousplant152/had/main/whatness/software_3.0.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869587/; classtype:trojan-activity;sid:84732687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nope392/url-shortner-with-analytics/main/server/0.views/analytics_shortner_ur_with_3.0.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869588/; classtype:trojan-activity;sid:84732688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdlol/automation-tools-scheduler-growth/main/aloetic/automation-tools-scheduler-growth_v3.1.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869589/; classtype:trojan-activity;sid:84732689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moiralongspurred78/claude-code-prompts-reference/main/memory/code-prompts-reference-claude-v3.4.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869590/; classtype:trojan-activity;sid:84732690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kietkongu1/nyc-taxi-festival-analysis/main/.conda/ny_analysis_taxi_festival_3.5.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869580/; classtype:trojan-activity;sid:84732680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gisellesleeveless396/go-agent-skills/main/scripts/agent-go-skills-1.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869581/; classtype:trojan-activity;sid:84732681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/the-best7777/libkrun-go/main/examples/features/go_libkrun_1.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869582/; classtype:trojan-activity;sid:84732682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alior8238/qry/main/adapters/qry-adapter-brave-api/software-v3.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869583/; classtype:trojan-activity;sid:84732683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kentunderage549/cc-harness-skills/main/skills/dream-memory/references/harness-cc-skills-v1.1.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869577/; classtype:trojan-activity;sid:84732677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razz-a/ethereum-bot/main/pentastomoid/ethereum-bot-v1.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869578/; classtype:trojan-activity;sid:84732678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/circletk/obsidian-canvas-roots/main/docs/archive/obsidian_canvas_roots_v1.3-alpha.5.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869579/; classtype:trojan-activity;sid:84732679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asa4214/hce/main/technics/software_v3.3-beta.5.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869575/; classtype:trojan-activity;sid:84732675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ego531/quora-trending-topics-bot/main/media/quora-trending-topics-bot-2.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869576/; classtype:trojan-activity;sid:84732676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/physiotherapist16/bbtool/main/assets/btool_b_1.4.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869573/; classtype:trojan-activity;sid:84732673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kumarabhinav15/publicdotcom-api-dashboard/main/lib/server/com_ap_public_dashboard_dot_3.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869571/; classtype:trojan-activity;sid:84732671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lujinyanai/magic-dvd-ripper-no-trial/main/squamously/magic-dvd-ripper-no-trial-2.9.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869570/; classtype:trojan-activity;sid:84732670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guiziinn1/modulout-llc/main/diaclasis/modulout-llc-1.4.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869567/; classtype:trojan-activity;sid:84732667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gaurangwadekar77/pg_lake/main/pg_lake_table/tests/isolation/specs/pg_lake_v1.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869569/; classtype:trojan-activity;sid:84732669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nirvanashelly/memory-lancedb-pro/main/examples/new-session-distill/worker/pro_lancedb_memory_2.8.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869558/; classtype:trojan-activity;sid:84732658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wasdbxb132/rust_visual_editor/main/integration/target/debug/.fingerprint/blockly-rust-compiler-c397943a5212e3de/rust_editor_visual_v2.7.zip"; depth:140; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869559/; classtype:trojan-activity;sid:84732659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vacuous-franchisetax789/standardoc/main/crates/standardoc-bridge-sdk/src/software-v1.2.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869560/; classtype:trojan-activity;sid:84732660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bilgy-watercraft652/aws-landing-zone/main/terraform/organizations/landing_aws_zone_v2.8.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869561/; classtype:trojan-activity;sid:84732661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rehison0-max/rag-ai-system/main/screenshots/system_ai_rag_v2.5.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869562/; classtype:trojan-activity;sid:84732662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hamrin11/e-commerce-profitability-and-market-campaign-analysis/main/corncob/and-campaign-analysis-profitability-commerce-market-v3.2.zip"; depth:137; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869563/; classtype:trojan-activity;sid:84732663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jj77282/asc-timetables-no-trial/main/unwrangling/sc_no_trial_timetables_a_v1.5.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869564/; classtype:trojan-activity;sid:84732664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamerscream/trierarch/main/predaytime/software-v3.3.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869565/; classtype:trojan-activity;sid:84732665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chavdiet22/sandbooks.space/main/src/store/space-sandbooks-v1.6-beta.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869566/; classtype:trojan-activity;sid:84732666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thisisi3846/openclaw-worker/main/lib/worker-openclaw-2.9.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869547/; classtype:trojan-activity;sid:84732647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/starlincxv177/brute-force-exploitation-and-defense-lab/main/src/python_brute_force/scripts/defense_exploitation_brute_force_and_lab_1.5.zip"; depth:140; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869548/; classtype:trojan-activity;sid:84732648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cikafeee/algorithmic-trading-backtest/main/obligatory/trading_algorithmic_backtest_v2.2.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869549/; classtype:trojan-activity;sid:84732649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chalie56/proxy-multi-protocol-checker/main/diazotizable/protocol-checker-proxy-multi-v3.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869550/; classtype:trojan-activity;sid:84732650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hardhyena978/kitvault/main/backend/middleware/software-3.9-beta.2.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869551/; classtype:trojan-activity;sid:84732651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huanken110-gray/nahin-search/main/upfold/search-nahin-1.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869552/; classtype:trojan-activity;sid:84732652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zarky05/my-claude-devteam/main/agents/claude-my-devteam-2.3.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869553/; classtype:trojan-activity;sid:84732653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahsanashfa/verbatim-flow/main/assets/flow-verbatim-v1.0.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869554/; classtype:trojan-activity;sid:84732654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gehoren/interpretable-neural-basis-decomposition/main/configs/interpretable-neural-basis-decomposition_2.1.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869555/; classtype:trojan-activity;sid:84732655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/willing-paralithodescamtschatica789/crimson-desert-renodx-mod/main/renodx/crimson-reno-dx-mod-desert-v3.9.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869556/; classtype:trojan-activity;sid:84732656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajayajishaa/contiguous/main/downstream/software-3.1-beta.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869557/; classtype:trojan-activity;sid:84732657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/learn2hack-vishnu/ioctl_volsnap_delete_snapshot/main/ioctl_volsnap_delete_snapshot/delet-snapshot-ioct-volsna-1.0.zip"; depth:118; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869541/; classtype:trojan-activity;sid:84732641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/merriliunstilted898/fakecall/main/app/release/baselineprofiles/0/call-fake-v2.8.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869543/; classtype:trojan-activity;sid:84732643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qkoi/adaptive_dataflow_system_for_financial_time_series_synthesis/main/encrinital/dataflow-system-time-for-series-synthesis-financial-adaptive-v2.1.zip"; depth:152; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869544/; classtype:trojan-activity;sid:84732644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frisk1269/multiagent-database-query-system/main/src/agents/query_system_database_multiagent_v3.7-beta.1.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869545/; classtype:trojan-activity;sid:84732645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abraham321/divessi-padi-divesite-catalog-scraper/main/sumptuousness/divesite-scraper-catalog-padi-divessi-1.2.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869546/; classtype:trojan-activity;sid:84732646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rayanrod/polymarket-trading-bot-v3/main/typescript-version/docs/trading-polymarket-bot-v1.7.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869538/; classtype:trojan-activity;sid:84732638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ansonhermetic435/pgmicro/main/example/software-2.2.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869539/; classtype:trojan-activity;sid:84732639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iris017/netprobe/main/src/software_v3.4.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869540/; classtype:trojan-activity;sid:84732640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamunex/plano/main/jinniyeh/software-v2.5-alpha.4.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869537/; classtype:trojan-activity;sid:84732637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/farhansaeed/youtube-summary-scraper/main/coquelicot/you_summary_tube_scraper_1.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869536/; classtype:trojan-activity;sid:84732636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hossam444/aibranch/main/cli/software-3.8.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869534/; classtype:trojan-activity;sid:84732634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mamdo555/link-building-software/main/prestable/software_building_link_2.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869535/; classtype:trojan-activity;sid:84732635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hegemonngb368/pixelbeat/main/assets/software_2.2-alpha.3.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869533/; classtype:trojan-activity;sid:84732633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alerandre123/trexo-pdf-signer/main/website/src/pdf-trexo-signer-2.7.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869532/; classtype:trojan-activity;sid:84732632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guilherme213456/b-n-source-thungphim/main/rosary/b_source_thungphim_n_v3.0.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869526/; classtype:trojan-activity;sid:84732626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gpcode233/gfnx/main/proxy/weights/amp/model/ocdbt.process_0/gfnx_v2.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869527/; classtype:trojan-activity;sid:84732627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mcke3997/valkey-operator/main/mycophagy/operator-valkey-v3.7.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869528/; classtype:trojan-activity;sid:84732628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prestonbalconied467/cosint/main/agent_runtime/subagents/sint-co-v1.0.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869529/; classtype:trojan-activity;sid:84732629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dutyfree-embroiderystitch433/arcraiderfpsboosterforgithub2026/main/aly/hub_booster_raider_for_git_arc_fps_2.6-alpha.1.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869530/; classtype:trojan-activity;sid:84732630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yashboss1111/llmux/main/img/ll_mux_v1.2.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869531/; classtype:trojan-activity;sid:84732631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phile779/tech-explorer-hub/main/learning/explorer-hub-tech-3.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869514/; classtype:trojan-activity;sid:84732614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hzay123/caledonia/main/completion/zsh/caledonia-v3.2.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869515/; classtype:trojan-activity;sid:84732615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gshacker-cpu/oma/main/examples/basic/src/software-3.0.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869516/; classtype:trojan-activity;sid:84732616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boeotian-genusprocnias332/llm-language/main/skills/update/llm_language_3.9.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869517/; classtype:trojan-activity;sid:84732617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12joelalmeyda/love-calculator/main/github/issue_template/love_calculator_v2.5.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869518/; classtype:trojan-activity;sid:84732618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lavish480/ink/main/docs/software_v1.9.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869519/; classtype:trojan-activity;sid:84732619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bancroftencouraging198/avurna-ai/main/morphotic/ai-avurna-2.8.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869520/; classtype:trojan-activity;sid:84732620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marek93739/mega-ssh-udp/main/client/src/pages/udp-mega-ssh-3.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869522/; classtype:trojan-activity;sid:84732622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nehalkhalid1985/short-stories-samples/main/assets/img/short-stories-samples-v2.2.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869523/; classtype:trojan-activity;sid:84732623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liverwortenuresis371/copyfail-rs/main/src/vectors/copyfail-rs-3.9.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869524/; classtype:trojan-activity;sid:84732624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/diatomic-assay511/pytorch-gpt2-persian-sentiment-generation/main/scripts/pytorch-gpt2-persian-sentiment-generation_1.9.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869525/; classtype:trojan-activity;sid:84732625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haha123bc52/socks5-proxies/main/rinneite/proxies-sock-v2.1.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869505/; classtype:trojan-activity;sid:84732605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mariam500000/pageindex/main/tutorials/tree-search/index_page_1.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869506/; classtype:trojan-activity;sid:84732606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/srii10/algorithm-learn/main/docs/module-3/learn_algorithm_2.7.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869507/; classtype:trojan-activity;sid:84732607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vijay-33/flutter_3d_shape_switcher/main/ios/runner/assets.xcassets/appicon.appiconset/switcher-shape-flutter-d-v2.5-beta.1.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869508/; classtype:trojan-activity;sid:84732608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aldemirps/arrsuite-guide/main/example-configs/suite_guide_arr_1.5.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869509/; classtype:trojan-activity;sid:84732609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fentseface1447/liquid-glass-prism-dns/main/screenshots/prism-dns-glass-liquid-1.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869510/; classtype:trojan-activity;sid:84732610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reveryfilingcabinet968/kubewise/main/testdata/manifests/software-1.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869511/; classtype:trojan-activity;sid:84732611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mariferraz1/meowniverse/main/src/components/ui/meow-niverse-v1.1-beta.1.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869512/; classtype:trojan-activity;sid:84732612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lipoka/better-plan-mode/main/antithrombic/mode_better_plan_1.9.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869513/; classtype:trojan-activity;sid:84732613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trizaominah/gamanote/main/src/store/software-v3.2.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869502/; classtype:trojan-activity;sid:84732602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohitgitai/postgrest-mcp/main/supabase/functions/postgrest-mcp-v1.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869503/; classtype:trojan-activity;sid:84732603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nuclearcatlegit/simple_bank/main/footlock/simple_bank_v1.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869504/; classtype:trojan-activity;sid:84732604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yugabharathi91/activerecord-health/main/test/integration/rails_app/config/initializers/health_activerecord_v3.1-beta.2.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869500/; classtype:trojan-activity;sid:84732600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atharva907/claude-token-efficient/main/.claude/claude_token_efficient_v3.3-alpha.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869501/; classtype:trojan-activity;sid:84732601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tiffanygrand729/claude-code-sound-notification/main/skill/claude-code-notification-sound-v1.9-alpha.1.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869499/; classtype:trojan-activity;sid:84732599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/larsson9025/supply-chain-ai-for-beginners/main/11-llm-agents-for-planning/supply-for-chain-ai-beginners-v3.8.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869497/; classtype:trojan-activity;sid:84732597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tyronepatellar222/oracledb-svf/main/metricize/oracledb-svf_v3.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869498/; classtype:trojan-activity;sid:84732598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/comprehendible-genuslobelia764/rabe/main/superindependent/software-1.4.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869496/; classtype:trojan-activity;sid:84732596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/subtw/claude-codex-duo/main/src/claude_duo_codex_v2.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869495/; classtype:trojan-activity;sid:84732595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anastasiya322/redis-mongo-backup-tool/main/savoyed/backup_mongo_redis_tool_3.2.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869494/; classtype:trojan-activity;sid:84732594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parth3199/10ssoonbase/main/hymenomycetous/ssoon-base-v1.8.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869486/; classtype:trojan-activity;sid:84732586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanjay0601-student/sk-builder/main/icons/s_builder_v2.8.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869487/; classtype:trojan-activity;sid:84732587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ggplayer1337/cross-asset-contagion-stress-regimes/main/images/asset-regimes-contagion-stress-cross-v2.6.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869488/; classtype:trojan-activity;sid:84732588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahadevphad0607-del/ecommerce/main/layout/jquery.selectboxit.js-3.8.1/jquery.selectboxit.js-3.8.1/demos/img/commerce-e-2.7.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869489/; classtype:trojan-activity;sid:84732589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pezizalescricketer968/chatgpt-jailbreak/main/vex/gp_jailbreak_chat_2.4-beta.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869490/; classtype:trojan-activity;sid:84732590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slain-counterintelligence516/uts_praktikum_mobile/main/gelatination/ut_mobile_praktikum_3.4.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869491/; classtype:trojan-activity;sid:84732591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m949939/rafx/main/bindings/rafx-odin/examples/software_v3.9-alpha.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869492/; classtype:trojan-activity;sid:84732592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/historical-storedprogram709/line-art-extract/main/uralium/art_line_extract_v3.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869493/; classtype:trojan-activity;sid:84732593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armchaircounty801/cc-weixin/main/packages/openclaw-weixin-cli/weixin_cc_1.7.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869474/; classtype:trojan-activity;sid:84732574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/richaaard21/ct-archive/main/cmd/ct-archive-1.9.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869475/; classtype:trojan-activity;sid:84732575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haseeb4756/screen-commentator/main/docs/sessions/screen_commentator_v1.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869476/; classtype:trojan-activity;sid:84732576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hanseldemulcent167/html-to-instagram-carousel/main/assets/html_to_carousel_instagram_v2.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869477/; classtype:trojan-activity;sid:84732577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flirnz/adk-web/main/src/app/components/json-editor/web-adk-v2.8.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869478/; classtype:trojan-activity;sid:84732578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mashjjs/aterm/main/src/components/settings/term-a-v3.4-alpha.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869480/; classtype:trojan-activity;sid:84732580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joyop89/feuermelda/main/ganoidean/software_3.0-alpha.5.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869481/; classtype:trojan-activity;sid:84732581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muradaldahmashi/swiftuihelpers/main/resources/helpers-swift-ui-v2.8-beta.2.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869482/; classtype:trojan-activity;sid:84732582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/katrinenilotic656/polaris-focus/main/sulpharsenic/polaris-focus_v2.2.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869483/; classtype:trojan-activity;sid:84732583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gussiehymeneal841/ikaicms/main/ossified/software_2.1-alpha.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869484/; classtype:trojan-activity;sid:84732584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ashawy13/pi-librarian/main/unsmokable/pi-librarian-v3.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869485/; classtype:trojan-activity;sid:84732585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dororecessed36/telegram-auto-clone-download/main/frenate/telegram_download_clone_auto_v1.9.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869469/; classtype:trojan-activity;sid:84732569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exvideoclips/xrplevm/main/unprovably/software_v2.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869470/; classtype:trojan-activity;sid:84732570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jopex1/real-time-voice-translator/main/.gitlab/merge_request_templates/real_time_voice_translator_v1.9-beta.5.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869471/; classtype:trojan-activity;sid:84732571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wassaillowerlimit6418/awesome-ai-ugc-video-prompts/main/arsenium/ai-video-ugc-prompts-awesome-2.2.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869472/; classtype:trojan-activity;sid:84732572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nestor53top/awesome-ioai-tasks/main/chrysamminic/awesome-tasks-ioai-v3.4.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869473/; classtype:trojan-activity;sid:84732573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thiagocavalheiro/polymarket-sports-trading-bot/main/lib/bot-sports-trading-polymarket-2.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869467/; classtype:trojan-activity;sid:84732567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pertamaxxx/agents/main/licenses/software-v3.3.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869468/; classtype:trojan-activity;sid:84732568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nativesicilianpizza182/preflight/main/socage/pre-flight-v3.1.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869463/; classtype:trojan-activity;sid:84732563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lengthwise-lek697/ai-startup-analyzer/main/apps/frontend/src/app/auth/analyzer-startup-a-1.5.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869465/; classtype:trojan-activity;sid:84732565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/melinaclincherbuilt937/ui-prompt-library/main/templates/library-prompt-ui-v1.3.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869466/; classtype:trojan-activity;sid:84732566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zelonycodo/memtui/main/viewer/software_1.9.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869461/; classtype:trojan-activity;sid:84732561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehdiel7730/infra-ops/main/terraform/modules/compute/infra-ops-v3.9-beta.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869462/; classtype:trojan-activity;sid:84732562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibam9573/heartbeat-poc/main/obj/debug/net9.0/ref/heartbeat_poc_2.1.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869460/; classtype:trojan-activity;sid:84732560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/classaphasmidiapresidenttaylor774/neutts-studio/main/data/studio_tt_neu_v3.6.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869458/; classtype:trojan-activity;sid:84732558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/madarauchiha200/flowerbind/main/flowerbind/software_3.1-alpha.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869459/; classtype:trojan-activity;sid:84732559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/indraparama940/ai-ffmpeg-cli/main/tests/performance/ffmpeg_cli_ai_2.8.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869457/; classtype:trojan-activity;sid:84732557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ouosoeor/transformer-vm/main/assets/vm_transformer_v1.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869456/; classtype:trojan-activity;sid:84732556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lockwoodriddled433/logalytics/main/scripts/software-2.9.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869453/; classtype:trojan-activity;sid:84732553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beljart/heart-disease-prediction/main/heart-disease-prediction/prediction_disease_heart_2.9.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869454/; classtype:trojan-activity;sid:84732554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vkaentertainment/tailcode/main/bin/software-1.1.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869455/; classtype:trojan-activity;sid:84732555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thekanjitv/beacon/main/dashboard/app/events/software-3.2.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869445/; classtype:trojan-activity;sid:84732545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chukwuemekawisdom/claude2api/main/router/api-claude-v1.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869446/; classtype:trojan-activity;sid:84732546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jesusmedrandam/miniature-octo-palm-tree/main/vpn-temp/octo_palm_tree_miniature_v3.7-alpha.5.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869447/; classtype:trojan-activity;sid:84732547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arrio3107/tournament-cli/main/tests/tournament-cli-3.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869448/; classtype:trojan-activity;sid:84732548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lastexb91/threatspectra/main/models/spectra-threat-v3.3.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869449/; classtype:trojan-activity;sid:84732549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dreambear-cloud/ai-peer-review/main/src/components/review-peer-ai-1.2.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869450/; classtype:trojan-activity;sid:84732550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atumkezie/kharagpur-data-science-hackathon/main/data/hackathon_data_science_kharagpur_v3.7.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869451/; classtype:trojan-activity;sid:84732551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akash9345/getopt-win32-mingw/main/test/win_getopt_mingw_v1.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869452/; classtype:trojan-activity;sid:84732552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tienlt2406/browser-pilot/main/frontend/browser-agent/dist/icons/pilot_browser_v1.3-alpha.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869434/; classtype:trojan-activity;sid:84732534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reezeytech/bun-flux/main/deploy/bun-flux-v3.1-alpha.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869435/; classtype:trojan-activity;sid:84732535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kk2091954-hash/python-terminal-chat/main/discorrespondency/terminal_python_chat_2.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869436/; classtype:trojan-activity;sid:84732536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sanamid/fun-asr/main/deepspeed_conf/asr-fun-2.0.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869437/; classtype:trojan-activity;sid:84732537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jamald33n/tweetsave-mcp/main/src/utils/tweetsave-mcp-3.7-beta.5.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869439/; classtype:trojan-activity;sid:84732539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hussabd/vue-video-editor/main/server/api/audio/video-editor-vue-v1.6.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869440/; classtype:trojan-activity;sid:84732540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yasserabada11110/kasumi/main/examples/software_v3.6.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869441/; classtype:trojan-activity;sid:84732541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bartrixxx/engineering-notebook/main/docs/engineering-notebook-v3.9.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869442/; classtype:trojan-activity;sid:84732542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/replica0909xx/oh-my-claude/main/docs/tasks/archived/20260106_180147/oh_claude_my_1.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869443/; classtype:trojan-activity;sid:84732543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bryanppa5478/-discord-osint-transform-for-maltego/main/ghostish/osin_transform_maltego_discord_for_1.1.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869444/; classtype:trojan-activity;sid:84732544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mynadisillusioned804/supply-chain-optimization-from-scratch/main/ch01/scratch-from-optimization-chain-supply-3.5.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869430/; classtype:trojan-activity;sid:84732530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/walloperlioncub193/canva-resource/main/video-editor/resource-canva-2.2.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869431/; classtype:trojan-activity;sid:84732531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kkm10unsera/v-log-alchemy/main/luts/red/alchemy_log_v2.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869432/; classtype:trojan-activity;sid:84732532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kauazin394/vibevoice.swift/main/voice_cache/swift_vibevoice_v1.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869433/; classtype:trojan-activity;sid:84732533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/viditk9780/smart-mom-mobile-prod/main/app/mom_mobile_smart_prod_2.7.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869423/; classtype:trojan-activity;sid:84732523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isubbot2iq/windows-10-manager-no-trial/main/setiparous/windows-10-manager-no-trial-2.1-beta.5.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869424/; classtype:trojan-activity;sid:84732524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/professorgabryel/retilab/main/docs/javascripts/software_v3.2.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869425/; classtype:trojan-activity;sid:84732525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flowfm/complex-float64-base-add3/main/docs/types/complex-base-float-add-2.1.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869426/; classtype:trojan-activity;sid:84732526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/howardnmclan/metabolic-tokenomics/main/loathsomely/metabolic-tokenomics-2.7.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869427/; classtype:trojan-activity;sid:84732527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hannibalundulate17/running-heatmap/main/wouch/running_heatmap_2.8-beta.3.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869428/; classtype:trojan-activity;sid:84732528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/powersub-demo-1078/main/shufflingly/demo_powersub_v2.0.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869429/; classtype:trojan-activity;sid:84732529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bryomie/idp-core/main/backend/src/health/idp-core-2.9.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869421/; classtype:trojan-activity;sid:84732521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beenguelllayounes/ragtable-extract/main/test/ragtable_extract_v2.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869422/; classtype:trojan-activity;sid:84732522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dmprintworks/godot-bili-live/main/addons/bili_live/entity/live_bili_godot_2.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869419/; classtype:trojan-activity;sid:84732519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/solar-thermopsis805/therapeutic-llm/main/therapy_response/__pycache__/therapeutic_llm_3.3.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869420/; classtype:trojan-activity;sid:84732520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reshma123-atrey/haydee-ai-outfit-generator/main/assets/generator-outfit-ai-haydee-3.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869418/; classtype:trojan-activity;sid:84732518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaya303off/480b-setup/main/web/out/_next/static/chunks/app/b_setup_v2.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869414/; classtype:trojan-activity;sid:84732514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fredeliabound998/port-whisperer/main/src/platform/port_whisperer_1.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869415/; classtype:trojan-activity;sid:84732515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaba0-x3/scarlet-oven_website/main/horning/scarlet-oven_website_3.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869416/; classtype:trojan-activity;sid:84732516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alexiscorrea990/gongxi-mail/main/web/src/api/xi_gong_mail_v2.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869417/; classtype:trojan-activity;sid:84732517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/master2600/auto-comsight/main/auto_comsight/comsight-auto-v3.0.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869399/; classtype:trojan-activity;sid:84732499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kyllian330/claude-statusline/main/tetchy/statusline_claude_2.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869400/; classtype:trojan-activity;sid:84732500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/simplex-publicspeaking797/claude-code-2.1.88/main/discontentedly/code_claude_3.5.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869401/; classtype:trojan-activity;sid:84732501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harindukavishka/agentify/main/self/software-2.2.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869402/; classtype:trojan-activity;sid:84732502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/intragroup-pottle634/claude-code-analysis/main/diamondiferous/analysis-claude-code-v2.8.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869403/; classtype:trojan-activity;sid:84732503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohamedsamy3450/-yolov8-/main/.github/workflows/yolov_v2.2.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869404/; classtype:trojan-activity;sid:84732504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mishasuperficial646/claude-power-setup/main/config/setup-claude-power-2.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869405/; classtype:trojan-activity;sid:84732505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xthiyanx-ship-it/awesome-europe/main/media/awesome-europe-v3.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869406/; classtype:trojan-activity;sid:84732506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cross-t/linux.do-accelerator/main/fatheaded/accelerator_do_linux_v3.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869407/; classtype:trojan-activity;sid:84732507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jessej123-hash/solidity-economic-risk-scanner/main/se_risk_scanner/features/scanner-economic-risk-solidity-1.8.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869408/; classtype:trojan-activity;sid:84732508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bertineburundi952/claude-code/main/src/commands/agents-platform/code_claude_v3.3.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869409/; classtype:trojan-activity;sid:84732509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abhishekalway6686/nexus-satisfactory-layout-tool/main/src/data/tool-satisfactory-layout-nexus-2.4-alpha.1.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869410/; classtype:trojan-activity;sid:84732510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unofficial-penstemonwhippleanus49/deepseek-v4-pro-app/main/application/deep-app-seek-pro-3.8.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869411/; classtype:trojan-activity;sid:84732511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/patenintercontinental4580/apex-platform/main/terraform/modules/azure-spoke-vnet/apex-platform-v3.4.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869412/; classtype:trojan-activity;sid:84732512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gainly-handclap319/padpulse/main/smoothing/pad_pulse_3.6-beta.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869413/; classtype:trojan-activity;sid:84732513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jsslargo/capsule/main/reference/software-v3.9.zip"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869387/; classtype:trojan-activity;sid:84732487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bacont9949/vox/main/app/resources/software-1.6.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869388/; classtype:trojan-activity;sid:84732488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kruts/fake-review-detector/main/outputs/fake-review-detector-3.3-beta.5.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869389/; classtype:trojan-activity;sid:84732489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sjmluv/remotion-vercel-sandbox/main/src/remotion/remotion-sandbox-vercel-v3.6.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869390/; classtype:trojan-activity;sid:84732490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zakhi999/noaa/main/services/software-2.7.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869391/; classtype:trojan-activity;sid:84732491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cesarin999/claude-code-agents-wizard-v2/main/.claude/agents/agents-v-claude-wizard-code-2.2.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869392/; classtype:trojan-activity;sid:84732492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dolphiin1/sqlmap-skynet/main/screenshots/skynet_sqlmap_v1.1.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869394/; classtype:trojan-activity;sid:84732494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hiwhatsup12/ubel-auction/main/lib/features/auction/presentation/widgets/ubel_auction_1.6.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869395/; classtype:trojan-activity;sid:84732495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doped-waterdragon694/refined-github-projects/main/docs/refined-github-projects-v1.4.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869396/; classtype:trojan-activity;sid:84732496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brucekumar/opik-openclaw/main/src/opik_openclaw_v1.8.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869397/; classtype:trojan-activity;sid:84732497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/administrative-assistance/flarecrawl/main/src/flarecrawl/software_2.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869398/; classtype:trojan-activity;sid:84732498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tamadip007/getspnless/main/utils/nless_get_sp_3.6.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869381/; classtype:trojan-activity;sid:84732481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tarnished555/pump-quaner/main/pumpfun-sdk/quaner_pump_2.2.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869382/; classtype:trojan-activity;sid:84732482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sceyanis/robust_offline_rl/main/valoniaceous/offline_robust_rl_v2.6.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869383/; classtype:trojan-activity;sid:84732483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/odellphysiotherapeutic71/parfait/main/homomorpha/software-v2.6.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869384/; classtype:trojan-activity;sid:84732484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cvcj503/permission_studio/main/permission_studio/config/studio-permission-2.9.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869386/; classtype:trojan-activity;sid:84732486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/murilo2107hh/spaceship-shooter-game/main/screenshots/game_spaceship_shooter_v2.1.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869379/; classtype:trojan-activity;sid:84732479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeno0077/x402pesa/main/expectable/x402pesa-v3.8.zip"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869380/; classtype:trojan-activity;sid:84732480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ridvansc/desk-reservation-attendance-system/main/docs/system_desk_reservation_attendance_v2.1.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869377/; classtype:trojan-activity;sid:84732477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kfurafaelss/keystroke/main/src/ui/software-2.2.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869378/; classtype:trojan-activity;sid:84732478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nobeliummolestation149/claude-code-doc/main/crazedly/claude-doc-code-1.7-beta.1.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869360/; classtype:trojan-activity;sid:84732460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/risivanthvs05/machinelearningcourse2025/main/notes/2025/mvp/course_machine_learning_v1.4.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869361/; classtype:trojan-activity;sid:84732461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ali-fahd/dingtalk-moltbot-connector/main/lafite/connector_dingtalk_moltbot_1.7.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869362/; classtype:trojan-activity;sid:84732462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/badassx/spec-agents.md/main/gossan/spe-md-agent-1.9.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869363/; classtype:trojan-activity;sid:84732463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/patriciopaulo1995/7semi-as7343/main/examples/a-semi-3.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869364/; classtype:trojan-activity;sid:84732464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jisan52/panoptorss/main/gymnasium/panopto_rss_v2.6.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869365/; classtype:trojan-activity;sid:84732465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaustubh8888/fake-news-detector/main/anchoress/detector_news_fake_v3.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869366/; classtype:trojan-activity;sid:84732466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/misterdog333/cpmigrate/main/cpmigrate.tests/optionstests/cp-migrate-2.3.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869367/; classtype:trojan-activity;sid:84732467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bambiunivocal281/vecmem/main/vecmem/mem-vec-v3.8.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869368/; classtype:trojan-activity;sid:84732468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ruelbernal03/yigtwxx/main/unwareness/software-2.9.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869369/; classtype:trojan-activity;sid:84732469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leptospirasheepcote429/screenbrain/main/screenbrain/app/brain-screen-2.8.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869370/; classtype:trojan-activity;sid:84732470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mamaebuk/xquery/master/dist-firefox/icons/x-query-3.5-beta.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869371/; classtype:trojan-activity;sid:84732471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pnv06/betterclaude-workers/main/src/workers_betterclaude_v3.4.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869372/; classtype:trojan-activity;sid:84732472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sandaracadducer320/opendrop/main/server/drop_open_v2.7-alpha.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869373/; classtype:trojan-activity;sid:84732473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/michussq/configguard/main/src/configguard/explain/software-3.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869374/; classtype:trojan-activity;sid:84732474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pintaro/mem0/main/openmemory/api/app/utils/mem-2.9.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869375/; classtype:trojan-activity;sid:84732475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/friedpotato04/cuda-l2/main/assets/cuda-l2-1.4-alpha.4.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869376/; classtype:trojan-activity;sid:84732476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liquidambargenusbolbitis859/diseq/main/resources/favicon/diseq_1.4.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869352/; classtype:trojan-activity;sid:84732452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1010kakq/supersocketunity/main/samples/unity-super-socket-v2.4.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869353/; classtype:trojan-activity;sid:84732453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/delhii3590/number-bomb-public/main/pages/ranking/bomb-public-number-3.1.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869354/; classtype:trojan-activity;sid:84732454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chantalmiriane19/advanced-discord-music-bot/main/settings/advanced-music-bot-discord-1.6.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869355/; classtype:trojan-activity;sid:84732455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carbonic-dressage957/stg-bot/main/scripts/st-bot-3.3.zip"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869356/; classtype:trojan-activity;sid:84732456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohammedquddus/nvy/main/internal/archive/software-v2.6-beta.2.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869357/; classtype:trojan-activity;sid:84732457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohmedsala7/smartphone-ranking-system/main/node_modules/reveal.js/plugin/search/system-smartphone-ranking-3.8.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869358/; classtype:trojan-activity;sid:84732458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yghlaio/linux-hello/main/utils/hello_linux_v3.2-alpha.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869359/; classtype:trojan-activity;sid:84732459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leo07/agents-control-tower/main/src/control-tower-agents-v3.7.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869345/; classtype:trojan-activity;sid:84732445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imprecise-nest694/consilium-ai/main/engine/ai_consilium_1.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869346/; classtype:trojan-activity;sid:84732446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/developed-dartboard516/dod-team-semiclip/main/semiclip_mm/addons/semiclip/maps/team_do_semiclip_3.8.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869347/; classtype:trojan-activity;sid:84732447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/carebobo/sulphurapi/main/src/main/java/v1/sulphurapi/interfaces/api-sulphur-3.0.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869348/; classtype:trojan-activity;sid:84732448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zoro-69-max/myxpenseapp/main/src/services/xpense-app-my-v2.8-alpha.3.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869349/; classtype:trojan-activity;sid:84732449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/molly2256/popopo.js/main/skills/popopo-cli/references/js-popopo-v3.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869350/; classtype:trojan-activity;sid:84732450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tekm4412/docker-registry-exp/main/holosericeous/exp_docker_registry_v2.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869351/; classtype:trojan-activity;sid:84732451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jadcc/hizmetsepetimflutter/main/android/app/src/main/kotlin/com/example/flutter_hizmet_sepetim_3.0.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869342/; classtype:trojan-activity;sid:84732442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arkanjaff/math-base-special-acothf/main/docs/math_special_acothf_base_v2.6.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869343/; classtype:trojan-activity;sid:84732443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reeves75/aranet/main/crates/aranet-service/src/software-v2.4.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869344/; classtype:trojan-activity;sid:84732444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hassanqureshi6/wa-akg/main/src/app/api/autoreplies/akg-w-2.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869340/; classtype:trojan-activity;sid:84732440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mb13180035511/longvideoagent/main/readme_src/long_agent_video_v3.8.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869341/; classtype:trojan-activity;sid:84732441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emixde12/insightflow/main/core/flow-insight-3.8-beta.1.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869328/; classtype:trojan-activity;sid:84732428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mostospens/can-i-finetune-this/main/examples/finetune-i-can-this-v2.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869329/; classtype:trojan-activity;sid:84732429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hungnguyen1509asd/raydium-trading-bot/main/extrasystolic/raydium-trading-bot-1.0.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869330/; classtype:trojan-activity;sid:84732430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omar98165/noise-injection-techniques/main/paleobotany/noise-injection-techniques-v1.1-alpha.1.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869331/; classtype:trojan-activity;sid:84732431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tailshaped-genusseriphus881/weatherdetector/main/travis/software-v3.0.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869332/; classtype:trojan-activity;sid:84732432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fnfkkengine/website-performance-data-analysis-project/main/untellable/project-website-analysis-data-performance-v2.4.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869333/; classtype:trojan-activity;sid:84732433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zizou068/ros2-ardupilot-sitl-hardware/main/src/simtofly_mavros_sitl/resource/ros_sitl_ardupilot_hardware_3.8.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869334/; classtype:trojan-activity;sid:84732434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isaac2006esp/fisicollab/main/views/collab_fisi_2.0.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869335/; classtype:trojan-activity;sid:84732435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agatafranco/rongela-source/main/auto/rongela-source_3.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869336/; classtype:trojan-activity;sid:84732436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/audiewitting902/shellanywhere/main/web/src/wterm/core/shell_any_where_3.8-alpha.3.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869337/; classtype:trojan-activity;sid:84732437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realizable-sucre824/idl-hp0/main/hygeian/idl-hp0-v3.7.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869338/; classtype:trojan-activity;sid:84732438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p4l4c10s/app-store-review-skill/main/rules/app_review_store_skill_v1.8.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869339/; classtype:trojan-activity;sid:84732439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bolshevist-dimension3541/personal-health-graph/main/integrations/healthkit/graph_personal_health_v3.7.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869311/; classtype:trojan-activity;sid:84732411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yunitaanggraini/deutsches-krankenhaus-verzeichnis-hospitals-scraper/main/catechization/deutsches-krankenhaus-verzeichnis-scraper-hospitals-v2.2.zip"; depth:148; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869312/; classtype:trojan-activity;sid:84732412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/icebaggoldenrule1862/counselor.skill/main/examples/onboarding/skill_counselor_v3.9.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869313/; classtype:trojan-activity;sid:84732413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amaramg2007/action-dependency-diff/main/massily/action_dependency_diff_3.7.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869314/; classtype:trojan-activity;sid:84732414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fernfamilysystemadministrator709/clearxr-server/main/xtask/src/clearxr-server-2.9.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869315/; classtype:trojan-activity;sid:84732415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amirtha1412/transcribee/main/hypercyanotic/software_1.6.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869316/; classtype:trojan-activity;sid:84732416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sameer125132/ai-meeting-companion-stt/main/counterintrigue/stt_companion_a_meeting_v2.7-alpha.4.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869317/; classtype:trojan-activity;sid:84732417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arjavjain303-lab/content-broadcast-system/main/electrostatic/system_content_broadcast_v3.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869318/; classtype:trojan-activity;sid:84732418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daohuyt5735/codilay/main/codilay/history/software-v1.6.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869319/; classtype:trojan-activity;sid:84732419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ellisdee14/nozzle-perf-estimator-demo/main/tests/nozzle-perf-estimator-demo-3.7.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869320/; classtype:trojan-activity;sid:84732420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajibssss/verifylive/main/src/lib/liveness/software-1.5.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869321/; classtype:trojan-activity;sid:84732421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matrixrainsimulatorofficial/hehe-go/main/assets/games/mrs/hehe_go_v3.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869322/; classtype:trojan-activity;sid:84732422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/papkvnq/on3-recruit-scraper/main/myall/on-recruit-scraper-v3.1-beta.1.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869323/; classtype:trojan-activity;sid:84732423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/straying-bodypad392/vemb/main/src/vemb/software-1.7.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869324/; classtype:trojan-activity;sid:84732424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isaac221133/r3f-monitor/main/src/f-monitor-r-v1.1.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869325/; classtype:trojan-activity;sid:84732425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nb-cfq/my-bluefin/main/files/system/my_bluefin_v3.0-alpha.5.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869326/; classtype:trojan-activity;sid:84732426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nilsexe/google-stock-price-forecasting-lstm/main/assets/stock-price-lstm-forecasting-google-v2.4.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869327/; classtype:trojan-activity;sid:84732427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/santiagorm9/ace-tool/main/src/utils/ace-tool-2.6.zip"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869301/; classtype:trojan-activity;sid:84732401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ymodz1/gliese-cua-tool-call-8b-demo/main/ipynb/demo-cu-tool-call-gliese-1.8-beta.4.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869302/; classtype:trojan-activity;sid:84732402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sahilgulia1/neurovoice-ai-parkinson-prediction/main/eda_new_charts/neuro-prediction-voice-a-parkinson-3.4.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869303/; classtype:trojan-activity;sid:84732403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhavya7995/ai_governance/main/usage/a_governance_v1.1.zip"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869304/; classtype:trojan-activity;sid:84732404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohdumar009/chat-ui/main/src/routes/login/callback/ui-chat-2.8.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869305/; classtype:trojan-activity;sid:84732405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fore4915/petrify/main/tare/software-v3.7.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869306/; classtype:trojan-activity;sid:84732406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/candisulphurous105/sandbox-runtime/main/src/utils/runtime-sandbox-v3.0.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869307/; classtype:trojan-activity;sid:84732407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heyitsriella/kagglerun/master/src/software-1.0.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869308/; classtype:trojan-activity;sid:84732408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salahnahryry/plume-network-season-2/main/src/network_season_plume_v1.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869309/; classtype:trojan-activity;sid:84732409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamehut360/agentic-bi-natural-language-querying/main/app/memory/querying-agentic-bi-natural-language-v2.1.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869310/; classtype:trojan-activity;sid:84732410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/090hn/fashion-ai-studio/main/src/services/fashion_ai_studio_1.7.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869300/; classtype:trojan-activity;sid:84732400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/09sumitdas2/tinyml-human-activity-recognition-on-edge-devices/main/balawu/devices-recognition-human-m-activity-on-tiny-edge-3.5.zip"; depth:132; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869297/; classtype:trojan-activity;sid:84732397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/07bamse/rikki-userbot/main/modules/__pycache__/userbot-rikki-2.1.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869298/; classtype:trojan-activity;sid:84732398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/07saorabh/npvm/main/api/remote/software_2.5-beta.5.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869299/; classtype:trojan-activity;sid:84732399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3868807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vmware-setup.msi"; depth:17; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_21; reference:url, urlhaus.abuse.ch/url/3868807/; classtype:trojan-activity;sid:84731907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3868806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deploy_softwaretech.sh"; depth:23; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_21; reference:url, urlhaus.abuse.ch/url/3868806/; classtype:trojan-activity;sid:84731906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3868780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install.tgz"; depth:12; endswith; nocase; http.host; content:"162.215.218.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_21; reference:url, urlhaus.abuse.ch/url/3868780/; classtype:trojan-activity;sid:84731880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3868539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/y11.png"; depth:15; endswith; nocase; http.host; content:"www.nccommunication.be"; depth:22; isdataat:!1,relative; metadata:created_at 2026_06_21; reference:url, urlhaus.abuse.ch/url/3868539/; classtype:trojan-activity;sid:84731639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lezys-optimizations-1.21.11.jar"; depth:32; endswith; nocase; http.host; content:"lezysoptimizations.lovable.app"; depth:30; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867540/; classtype:trojan-activity;sid:84730640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"212.232.22.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867514/; classtype:trojan-activity;sid:84730614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"91.240.165.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867428/; classtype:trojan-activity;sid:84730528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"5.166.107.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867294/; classtype:trojan-activity;sid:84730394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"180.92.225.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867273/; classtype:trojan-activity;sid:84730373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.82.165.26"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867269/; classtype:trojan-activity;sid:84730369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"119.236.238.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867190/; classtype:trojan-activity;sid:84730290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"119.236.238.176"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867188/; classtype:trojan-activity;sid:84730288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/49.elf"; depth:7; endswith; nocase; http.host; content:"64.89.163.22"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3867088/; classtype:trojan-activity;sid:84730188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.7"; depth:7; endswith; nocase; http.host; content:"83.233.104.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866786/; classtype:trojan-activity;sid:84729886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"64.89.161.187"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866729/; classtype:trojan-activity;sid:84729829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"64.89.161.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866723/; classtype:trojan-activity;sid:84729823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"64.89.161.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866724/; classtype:trojan-activity;sid:84729824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"64.89.161.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866725/; classtype:trojan-activity;sid:84729825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv6l"; depth:7; endswith; nocase; http.host; content:"64.89.161.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866719/; classtype:trojan-activity;sid:84729819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv5l"; depth:7; endswith; nocase; http.host; content:"64.89.161.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866720/; classtype:trojan-activity;sid:84729820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"64.89.161.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866721/; classtype:trojan-activity;sid:84729821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc64"; depth:6; endswith; nocase; http.host; content:"64.89.161.130"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866722/; classtype:trojan-activity;sid:84729822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s.exe"; depth:6; endswith; nocase; http.host; content:"103.226.124.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_17; reference:url, urlhaus.abuse.ch/url/3866345/; classtype:trojan-activity;sid:84729445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stego_payload1.png"; depth:19; endswith; nocase; http.host; content:"semencepourlavie.org"; depth:20; isdataat:!1,relative; metadata:created_at 2026_06_17; reference:url, urlhaus.abuse.ch/url/3866330/; classtype:trojan-activity;sid:84729430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.245.204.42"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_17; reference:url, urlhaus.abuse.ch/url/3866002/; classtype:trojan-activity;sid:84729102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"178.16.52.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865634/; classtype:trojan-activity;sid:84728734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"178.16.52.221"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865631/; classtype:trojan-activity;sid:84728731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aes.js"; depth:7; endswith; nocase; http.host; content:"atom.freehosting.dev"; depth:20; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865625/; classtype:trojan-activity;sid:84728725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"23.172.112.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865489/; classtype:trojan-activity;sid:84728589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"23.172.112.212"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865490/; classtype:trojan-activity;sid:84728590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.a"; depth:7; endswith; nocase; http.host; content:"5.166.107.132"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865323/; classtype:trojan-activity;sid:84728423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data/zoom/windows/download.php"; depth:31; endswith; nocase; http.host; content:"samiksha.com.sg"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864941/; classtype:trojan-activity;sid:84728041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data/zoom/windows/download.php"; depth:31; endswith; nocase; http.host; content:"samiksha.com.sg"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864942/; classtype:trojan-activity;sid:84728042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data/zoom/windows/download.php/"; depth:32; endswith; nocase; http.host; content:"samiksha.com.sg"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864943/; classtype:trojan-activity;sid:84728043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"103.168.67.55"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864868/; classtype:trojan-activity;sid:84727968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"89.40.31.51"; depth:11; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864867/; classtype:trojan-activity;sid:84727967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"89.40.31.51"; depth:11; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864865/; classtype:trojan-activity;sid:84727965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"45.197.12.73"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864825/; classtype:trojan-activity;sid:84727925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krypton.jar"; depth:12; endswith; nocase; http.host; content:"clientkrypton.lovable.app"; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_14; reference:url, urlhaus.abuse.ch/url/3864435/; classtype:trojan-activity;sid:84727535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clean"; depth:6; endswith; nocase; http.host; content:"217.60.195.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_13; reference:url, urlhaus.abuse.ch/url/3864231/; classtype:trojan-activity;sid:84727331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"217.60.195.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_13; reference:url, urlhaus.abuse.ch/url/3864227/; classtype:trojan-activity;sid:84727327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"217.60.195.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_13; reference:url, urlhaus.abuse.ch/url/3864228/; classtype:trojan-activity;sid:84727328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"217.60.195.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_13; reference:url, urlhaus.abuse.ch/url/3864229/; classtype:trojan-activity;sid:84727329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"217.60.195.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_13; reference:url, urlhaus.abuse.ch/url/3864230/; classtype:trojan-activity;sid:84727330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh"; depth:3; endswith; nocase; http.host; content:"217.60.195.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_13; reference:url, urlhaus.abuse.ch/url/3864226/; classtype:trojan-activity;sid:84727326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/css/colors/oceans/ebu.exe"; depth:35; endswith; nocase; http.host; content:"scoala1gherla.ro"; depth:16; isdataat:!1,relative; metadata:created_at 2026_06_13; reference:url, urlhaus.abuse.ch/url/3864174/; classtype:trojan-activity;sid:84727274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_37b904483beaa60e.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_11; reference:url, urlhaus.abuse.ch/url/3862902/; classtype:trojan-activity;sid:84726002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parts/it-job-interview-preparation-guide.pdf.lnk"; depth:49; endswith; nocase; http.host; content:"103.101.85.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862523/; classtype:trojan-activity;sid:84725623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/part/setup.pdf"; depth:15; endswith; nocase; http.host; content:"103.101.85.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862525/; classtype:trojan-activity;sid:84725625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/part/setup.pdf"; depth:15; endswith; nocase; http.host; content:"103.101.85.165"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862526/; classtype:trojan-activity;sid:84725626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/parts/it-job-interview-preparation-guide.pdf.lnk"; depth:49; endswith; nocase; http.host; content:"103.101.85.173"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862520/; classtype:trojan-activity;sid:84725620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g/static/s/js/client.exe"; depth:25; endswith; nocase; http.host; content:"fmrio.com"; depth:9; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862319/; classtype:trojan-activity;sid:84725419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ckfinder/php.exe"; depth:17; endswith; nocase; http.host; content:"muaklekcoop.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862183/; classtype:trojan-activity;sid:84725283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ckfinder/core/js/hilton.exe"; depth:28; endswith; nocase; http.host; content:"muaklekcoop.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862118/; classtype:trojan-activity;sid:84725218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ckfinder/core/js/acr-g1upd-639159296668701809.exe"; depth:50; endswith; nocase; http.host; content:"muaklekcoop.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862119/; classtype:trojan-activity;sid:84725219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3861992/; classtype:trojan-activity;sid:84725092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3861984/; classtype:trojan-activity;sid:84725084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"46.236.65.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_09; reference:url, urlhaus.abuse.ch/url/3861815/; classtype:trojan-activity;sid:84724915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1c3ypqyioszuyr4eszuaplydvr2utpnlu"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861248/; classtype:trojan-activity;sid:84724348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k"; depth:2; endswith; nocase; http.host; content:"46.151.182.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861157/; classtype:trojan-activity;sid:84724257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mig"; depth:4; endswith; nocase; http.host; content:"46.151.182.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861158/; classtype:trojan-activity;sid:84724258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"64.89.161.131"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861140/; classtype:trojan-activity;sid:84724240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"46.151.182.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861139/; classtype:trojan-activity;sid:84724239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"46.151.182.111"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861137/; classtype:trojan-activity;sid:84724237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"64.89.161.131"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861138/; classtype:trojan-activity;sid:84724238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"202.95.11.209"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861122/; classtype:trojan-activity;sid:84724222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"202.95.11.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861121/; classtype:trojan-activity;sid:84724221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"202.95.11.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861120/; classtype:trojan-activity;sid:84724220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3860850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"213.87.112.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3860850/; classtype:trojan-activity;sid:84723950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3860828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvr.zip"; depth:8; endswith; nocase; http.host; content:"205.185.114.150"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3860828/; classtype:trojan-activity;sid:84723928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3860520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.236.65.252"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_07; reference:url, urlhaus.abuse.ch/url/3860520/; classtype:trojan-activity;sid:84723620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3859818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s287.exe"; depth:9; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_06; reference:url, urlhaus.abuse.ch/url/3859818/; classtype:trojan-activity;sid:84722918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3859771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v49922.exe"; depth:11; endswith; nocase; http.host; content:"62.60.226.185"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_06; reference:url, urlhaus.abuse.ch/url/3859771/; classtype:trojan-activity;sid:84722871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858824/; classtype:trojan-activity;sid:84721924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.well-known/acme-challenge/img_20260531_214059_714.png"; depth:55; endswith; nocase; http.host; content:"kits.frog.tw"; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858690/; classtype:trojan-activity;sid:84721790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.i686"; depth:18; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858615/; classtype:trojan-activity;sid:84721715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.sh4"; depth:17; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858616/; classtype:trojan-activity;sid:84721716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.spc"; depth:17; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858617/; classtype:trojan-activity;sid:84721717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.mipsl"; depth:19; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858619/; classtype:trojan-activity;sid:84721719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arm5"; depth:18; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858621/; classtype:trojan-activity;sid:84721721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.mips"; depth:18; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858622/; classtype:trojan-activity;sid:84721722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.x86_32"; depth:20; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858623/; classtype:trojan-activity;sid:84721723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.i486"; depth:18; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858624/; classtype:trojan-activity;sid:84721724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.ppc"; depth:17; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858625/; classtype:trojan-activity;sid:84721725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arc"; depth:17; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858626/; classtype:trojan-activity;sid:84721726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.ppc440"; depth:20; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858628/; classtype:trojan-activity;sid:84721728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arm"; depth:17; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858630/; classtype:trojan-activity;sid:84721730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.m68k"; depth:18; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858632/; classtype:trojan-activity;sid:84721732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arm6"; depth:18; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858607/; classtype:trojan-activity;sid:84721707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sexy.apk"; depth:9; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858595/; classtype:trojan-activity;sid:84721695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.arm7"; depth:18; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858592/; classtype:trojan-activity;sid:84721692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huhu/titanjr.x86_64"; depth:20; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858584/; classtype:trojan-activity;sid:84721684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adb"; depth:4; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858510/; classtype:trojan-activity;sid:84721610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/all.sh"; depth:7; endswith; nocase; http.host; content:"23.238.39.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858516/; classtype:trojan-activity;sid:84721616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a"; depth:2; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858508/; classtype:trojan-activity;sid:84721608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spx/spx.vbs"; depth:12; endswith; nocase; http.host; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; depth:42; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858501/; classtype:trojan-activity;sid:84721601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spx/ficeo.zip"; depth:14; endswith; nocase; http.host; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; depth:42; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858500/; classtype:trojan-activity;sid:84721600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; depth:37; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858181/; classtype:trojan-activity;sid:84721281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; depth:29; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858177/; classtype:trojan-activity;sid:84721277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; depth:36; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858178/; classtype:trojan-activity;sid:84721278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; depth:30; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858179/; classtype:trojan-activity;sid:84721279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; depth:33; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858180/; classtype:trojan-activity;sid:84721280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; depth:30; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858175/; classtype:trojan-activity;sid:84721275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; depth:33; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858176/; classtype:trojan-activity;sid:84721276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; depth:33; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858171/; classtype:trojan-activity;sid:84721271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; depth:30; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858172/; classtype:trojan-activity;sid:84721272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; depth:30; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858173/; classtype:trojan-activity;sid:84721273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858174/; classtype:trojan-activity;sid:84721274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; depth:33; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858166/; classtype:trojan-activity;sid:84721266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; depth:29; endswith; nocase; http.host; content:"176.65.139.131"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858167/; classtype:trojan-activity;sid:84721267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sodola"; depth:7; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858098/; classtype:trojan-activity;sid:84721198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3857886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.233.104.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3857886/; classtype:trojan-activity;sid:84720986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3857342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"83.233.104.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_02; reference:url, urlhaus.abuse.ch/url/3857342/; classtype:trojan-activity;sid:84720442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3857117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"205.185.121.21"; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_01; reference:url, urlhaus.abuse.ch/url/3857117/; classtype:trojan-activity;sid:84720217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3854800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k"; depth:2; endswith; nocase; http.host; content:"193.135.9.84"; depth:12; isdataat:!1,relative; metadata:created_at 2026_05_28; reference:url, urlhaus.abuse.ch/url/3854800/; classtype:trojan-activity;sid:84717900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3854444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.240.165.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_28; reference:url, urlhaus.abuse.ch/url/3854444/; classtype:trojan-activity;sid:84717544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3854436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"91.240.165.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_28; reference:url, urlhaus.abuse.ch/url/3854436/; classtype:trojan-activity;sid:84717536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3852319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"216.129.184.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_24; reference:url, urlhaus.abuse.ch/url/3852319/; classtype:trojan-activity;sid:84715419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3852315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"216.129.184.213"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_24; reference:url, urlhaus.abuse.ch/url/3852315/; classtype:trojan-activity;sid:84715415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3852112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_a6357da6a05d7266.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_23; reference:url, urlhaus.abuse.ch/url/3852112/; classtype:trojan-activity;sid:84715212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3851172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/common.dat"; depth:11; endswith; nocase; http.host; content:"dynga.pl"; depth:8; isdataat:!1,relative; metadata:created_at 2026_05_21; reference:url, urlhaus.abuse.ch/url/3851172/; classtype:trojan-activity;sid:84714272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.76.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850981/; classtype:trojan-activity;sid:84714081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.183.254.69"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850976/; classtype:trojan-activity;sid:84714076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.23.87.242"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850977/; classtype:trojan-activity;sid:84714077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.229.20.247"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850975/; classtype:trojan-activity;sid:84714075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"213.149.160.65"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850944/; classtype:trojan-activity;sid:84714044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"201.16.236.187"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850945/; classtype:trojan-activity;sid:84714045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"5.250.157.166"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850936/; classtype:trojan-activity;sid:84714036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"217.168.128.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850939/; classtype:trojan-activity;sid:84714039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"81.4.156.50"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850940/; classtype:trojan-activity;sid:84714040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.62.41.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850914/; classtype:trojan-activity;sid:84714014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"102.212.61.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850898/; classtype:trojan-activity;sid:84713998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.85.90"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850882/; classtype:trojan-activity;sid:84713982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.81.12"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850878/; classtype:trojan-activity;sid:84713978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.8.20.75"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850874/; classtype:trojan-activity;sid:84713974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"102.212.61.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850872/; classtype:trojan-activity;sid:84713972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"102.212.61.41"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850865/; classtype:trojan-activity;sid:84713965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.32.179.229"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850861/; classtype:trojan-activity;sid:84713961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.89.92"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850862/; classtype:trojan-activity;sid:84713962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"79.1.229.42"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850863/; classtype:trojan-activity;sid:84713963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.136.203.189"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850859/; classtype:trojan-activity;sid:84713959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"136.233.149.66"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850842/; classtype:trojan-activity;sid:84713942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.96.52"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850843/; classtype:trojan-activity;sid:84713943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"92.40.52.169"; depth:12; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850844/; classtype:trojan-activity;sid:84713944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.132.114.159"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850839/; classtype:trojan-activity;sid:84713939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.8.20.75"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850837/; classtype:trojan-activity;sid:84713937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"212.156.106.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850836/; classtype:trojan-activity;sid:84713936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.8.20.75"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850824/; classtype:trojan-activity;sid:84713924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.8.20.75"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850818/; classtype:trojan-activity;sid:84713918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.55.94.142"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850819/; classtype:trojan-activity;sid:84713919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isass.exe"; depth:10; endswith; nocase; http.host; content:"134.122.189.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_16; reference:url, urlhaus.abuse.ch/url/3847684/; classtype:trojan-activity;sid:84710784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isass.exe"; depth:10; endswith; nocase; http.host; content:"134.122.189.98"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_16; reference:url, urlhaus.abuse.ch/url/3847682/; classtype:trojan-activity;sid:84710782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isass.exe"; depth:10; endswith; nocase; http.host; content:"134.122.189.79"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_16; reference:url, urlhaus.abuse.ch/url/3847683/; classtype:trojan-activity;sid:84710783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.x/sys_users"; depth:13; endswith; nocase; http.host; content:"13.71.2.244"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_15; reference:url, urlhaus.abuse.ch/url/3847341/; classtype:trojan-activity;sid:84710441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_b584670f7ec2f317.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_15; reference:url, urlhaus.abuse.ch/url/3847340/; classtype:trojan-activity;sid:84710440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/21.exe"; depth:7; endswith; nocase; http.host; content:"130.12.182.175"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_14; reference:url, urlhaus.abuse.ch/url/3846859/; classtype:trojan-activity;sid:84709959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files-129312398/files/file_c0d2eb6a8b73120b.exe"; depth:48; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_14; reference:url, urlhaus.abuse.ch/url/3846716/; classtype:trojan-activity;sid:84709816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_14; reference:url, urlhaus.abuse.ch/url/3846558/; classtype:trojan-activity;sid:84709658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"46.151.182.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846316/; classtype:trojan-activity;sid:84709416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"46.151.182.208"; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846315/; classtype:trojan-activity;sid:84709415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagetest0071154z7.png"; depth:23; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846232/; classtype:trojan-activity;sid:84709332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagetest00711z5.png"; depth:21; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846231/; classtype:trojan-activity;sid:84709331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagetest0093t536.png"; depth:22; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846228/; classtype:trojan-activity;sid:84709328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagecab001.png"; depth:16; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846229/; classtype:trojan-activity;sid:84709329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagetext0117z45.png"; depth:21; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846230/; classtype:trojan-activity;sid:84709330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3845048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"88.88.191.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_05_12; reference:url, urlhaus.abuse.ch/url/3845048/; classtype:trojan-activity;sid:84708148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3841856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagetest001.png"; depth:17; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_08; reference:url, urlhaus.abuse.ch/url/3841856/; classtype:trojan-activity;sid:84704956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pppc"; depth:10; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840659/; classtype:trojan-activity;sid:84703759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/px86"; depth:10; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840660/; classtype:trojan-activity;sid:84703760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kla.sh"; depth:12; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840654/; classtype:trojan-activity;sid:84703754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm6"; depth:11; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840655/; classtype:trojan-activity;sid:84703755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/psh4"; depth:10; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840656/; classtype:trojan-activity;sid:84703756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmpsl"; depth:11; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840657/; classtype:trojan-activity;sid:84703757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/pmips"; depth:11; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840658/; classtype:trojan-activity;sid:84703758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm"; depth:10; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840538/; classtype:trojan-activity;sid:84703638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm7"; depth:11; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840539/; classtype:trojan-activity;sid:84703639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3840540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/parm5"; depth:11; endswith; nocase; http.host; content:"89.32.41.16"; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_06; reference:url, urlhaus.abuse.ch/url/3840540/; classtype:trojan-activity;sid:84703640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajendra2604/rajendra2604.github.io/refs/heads/main/hypereutectoid/rajendra-github-io-1.7.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836242/; classtype:trojan-activity;sid:84699342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajendra2604/rajendra2604.github.io/raw/refs/heads/main/hypereutectoid/rajendra-github-io-1.7.zip"; depth:98; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836232/; classtype:trojan-activity;sid:84699332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajendra2604/kanban-for-ai-agents/refs/heads/main/amphitheatrically/agents_for_a_kanban_1.5.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836233/; classtype:trojan-activity;sid:84699333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajendra2604/rajendra2604.github.io/raw/refs/heads/main/hypereutectoid/io-github-rajendra-collectivize.zip"; depth:107; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836228/; classtype:trojan-activity;sid:84699328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajendra2604/kanban-for-ai-agents/refs/heads/main/amphitheatrically/kanban-agents-a-for-3.7.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836224/; classtype:trojan-activity;sid:84699324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajendra2604/rajendra2604.github.io/refs/heads/main/hypereutectoid/io-github-rajendra-collectivize.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836226/; classtype:trojan-activity;sid:84699326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajendra2604/kanban-for-ai-agents/raw/refs/heads/main/amphitheatrically/agents_for_a_kanban_1.5.zip"; depth:100; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836221/; classtype:trojan-activity;sid:84699321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rajendra2604/kanban-for-ai-agents/raw/refs/heads/main/amphitheatrically/kanban-agents-a-for-3.7.zip"; depth:100; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836222/; classtype:trojan-activity;sid:84699322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asherfn/asherfn.github.io/raw/refs/heads/main/swankily/io-asherfn-github-3.6.zip"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836187/; classtype:trojan-activity;sid:84699287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khonneymann/nightops-drop/raw/refs/heads/main/loggat/nightops_drop_2.6.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836188/; classtype:trojan-activity;sid:84699288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asherfn/asherfn.github.io/refs/heads/main/swankily/io-asherfn-github-3.6.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836183/; classtype:trojan-activity;sid:84699283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asherfn/acadex-ai-google-deepmind/refs/heads/main/components/deepmind-a-acadex-google-v1.8-alpha.4.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836185/; classtype:trojan-activity;sid:84699285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-greque/paimon-cpp/raw/refs/heads/main/conspirant/cpp-paimon-v1.9-alpha.3.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836171/; classtype:trojan-activity;sid:84699271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asherfn/acadex-ai-google-deepmind/raw/refs/heads/main/components/deepmind-a-acadex-google-v1.8-alpha.4.zip"; depth:107; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836172/; classtype:trojan-activity;sid:84699272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rockspeeder/devbar/refs/heads/main/prediplomatic/software-v3.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836174/; classtype:trojan-activity;sid:84699274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rockspeeder/rockspeeder.github.io/refs/heads/main/geognost/rockspeeder_github_io_v1.9.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836175/; classtype:trojan-activity;sid:84699275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khonneymann/khonneymann.github.io/raw/refs/heads/main/ourselves/khonneymann_io_github_1.1.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836163/; classtype:trojan-activity;sid:84699263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khonneymann/nightops-drop/refs/heads/main/loggat/nightops_drop_2.6.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836165/; classtype:trojan-activity;sid:84699265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rockspeeder/rockspeeder.github.io/raw/refs/heads/main/geognost/rockspeeder_github_io_v1.9.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836166/; classtype:trojan-activity;sid:84699266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-greque/paimon-cpp/refs/heads/main/conspirant/cpp-paimon-v1.9-alpha.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836167/; classtype:trojan-activity;sid:84699267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khonneymann/khonneymann.github.io/refs/heads/main/ourselves/khonneymann_io_github_1.1.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836152/; classtype:trojan-activity;sid:84699252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rockspeeder/devbar/raw/refs/heads/main/prediplomatic/software-v3.1.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836149/; classtype:trojan-activity;sid:84699249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-greque/i-greque.github.io/raw/refs/heads/main/preseal/greque_i_io_github_3.4.zip"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836147/; classtype:trojan-activity;sid:84699247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-greque/i-greque.github.io/refs/heads/main/preseal/greque_i_io_github_3.4.zip"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836146/; classtype:trojan-activity;sid:84699246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mctvcell/zon-ts/raw/refs/heads/main/benchmarks/core/ts_zon_3.3.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836136/; classtype:trojan-activity;sid:84699236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mctvcell/zon-ts/refs/heads/main/benchmarks/core/ts_zon_3.3.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836126/; classtype:trojan-activity;sid:84699226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/primmslimx/fivem-spoofer/refs/heads/main/cfxbypass.exe"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836094/; classtype:trojan-activity;sid:84699194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/primmslimx/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836095/; classtype:trojan-activity;sid:84699195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3835141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/run.sh"; depth:7; endswith; nocase; http.host; content:"103.83.87.122"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_30; reference:url, urlhaus.abuse.ch/url/3835141/; classtype:trojan-activity;sid:84698241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3833868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"109.236.46.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_04_28; reference:url, urlhaus.abuse.ch/url/3833868/; classtype:trojan-activity;sid:84696968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3833743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rum/optimized_msi.png"; depth:22; endswith; nocase; http.host; content:"spgint.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_28; reference:url, urlhaus.abuse.ch/url/3833743/; classtype:trojan-activity;sid:84696843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3833733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/optimized_msi.png"; depth:18; endswith; nocase; http.host; content:"postelnini.mk"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_28; reference:url, urlhaus.abuse.ch/url/3833733/; classtype:trojan-activity;sid:84696833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3833499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.236.46.215"; depth:14; isdataat:!1,relative; metadata:created_at 2026_04_28; reference:url, urlhaus.abuse.ch/url/3833499/; classtype:trojan-activity;sid:84696599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"202.62.41.165"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_27; reference:url, urlhaus.abuse.ch/url/3832920/; classtype:trojan-activity;sid:84696020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.88.191.25"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_27; reference:url, urlhaus.abuse.ch/url/3832742/; classtype:trojan-activity;sid:84695842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.exe"; depth:34; endswith; nocase; http.host; content:"45.138.16.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_26; reference:url, urlhaus.abuse.ch/url/3832456/; classtype:trojan-activity;sid:84695556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerd1337-afk/1337/raw/refs/heads/main/abe_decrypt.dll"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_26; reference:url, urlhaus.abuse.ch/url/3832353/; classtype:trojan-activity;sid:84695453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/opvjr94jfe/plugins/cred64.dll"; depth:30; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_26; reference:url, urlhaus.abuse.ch/url/3832039/; classtype:trojan-activity;sid:84695139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/opvjr94jfe/plugins/cred.dll"; depth:28; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_26; reference:url, urlhaus.abuse.ch/url/3832038/; classtype:trojan-activity;sid:84695138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labieds/splitwriter/raw/refs/heads/main/public/splitwriter-v2.8.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831490/; classtype:trojan-activity;sid:84694590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jamesnaismit/cv-screener/raw/refs/heads/main/web/hooks/cv-screener-3.4.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831491/; classtype:trojan-activity;sid:84694591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/123affano1/claudetrack/raw/refs/heads/main/client/src/pages/software_v1.6.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831479/; classtype:trojan-activity;sid:84694579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/douniajammali31/grammarfixer/raw/refs/heads/main/images/grammarfixer-2.5.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831480/; classtype:trojan-activity;sid:84694580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chamara1989/prismos-ai/main/docs/screenshots/prismos_ai_2.6.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831481/; classtype:trojan-activity;sid:84694581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamsujalarora/githubmeter/raw/refs/heads/main/src/styles/github_meter_v2.5.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831483/; classtype:trojan-activity;sid:84694583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ggshcgdh/localtranslateapp/raw/refs/heads/main/kittly/translate_app_local_3.5.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831485/; classtype:trojan-activity;sid:84694585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jamesnaismit/cv-screener/raw/refs/heads/main/api/postman/screener_cv_v2.8-alpha.2.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831487/; classtype:trojan-activity;sid:84694587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/douniajammali31/grammarfixer/raw/refs/heads/main/grammarfixer/resources/fixer-grammar-1.6.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831488/; classtype:trojan-activity;sid:84694588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lapk0m/n01d-overwatch/main/shared/overwatch-n-d-2.9.zip"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831478/; classtype:trojan-activity;sid:84694578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikey143-kun/agentchattr/main/session_templates/software-3.8.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831477/; classtype:trojan-activity;sid:84694577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayubalishah/mac-recorder/raw/refs/heads/main/dist/macrecorder-0.2.0.pkg"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831472/; classtype:trojan-activity;sid:84694572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayubalishah/mac-recorder/main/macrecorder/resources/assets.xcassets/recorder-mac-2.6.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831474/; classtype:trojan-activity;sid:84694574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nightmanvr/modernnav/raw/refs/heads/main/src/hooks/modern_nav_1.5.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831475/; classtype:trojan-activity;sid:84694575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nightmanvr/modernnav/raw/refs/heads/main/public/fonts/modern-nav-v3.5.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831467/; classtype:trojan-activity;sid:84694567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labieds/splitwriter/main/src/windows%20-%20old/boards/text-engine/_old/software-v2.8-beta.5.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831471/; classtype:trojan-activity;sid:84694571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/twelve-today822/juai/main/assets/ai_ju_riverwards.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831462/; classtype:trojan-activity;sid:84694562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lacquerwarepernyimoth791/crosshair-x-custom-crosshair-overlay-for-every-game/raw/refs/heads/main/1.24.2/for_game_custom_overlay_every_crosshair_3.2-alpha.2.zip"; depth:160; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831448/; classtype:trojan-activity;sid:84694548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrfrank-07/ipa-edit/raw/refs/heads/main/modules/edit_i_p_v1.7.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831443/; classtype:trojan-activity;sid:84694543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bragii044/securekey-vault/main/context/secure_vault_key_v2.5.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831445/; classtype:trojan-activity;sid:84694545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ajobka/teams-alive/raw/refs/heads/main/childe/teams-alive-1.1.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831436/; classtype:trojan-activity;sid:84694536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/holasisisi23/telegram-media-downloader/raw/refs/heads/main/unnoticed/media-telegram-downloader-unhatched.zip"; depth:109; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831438/; classtype:trojan-activity;sid:84694538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/funeralvalue508/crossdevicetracker.desktop/main/unheretical/cross_tracker_desktop_device_v1.8.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831433/; classtype:trojan-activity;sid:84694533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ke029121/energized-time-tracker/raw/refs/heads/main/phlebopexy/energized-time-tracker-1.7.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831435/; classtype:trojan-activity;sid:84694535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sparoecanthusfultoni104/exphora_db/raw/refs/heads/main/ui/src/components/settings/exphora-db-v3.4-beta.1.zip"; depth:109; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831429/; classtype:trojan-activity;sid:84694529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anandhupeepi/kafkalet/raw/refs/heads/main/frontend/node_modules/tailwindcss/lib/cli/software-cowardy.zip"; depth:105; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831430/; classtype:trojan-activity;sid:84694530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hundred-praisworthiness384/domainos/main/scripts/os-domain-1.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831425/; classtype:trojan-activity;sid:84694525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/acting-correlationalanalysis567/twin-bridge-v1/main/frontend/src/bridge_twin_1.1.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831427/; classtype:trojan-activity;sid:84694527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kathan2504/auto-voice-over-tool/raw/refs/heads/main/src/windows/main/auto_tool_over_voice_fining.zip"; depth:101; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831417/; classtype:trojan-activity;sid:84694517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/poetic-macroglia442/openclaw-desktop-launcher/raw/refs/heads/main/startopenclawlauncher/services/launcher_desktop_openclaw_v3.8-beta.2.zip"; depth:139; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831409/; classtype:trojan-activity;sid:84694509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sb090/tauri-plugin-macos-fps/main/examples/fps-diag/src-tauri/capabilities/plugin_macos_fps_tauri_2.4.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831411/; classtype:trojan-activity;sid:84694511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/koteshwr-ra/linux-mac/main/image/common/overlay/etc/linux_mac_hacker.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831403/; classtype:trojan-activity;sid:84694503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdulmejid/desktopledsync/main/providers/desktop_led_sync_v3.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831404/; classtype:trojan-activity;sid:84694504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eliasxii/nullbyte/raw/refs/heads/main/docs/assets/byte_null_v3.0-beta.4.zip"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831405/; classtype:trojan-activity;sid:84694505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rupa9495/youtube-hide-low-views-videos/raw/refs/heads/main/chelide/videos-hide-youtube-views-low-v2.6.zip"; depth:106; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830938/; classtype:trojan-activity;sid:84694038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rupa9495/n8n-mt5-fetch/refs/heads/main/telluriferous/fetch_n_mt_v3.9.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830936/; classtype:trojan-activity;sid:84694036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rupa9495/n8n-mt5-fetch/raw/refs/heads/main/telluriferous/fetch_n_mt_v3.9.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830937/; classtype:trojan-activity;sid:84694037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rupa9495/rupa9495.github.io/refs/heads/main/pterotheca/io-rupa-github-1.6.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830935/; classtype:trojan-activity;sid:84694035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rupa9495/rupa9495.github.io/raw/refs/heads/main/pterotheca/io-rupa-github-1.6.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830934/; classtype:trojan-activity;sid:84694034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rupa9495/youtube-hide-low-views-videos/refs/heads/main/chelide/videos-hide-youtube-views-low-v2.6.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830933/; classtype:trojan-activity;sid:84694033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/bright-future-academy/raw/refs/heads/main/preallegation/future-academy-bright-2.4.zip"; depth:95; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830856/; classtype:trojan-activity;sid:84693956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muradaldahmashi/swiftuihelpers/raw/refs/heads/main/resources/helpers-swift-ui-v2.8-beta.2.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830857/; classtype:trojan-activity;sid:84693957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muradaldahmashi/compose-password/raw/refs/heads/main/app/src/main/java/com/murad8al/passwordlock/ui/password-compose-v3.8.zip"; depth:126; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830859/; classtype:trojan-activity;sid:84693959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/particalfun/refs/heads/main/build/software-v3.8-beta.1.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830860/; classtype:trojan-activity;sid:84693960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevlar782/kevlar782.github.io/raw/refs/heads/main/elocutionary/io-github-kevlar-eremology.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830861/; classtype:trojan-activity;sid:84693961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/claude-code-showcase/raw/refs/heads/main/.claude/skills/core-components/showcase-claude-code-3.2-beta.5.zip"; depth:117; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830862/; classtype:trojan-activity;sid:84693962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fadeldia/data_analyst-bi_dev-portfolio.github.io/raw/refs/heads/main/assets/io_b_github_portfoli_analys_dat_de_v2.8.zip"; depth:120; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830863/; classtype:trojan-activity;sid:84693963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muradaldahmashi/compose-password/refs/heads/main/app/src/main/java/com/murad8al/passwordlock/ui/password-compose-v3.8.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830865/; classtype:trojan-activity;sid:84693965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/portfolio/raw/refs/heads/main/assets/projects/software_v3.4.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830866/; classtype:trojan-activity;sid:84693966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fadeldia/facebook-marketing-automation/refs/heads/main/baseheartedness/facebook_automation_marketing_1.0.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830868/; classtype:trojan-activity;sid:84693968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/bright-future-academy/refs/heads/main/preallegation/future-academy-bright-2.4.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830870/; classtype:trojan-activity;sid:84693970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/portfolio/refs/heads/main/assets/projects/software_v3.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830871/; classtype:trojan-activity;sid:84693971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muradaldahmashi/swiftuihelpers/refs/heads/main/resources/helpers-swift-ui-v2.8-beta.2.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830874/; classtype:trojan-activity;sid:84693974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fadeldia/facebook-marketing-automation/raw/refs/heads/main/baseheartedness/facebook_automation_marketing_1.0.zip"; depth:113; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830876/; classtype:trojan-activity;sid:84693976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/particalfun/raw/refs/heads/main/build/software-v3.8-beta.1.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830851/; classtype:trojan-activity;sid:84693951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fadeldia/data_analyst-bi_dev-portfolio.github.io/refs/heads/main/assets/io_b_github_portfoli_analys_dat_de_v2.8.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830853/; classtype:trojan-activity;sid:84693953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/ipoprock.github.io/refs/heads/main/decanically/io_github_ipoprock_2.0.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830854/; classtype:trojan-activity;sid:84693954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/builds/raw/refs/heads/main/build/software-1.4.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830855/; classtype:trojan-activity;sid:84693955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muradaldahmashi/android-development/refs/heads/main/examples/android-development-v3.7.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830849/; classtype:trojan-activity;sid:84693949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/builds/refs/heads/main/build/software-1.4.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830846/; classtype:trojan-activity;sid:84693946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/claude-code-showcase/refs/heads/main/.claude/skills/core-components/showcase-claude-code-3.2-beta.5.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830842/; classtype:trojan-activity;sid:84693942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muradaldahmashi/android-development/raw/refs/heads/main/examples/android-development-v3.7.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830843/; classtype:trojan-activity;sid:84693943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ipoprock/ipoprock.github.io/raw/refs/heads/main/decanically/io_github_ipoprock_2.0.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830844/; classtype:trojan-activity;sid:84693944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hankamarvanova/hankamarvanova.github.io/refs/heads/main/steamproof/io_hankamarvanova_github_v2.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830817/; classtype:trojan-activity;sid:84693917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hankamarvanova/unified-db/raw/refs/heads/main/sources/db_unified_3.9.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830819/; classtype:trojan-activity;sid:84693919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevlar782/genshin-ts/raw/refs/heads/main/whitecap/ts-genshin-2.2-alpha.5.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830826/; classtype:trojan-activity;sid:84693926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/espressivep/nextjs-tailwind-postgresql-project-template/raw/refs/heads/main/app/project-nextjs-template-tailwind-postgre-sq-v1.9.zip"; depth:133; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830828/; classtype:trojan-activity;sid:84693928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/espressivep/espressivep.github.io/raw/refs/heads/main/infelicitousness/io-espressivep-github-2.5.zip"; depth:101; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830829/; classtype:trojan-activity;sid:84693929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hankamarvanova/unified-db/refs/heads/main/sources/db_unified_3.9.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830831/; classtype:trojan-activity;sid:84693931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/espressivep/nextjs-tailwind-postgresql-project-template/refs/heads/main/app/project-nextjs-template-tailwind-postgre-sq-v1.9.zip"; depth:129; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830834/; classtype:trojan-activity;sid:84693934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/espressivep/espressivep.github.io/refs/heads/main/infelicitousness/io-espressivep-github-2.5.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830837/; classtype:trojan-activity;sid:84693937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevlar782/kevlar782.github.io/refs/heads/main/elocutionary/io-github-kevlar-eremology.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830838/; classtype:trojan-activity;sid:84693938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevlar782/genshin-ts/refs/heads/main/whitecap/ts-genshin-2.2-alpha.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830840/; classtype:trojan-activity;sid:84693940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hankamarvanova/hankamarvanova.github.io/raw/refs/heads/main/steamproof/io_hankamarvanova_github_v2.3.zip"; depth:105; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830814/; classtype:trojan-activity;sid:84693914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/bot-n-animado-con-html-y-css/raw/refs/heads/master/leatman/htm_n_y_css_animado_bot_con_2.2.zip"; depth:103; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830784/; classtype:trojan-activity;sid:84693884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/w_merchs/raw/refs/heads/main/src/layouts/merchs_3.4.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830780/; classtype:trojan-activity;sid:84693880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ziebwon/cnmsb/refs/heads/main/docs/apt/dists/stable/software-3.8.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830777/; classtype:trojan-activity;sid:84693877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeffplatinum1013/full-stack-fastapi-mongodb/refs/heads/main/%7d/scripts/mongodb_fastapi_full_stack_v3.5-beta.3.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830778/; classtype:trojan-activity;sid:84693878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/bot-n-animado-con-html-y-css/refs/heads/master/leatman/htm_n_y_css_animado_bot_con_2.2.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830763/; classtype:trojan-activity;sid:84693863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/propesy_demon/raw/refs/heads/main/public/propesy-demon-2.0.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830768/; classtype:trojan-activity;sid:84693868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeffplatinum1013/full-stack-fastapi-mongodb/raw/refs/heads/main/%7d/scripts/mongodb_fastapi_full_stack_v3.5-beta.3.zip"; depth:119; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830769/; classtype:trojan-activity;sid:84693869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/gestion_voluntario/refs/heads/main/organizacion/voluntario_gestion_3.7.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830770/; classtype:trojan-activity;sid:84693870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/gestion_voluntario/raw/refs/heads/main/organizacion/voluntario_gestion_3.7.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830771/; classtype:trojan-activity;sid:84693871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/w_merchs/refs/heads/main/src/layouts/merchs_3.4.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830774/; classtype:trojan-activity;sid:84693874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ziebwon/cnmsb/raw/refs/heads/main/docs/apt/dists/stable/software-3.8.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830776/; classtype:trojan-activity;sid:84693876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/propesy_demon/refs/heads/main/public/propesy-demon-2.0.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830749/; classtype:trojan-activity;sid:84693849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeffplatinum1013/jeffplatinum1013.github.io/refs/heads/main/crook/io_jeffplatinum_github_1.6-alpha.4.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830751/; classtype:trojan-activity;sid:84693851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/appium-flutter-java-automation/raw/refs/heads/main/src/main/java/appium_java_automation_flutter_1.2-alpha.3.zip"; depth:120; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830760/; classtype:trojan-activity;sid:84693860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/websyze.github.io/raw/refs/heads/main/invisible/io-github-websyze-overcustom.zip"; depth:89; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830743/; classtype:trojan-activity;sid:84693843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/websyze.github.io/refs/heads/main/invisible/io-github-websyze-overcustom.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830744/; classtype:trojan-activity;sid:84693844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeffplatinum1013/jeffplatinum1013.github.io/raw/refs/heads/main/crook/io_jeffplatinum_github_1.6-alpha.4.zip"; depth:109; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830746/; classtype:trojan-activity;sid:84693846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/websyze/appium-flutter-java-automation/refs/heads/main/src/main/java/appium_java_automation_flutter_1.2-alpha.3.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830747/; classtype:trojan-activity;sid:84693847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mo911-w16/novabar/refs/heads/main/src/about/bar-nova-spiritfully.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830725/; classtype:trojan-activity;sid:84693825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkexception22/darkexception22.github.io/raw/refs/heads/main/unreachably/darkexception_github_io_v2.7.zip"; depth:107; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830729/; classtype:trojan-activity;sid:84693829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/novabiriseg/gpio-led-cycle/refs/heads/main/drivers/stm32f4xx_hal_driver/src/le-cycle-gpi-1.3.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830730/; classtype:trojan-activity;sid:84693830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkexception22/darkexception22.github.io/refs/heads/main/unreachably/darkexception_github_io_v2.7.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830732/; classtype:trojan-activity;sid:84693832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mo911-w16/mo911-w16.github.io/raw/refs/heads/main/towards/github-w-mo-io-badenite.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830720/; classtype:trojan-activity;sid:84693820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mo911-w16/mo911-w16.github.io/refs/heads/main/towards/github-w-mo-io-badenite.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830721/; classtype:trojan-activity;sid:84693821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mo911-w16/novabar/raw/refs/heads/main/src/about/bar-nova-spiritfully.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830723/; classtype:trojan-activity;sid:84693823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/novabiriseg/gpio-led-cycle/raw/refs/heads/main/drivers/stm32f4xx_hal_driver/src/le-cycle-gpi-1.3.zip"; depth:101; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830724/; classtype:trojan-activity;sid:84693824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkexception22/da-hood-lock-script-showcase/refs/heads/main/noncredent/showcase_hood_da_script_lock_1.9.zip"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830712/; classtype:trojan-activity;sid:84693812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pgmonitorbrasil/pgmonitorbrasil.github.io/raw/refs/heads/main/schematonics/io_pgmonitorbrasil_github_v3.9.zip"; depth:110; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830713/; classtype:trojan-activity;sid:84693813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkexception22/aayush/refs/heads/master/dietic/software-commenceable.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830706/; classtype:trojan-activity;sid:84693806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkexception22/aayush/raw/refs/heads/master/dietic/software-commenceable.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830707/; classtype:trojan-activity;sid:84693807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkexception22/da-hood-lock-script-showcase/raw/refs/heads/main/noncredent/showcase_hood_da_script_lock_1.9.zip"; depth:113; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830708/; classtype:trojan-activity;sid:84693808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pgmonitorbrasil/nav2_hybrid_a_star/raw/refs/heads/main/src/data/nav_hybrid_star_v2.9.zip"; depth:89; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830702/; classtype:trojan-activity;sid:84693802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkexception22/alphabet/raw/refs/heads/main/src/cmps/software_unattuned.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830693/; classtype:trojan-activity;sid:84693793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pgmonitorbrasil/nav2_hybrid_a_star/refs/heads/main/src/data/nav_hybrid_star_v2.9.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830694/; classtype:trojan-activity;sid:84693794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pgmonitorbrasil/pgmonitorbrasil.github.io/refs/heads/main/schematonics/io_pgmonitorbrasil_github_v3.9.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830695/; classtype:trojan-activity;sid:84693795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/darkexception22/alphabet/refs/heads/main/src/cmps/software_unattuned.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830690/; classtype:trojan-activity;sid:84693790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sooryanaga/qt-liquid-glass/refs/heads/main/bulliform/qt_glass_liquid_3.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830682/; classtype:trojan-activity;sid:84693782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdoooali/corellm/refs/heads/main/corellm/software_calaba.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830681/; classtype:trojan-activity;sid:84693781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sooryanaga/obscure-affairs-unlocked-edition/refs/heads/branch/taurobolium/unlocked-obscure-affairs-edition-3.0.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830680/; classtype:trojan-activity;sid:84693780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/momofrd00/wpu-resolusi/raw/refs/heads/master/distractedness/wpu-resolusi-reapparition.zip"; depth:90; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830666/; classtype:trojan-activity;sid:84693766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wijewardhanagayashi/grifindo_toy_new_system/raw/refs/heads/main/buba/ew_system_n_grifindo_toy_1.7.zip"; depth:102; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830668/; classtype:trojan-activity;sid:84693768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/momofrd00/jquery-status-message/raw/refs/heads/main/css/status_message_jquery_2.2.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830669/; classtype:trojan-activity;sid:84693769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/momofrd00/dunia-gelap-butuh-resolusi-2023/refs/heads/main/nontidal/butuh-gelap-resolusi-dunia-v2.8.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830670/; classtype:trojan-activity;sid:84693770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huseindyslexic178/internee.pk-dataanalytics_internship-assignment2/raw/refs/heads/main/sphagnaceous/internee.pk-dataanalytics_internship-assignment2-v3.3.zip"; depth:158; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830671/; classtype:trojan-activity;sid:84693771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sooryanaga/obscure-affairs-unlocked-edition/raw/refs/heads/branch/taurobolium/unlocked-obscure-affairs-edition-3.0.zip"; depth:119; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830672/; classtype:trojan-activity;sid:84693772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/momofrd00/wpu-resolusi/refs/heads/master/distractedness/wpu-resolusi-reapparition.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830673/; classtype:trojan-activity;sid:84693773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/momofrd00/dunia-gelap-butuh-resolusi-2023/raw/refs/heads/main/nontidal/butuh-gelap-resolusi-dunia-v2.8.zip"; depth:107; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830674/; classtype:trojan-activity;sid:84693774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdoooali/corellm/raw/refs/heads/main/corellm/software_calaba.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830675/; classtype:trojan-activity;sid:84693775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wijewardhanagayashi/awesome-dotnet/refs/heads/main/impersonize/awesome-dotnet-v2.9.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830676/; classtype:trojan-activity;sid:84693776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/celestiapolyunsaturated14/helios-engine/raw/refs/heads/master/tests/helios_engine_v1.3-beta.1.zip"; depth:98; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830644/; classtype:trojan-activity;sid:84693744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lumansitrevormwesigwa/parallaxparticles/raw/refs/heads/main/parallax.xcodeproj/xcuserdata/pa.alekseev.xcuserdatad/xcschemes/parallax_particles_2.7.zip"; depth:151; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830645/; classtype:trojan-activity;sid:84693745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wijewardhanagayashi/photography_website/raw/refs/heads/master/phpmailer/vendor/phpmailer/phpmailer/src/photography_website_v3.5.zip"; depth:132; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830646/; classtype:trojan-activity;sid:84693746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wijewardhanagayashi/photography_website/refs/heads/master/phpmailer/vendor/phpmailer/phpmailer/src/photography_website_v3.5.zip"; depth:128; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830647/; classtype:trojan-activity;sid:84693747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huseindyslexic178/internee.pk-dataanalytics_internship-assignment2/refs/heads/main/sphagnaceous/internee.pk-dataanalytics_internship-assignment2-v3.3.zip"; depth:154; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830648/; classtype:trojan-activity;sid:84693748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/celestiapolyunsaturated14/helios-engine/refs/heads/master/tests/helios_engine_v1.3-beta.1.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830651/; classtype:trojan-activity;sid:84693751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdoooali/precision-aim-8ball-pool/raw/refs/heads/branch/catacorolla/precision-pool-aim-ball-1.3-beta.5.zip"; depth:108; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830652/; classtype:trojan-activity;sid:84693752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sooryanaga/qt-liquid-glass/raw/refs/heads/main/bulliform/qt_glass_liquid_3.5.zip"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830653/; classtype:trojan-activity;sid:84693753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wijewardhanagayashi/grifindo_toy_new_system/refs/heads/main/buba/ew_system_n_grifindo_toy_1.7.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830655/; classtype:trojan-activity;sid:84693755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdoooali/precision-aim-8ball-pool/refs/heads/branch/catacorolla/precision-pool-aim-ball-1.3-beta.5.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830658/; classtype:trojan-activity;sid:84693758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/momofrd00/jquery-status-message/refs/heads/main/css/status_message_jquery_2.2.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830660/; classtype:trojan-activity;sid:84693760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dishonorpeachpit230/fijahu-5/raw/refs/heads/main/quiz/fijahu_v2.1.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830663/; classtype:trojan-activity;sid:84693763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wijewardhanagayashi/awesome-dotnet/raw/refs/heads/main/impersonize/awesome-dotnet-v2.9.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830664/; classtype:trojan-activity;sid:84693764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lumansitrevormwesigwa/parallaxparticles/refs/heads/main/parallax.xcodeproj/xcuserdata/pa.alekseev.xcuserdatad/xcschemes/parallax_particles_2.7.zip"; depth:147; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830641/; classtype:trojan-activity;sid:84693741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dishonorpeachpit230/fijahu-5/refs/heads/main/quiz/fijahu_v2.1.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830640/; classtype:trojan-activity;sid:84693740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ericliu8888/blog-preview-card/raw/refs/heads/main/assets/preview-blog-card-outtop.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830621/; classtype:trojan-activity;sid:84693721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonasedwardsalkfirehose824/bobanimelist/raw/refs/heads/main/.droid/software-2.9-beta.4.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830622/; classtype:trojan-activity;sid:84693722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ericliu8888/blog-preview-card/refs/heads/main/assets/preview-blog-card-outtop.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830624/; classtype:trojan-activity;sid:84693724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonasedwardsalkfirehose824/bobanimelist/refs/heads/main/.droid/software-2.9-beta.4.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830620/; classtype:trojan-activity;sid:84693720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seizesectorpraise/7-days-to-die-player-detection/refs/heads/main/7daystodiepd-1.4.0-win64.rar"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830600/; classtype:trojan-activity;sid:84693700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seizesectorpraise/7-days-to-die-player-detection/raw/refs/heads/main/7daystodiepd-1.4.0-win64.rar"; depth:98; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830598/; classtype:trojan-activity;sid:84693698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.client.exe"; depth:23; endswith; nocase; http.host; content:"178.16.55.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830132/; classtype:trojan-activity;sid:84693232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/opvjr94jfe/plugins/vnc.exe"; depth:27; endswith; nocase; http.host; content:"91.92.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830135/; classtype:trojan-activity;sid:84693235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salesplataniik-commits/updates/v1/1583.txt"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829410/; classtype:trojan-activity;sid:84692510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salesplataniik-commits/sales/raw/refs/heads/main/nrrwihqidthwszel.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829411/; classtype:trojan-activity;sid:84692511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829387/; classtype:trojan-activity;sid:84692487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829389/; classtype:trojan-activity;sid:84692489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829391/; classtype:trojan-activity;sid:84692491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829392/; classtype:trojan-activity;sid:84692492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829393/; classtype:trojan-activity;sid:84692493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829394/; classtype:trojan-activity;sid:84692494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829395/; classtype:trojan-activity;sid:84692495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829396/; classtype:trojan-activity;sid:84692496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829397/; classtype:trojan-activity;sid:84692497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829398/; classtype:trojan-activity;sid:84692498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"23.140.244.57"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829399/; classtype:trojan-activity;sid:84692499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oualiide/manageengine-desktop-central-crack/refs/heads/master/ectocondyloid/central-crack-desktop-manage-engine-v2.7.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829211/; classtype:trojan-activity;sid:84692311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamevoid2366/authcrack-v8/raw/refs/heads/main/characteristically/auth-crack-v-2.1.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829208/; classtype:trojan-activity;sid:84692308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oualiide/manageengine-desktop-central-crack/raw/refs/heads/master/ectocondyloid/central-crack-desktop-manage-engine-v2.7.zip"; depth:125; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829209/; classtype:trojan-activity;sid:84692309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/cloudweb/raw/refs/heads/main/unshattered/software_v3.4-beta.5.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829210/; classtype:trojan-activity;sid:84692310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/cloudweb/refs/heads/main/unshattered/software_v3.4-beta.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829203/; classtype:trojan-activity;sid:84692303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamevoid2366/authcrack-v8/refs/heads/main/characteristically/auth-crack-v-2.1.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829205/; classtype:trojan-activity;sid:84692305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/vercel/refs/heads/main/methylanthracene/software_1.9.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829206/; classtype:trojan-activity;sid:84692306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/todo/refs/heads/main/eyeberry/software_v3.2.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829207/; classtype:trojan-activity;sid:84692307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/vercel/raw/refs/heads/main/methylanthracene/software_1.9.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829201/; classtype:trojan-activity;sid:84692301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/hash_crack/raw/refs/heads/main/node_modules/reveal.js/plugin/search/crack_hash_v3.4.zip"; depth:99; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829199/; classtype:trojan-activity;sid:84692299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/todo/raw/refs/heads/main/eyeberry/software_v3.2.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829200/; classtype:trojan-activity;sid:84692300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/web/raw/refs/heads/main/reticence/software-uncivilish.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829198/; classtype:trojan-activity;sid:84692298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/hash_crack/refs/heads/main/node_modules/reveal.js/plugin/search/crack_hash_v3.4.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829196/; classtype:trojan-activity;sid:84692296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jcalumag19/web/refs/heads/main/reticence/software-uncivilish.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829197/; classtype:trojan-activity;sid:84692297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wuaricoco23/whiteboxaescrack/raw/refs/heads/main/fonts/white-crack-box-aes-v2.5.zip"; depth:84; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829174/; classtype:trojan-activity;sid:84692274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wuaricoco23/valentine/raw/refs/heads/main/effortful/software-2.3.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829179/; classtype:trojan-activity;sid:84692279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wuaricoco23/whiteboxaescrack/refs/heads/main/fonts/white-crack-box-aes-v2.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829170/; classtype:trojan-activity;sid:84692270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wuaricoco23/valentine/refs/heads/main/effortful/software-2.3.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829172/; classtype:trojan-activity;sid:84692272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pammyhangdog747/claude-cracks-the-whip/refs/heads/main/lapidarist/the_cracks_whip_claude_3.0.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829150/; classtype:trojan-activity;sid:84692250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pammyhangdog747/claude-cracks-the-whip/raw/refs/heads/main/lapidarist/the_cracks_whip_claude_3.0.zip"; depth:101; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829151/; classtype:trojan-activity;sid:84692251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guvann/guvann1/raw/refs/heads/main/confirmatory/guvann-v1.7.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829135/; classtype:trojan-activity;sid:84692235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guvann/cursor-reset/raw/refs/heads/main/olympiadic/cursor_reset_1.3.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829125/; classtype:trojan-activity;sid:84692225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guvann/cursor-reset/refs/heads/main/olympiadic/cursor_reset_1.3.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829116/; classtype:trojan-activity;sid:84692216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guvann/guvann1/refs/heads/main/confirmatory/guvann-v1.7.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829117/; classtype:trojan-activity;sid:84692217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3828327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xclient...exe"; depth:14; endswith; nocase; http.host; content:"206.245.165.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3828327/; classtype:trojan-activity;sid:84691427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3828247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/8.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3828247/; classtype:trojan-activity;sid:84691347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3827862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grab.exe"; depth:9; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_21; reference:url, urlhaus.abuse.ch/url/3827862/; classtype:trojan-activity;sid:84690962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3826347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emacute/maize_disease_detection_system/raw/refs/heads/main/syllabicness/system_disease_detection_maize_2.5.zip"; depth:111; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_20; reference:url, urlhaus.abuse.ch/url/3826347/; classtype:trojan-activity;sid:84689447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3826343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/emacute/maize_disease_detection_system/refs/heads/main/syllabicness/system_disease_detection_maize_2.5.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_20; reference:url, urlhaus.abuse.ch/url/3826343/; classtype:trojan-activity;sid:84689443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3826334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/camilo-vs/patching-hacked-world/raw/refs/heads/principal/landrick_v3.2/__macosx/landrick_v3.2/html/php/patching_world_hacked_v3.8.zip"; depth:134; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_20; reference:url, urlhaus.abuse.ch/url/3826334/; classtype:trojan-activity;sid:84689434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3826320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/camilo-vs/patching-hacked-world/refs/heads/principal/landrick_v3.2/__macosx/landrick_v3.2/html/php/patching_world_hacked_v3.8.zip"; depth:130; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_20; reference:url, urlhaus.abuse.ch/url/3826320/; classtype:trojan-activity;sid:84689420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3825863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//tmp/f/10dfff942805d90d6ebb28bd58093653_20251208021850.so"; depth:58; endswith; nocase; http.host; content:"fd.v2downf.shop"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_19; reference:url, urlhaus.abuse.ch/url/3825863/; classtype:trojan-activity;sid:84688963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3825482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"217.168.128.146"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_18; reference:url, urlhaus.abuse.ch/url/3825482/; classtype:trojan-activity;sid:84688582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3824667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagedan73.png"; depth:15; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3824667/; classtype:trojan-activity;sid:84687767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alinaitweshalifu28-netizen/2/raw/refs/heads/main/1/4.log"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3823984/; classtype:trojan-activity;sid:84687084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alinaitweshalifu28-netizen/2/refs/heads/main/1/4.log"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3823983/; classtype:trojan-activity;sid:84687083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alinaitweshalifu28-netizen/2/refs/heads/main/1/3.log"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3823982/; classtype:trojan-activity;sid:84687082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alinaitweshalifu28-netizen/2/raw/refs/heads/main/1/3.log"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3823981/; classtype:trojan-activity;sid:84687081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itzmesultan01/eventpipe/raw/refs/heads/main/src/formats/software_2.6.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823979/; classtype:trojan-activity;sid:84687079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/restaurant-management-saas/refs/heads/main/frontend/src/lib/management-restaurant-saas-superinnocent.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823974/; classtype:trojan-activity;sid:84687074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/secure-vault/refs/heads/main/node_modules/%40supabase/auth-ui-shared/dist/vault_secure_1.8-beta.2.zip"; depth:114; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823975/; classtype:trojan-activity;sid:84687075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/securevault-password-manager/raw/refs/heads/main/node_modules/typescript/lib/tr/password-manager-secure-vault-v3.7.zip"; depth:131; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823972/; classtype:trojan-activity;sid:84687072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/securevault-password-manager/refs/heads/main/node_modules/typescript/lib/tr/password-manager-secure-vault-v3.7.zip"; depth:127; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823973/; classtype:trojan-activity;sid:84687073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/secure-vault/raw/refs/heads/main/node_modules/@supabase/auth-ui-shared/dist/vault_secure_1.8-beta.2.zip"; depth:116; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823967/; classtype:trojan-activity;sid:84687067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/spaceship-mcp/refs/heads/main/src/tools/mcp-spaceship-2.8.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823970/; classtype:trojan-activity;sid:84687070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/spaceship-mcp/raw/refs/heads/main/src/tools/mcp-spaceship-2.8.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823964/; classtype:trojan-activity;sid:84687064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/restaurant-management-saas/raw/refs/heads/main/frontend/src/lib/management-restaurant-saas-superinnocent.zip"; depth:121; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823965/; classtype:trojan-activity;sid:84687065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itzmesultan01/eventpipe/refs/heads/main/src/formats/software_2.6.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823958/; classtype:trojan-activity;sid:84687058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/smart-tutor/refs/heads/main/src/contexts/tutor_smart_v1.7.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823959/; classtype:trojan-activity;sid:84687059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naveenkm007/smart-tutor/raw/refs/heads/main/src/contexts/tutor_smart_v1.7.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823960/; classtype:trojan-activity;sid:84687060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackfalan/was/raw/refs/heads/master/augurship/software-v1.3-beta.2.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823951/; classtype:trojan-activity;sid:84687051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sandro-beep/discord-message-forwarder/raw/refs/heads/main/septuplication/discord-forwarder-message-v2.8-beta.3.zip"; depth:115; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823937/; classtype:trojan-activity;sid:84687037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jesusnnc/mtproxy/refs/heads/main/angiosporous/proxy_mt_v2.0.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823938/; classtype:trojan-activity;sid:84687038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jesusnnc/mtproxy/raw/refs/heads/main/angiosporous/proxy_mt_v2.0.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823942/; classtype:trojan-activity;sid:84687042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sandro-beep/discord-message-forwarder/refs/heads/main/septuplication/discord-forwarder-message-v2.8-beta.3.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823945/; classtype:trojan-activity;sid:84687045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackfalan/happyview/refs/heads/master/yow/software_v2.0-beta.1.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823932/; classtype:trojan-activity;sid:84687032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saramc89mc/personal-website-template/raw/refs/heads/main/src/components/sections/about/personal_template_website_2.2.zip"; depth:121; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823933/; classtype:trojan-activity;sid:84687033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alecyi/cache-components-granular/refs/heads/main/components/layout/notebook/page/components-cache-granular-v2.1.zip"; depth:116; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823930/; classtype:trojan-activity;sid:84687030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invertebratekinanesthesia779/aios-core/refs/heads/main/tests/unit/squad/fixtures/invalid-squad/core-aios-1.4.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823926/; classtype:trojan-activity;sid:84687026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackfalan/happyview/raw/refs/heads/master/yow/software_v2.0-beta.1.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823924/; classtype:trojan-activity;sid:84687024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alecyi/cache-components-granular/raw/refs/heads/main/components/layout/notebook/page/components-cache-granular-v2.1.zip"; depth:120; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823922/; classtype:trojan-activity;sid:84687022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackfalan/was/refs/heads/master/augurship/software-v1.3-beta.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823921/; classtype:trojan-activity;sid:84687021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invertebratekinanesthesia779/aios-core/raw/refs/heads/main/tests/unit/squad/fixtures/invalid-squad/core-aios-1.4.zip"; depth:117; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823919/; classtype:trojan-activity;sid:84687019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/industrialintelligence/willywarriorportfolio/refs/heads/master/fonts/font-awesome-4.7.0/fonts/software-3.7.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823912/; classtype:trojan-activity;sid:84687012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/industrialintelligence/willywarriorportfolio/raw/refs/heads/master/fonts/font-awesome-4.7.0/fonts/software-3.7.zip"; depth:115; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823913/; classtype:trojan-activity;sid:84687013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/industrialintelligence/homestead_new_backend/raw/refs/heads/master/validator/backend_homestead_new_v1.9-beta.5.zip"; depth:115; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823911/; classtype:trojan-activity;sid:84687011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/industrialintelligence/homestead_new_backend/refs/heads/master/validator/backend_homestead_new_v1.9-beta.5.zip"; depth:111; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823909/; classtype:trojan-activity;sid:84687009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/industrialintelligence/homestead/raw/refs/heads/master/images/funitture_icon/software-3.2-beta.4.zip"; depth:101; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823910/; classtype:trojan-activity;sid:84687010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45d5r/databricks-mcp-server/raw/refs/heads/main/databricks_mcp/resources/server_databricks_mcp_1.6.zip"; depth:103; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823908/; classtype:trojan-activity;sid:84687008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saramc89mc/personal-website-template/refs/heads/main/src/components/sections/about/personal_template_website_2.2.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823907/; classtype:trojan-activity;sid:84687007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/45d5r/databricks-mcp-server/refs/heads/main/databricks_mcp/resources/server_databricks_mcp_1.6.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823905/; classtype:trojan-activity;sid:84687005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/industrialintelligence/homestead/refs/heads/master/images/funitture_icon/software-3.2-beta.4.zip"; depth:97; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823906/; classtype:trojan-activity;sid:84687006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonisark/html-portfolioes/raw/refs/heads/main/someone/html_portfolioes_1.1.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822771/; classtype:trojan-activity;sid:84685871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonisark/djast/raw/refs/heads/main/4.3%20html%20porfolio%20project/software_2.5.zip"; depth:84; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822765/; classtype:trojan-activity;sid:84685865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonisark/joni/raw/refs/heads/main/epiklesis/software-1.5.zip"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822767/; classtype:trojan-activity;sid:84685867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonisark/git-demo/raw/refs/heads/main/unresponsiveness/demo_git_v2.4.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822761/; classtype:trojan-activity;sid:84685861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonisark/git-demo/refs/heads/main/unresponsiveness/demo_git_v2.4.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822762/; classtype:trojan-activity;sid:84685862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonisark/djast/refs/heads/main/4.3%20html%20porfolio%20project/software_2.5.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822755/; classtype:trojan-activity;sid:84685855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jonisark/html-portfolioes/refs/heads/main/someone/html_portfolioes_1.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822759/; classtype:trojan-activity;sid:84685859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yawnspe/custom-plugin-devops/raw/refs/heads/master/.github/workflows/plugin-devops-custom-2.6.zip"; depth:98; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822735/; classtype:trojan-activity;sid:84685835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reddinton95/custom-plugin-backend/raw/refs/heads/main/agents/02-database-management/backend-plugin-custom-1.2.zip"; depth:114; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822736/; classtype:trojan-activity;sid:84685836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reddinton95/custom-plugin-backend/refs/heads/main/agents/02-database-management/backend-plugin-custom-1.2.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822739/; classtype:trojan-activity;sid:84685839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junayedahmedd/assignment-2/refs/heads/main/img/assignment_shelyak.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822726/; classtype:trojan-activity;sid:84685826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junayedahmedd/assignment-2/raw/refs/heads/main/img/assignment_shelyak.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822727/; classtype:trojan-activity;sid:84685827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junayedahmedd/assignment-1/raw/refs/heads/main/img/assignment-2.3.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822728/; classtype:trojan-activity;sid:84685828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yawnspe/custom-plugin-devops/refs/heads/master/.github/workflows/plugin-devops-custom-2.6.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822729/; classtype:trojan-activity;sid:84685829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junayedahmedd/tailwindproject/refs/heads/main/node_modules/string-width-cjs/node_modules/ansi-regex/tailwind_project_v2.2.zip"; depth:126; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822730/; classtype:trojan-activity;sid:84685830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junayedahmedd/gemini_cli_skill/raw/refs/heads/main/mammillation/cli_skill_gemini_v3.8.zip"; depth:90; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822731/; classtype:trojan-activity;sid:84685831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isaacww/var-lighter-auto-tool/raw/refs/heads/main/turbinatoglobose/tool-lighter-var-auto-v3.6-beta.3.zip"; depth:105; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822732/; classtype:trojan-activity;sid:84685832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junayedahmedd/tailwindproject/raw/refs/heads/main/node_modules/string-width-cjs/node_modules/ansi-regex/tailwind_project_v2.2.zip"; depth:130; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822733/; classtype:trojan-activity;sid:84685833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/isaacww/var-lighter-auto-tool/refs/heads/main/turbinatoglobose/tool-lighter-var-auto-v3.6-beta.3.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822734/; classtype:trojan-activity;sid:84685834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junayedahmedd/assignment-1/refs/heads/main/img/assignment-2.3.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822724/; classtype:trojan-activity;sid:84685824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/junayedahmedd/gemini_cli_skill/refs/heads/main/mammillation/cli_skill_gemini_v3.8.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822725/; classtype:trojan-activity;sid:84685825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flix-ux/powersub-demo-7484/refs/heads/main/transpeer/powersub_demo_v3.7.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822718/; classtype:trojan-activity;sid:84685818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jallinskyluca/entregafinal/raw/refs/heads/main/css/final-entrega-3.0.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822720/; classtype:trojan-activity;sid:84685820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jallinskyluca/entregafinal/refs/heads/main/css/final-entrega-3.0.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822707/; classtype:trojan-activity;sid:84685807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jallinskyluca/ai-etl-anomaly-detection/raw/refs/heads/main/data/anomaly_etl_ai_detection_2.1.zip"; depth:97; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822711/; classtype:trojan-activity;sid:84685811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flix-ux/powersub-demo-7484/raw/refs/heads/main/transpeer/powersub_demo_v3.7.zip"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822713/; classtype:trojan-activity;sid:84685813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jallinskyluca/ai-etl-anomaly-detection/refs/heads/main/data/anomaly_etl_ai_detection_2.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822716/; classtype:trojan-activity;sid:84685816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizkiameli/blog-starter-template/raw/refs/heads/main/lib/blog_template_starter_2.4.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822698/; classtype:trojan-activity;sid:84685798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rizkiameli/blog-starter-template/refs/heads/main/lib/blog_template_starter_2.4.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822697/; classtype:trojan-activity;sid:84685797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/longphamok1323/2025doubao-free-api/refs/heads/master/public/doubao_api_free_inanga.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822678/; classtype:trojan-activity;sid:84685778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roseannspastic496/pyspark-etl-automation/raw/refs/heads/main/pridelessly/etl-automation-pyspark-3.4-alpha.1.zip"; depth:112; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822679/; classtype:trojan-activity;sid:84685779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roseannspastic496/pyspark-etl-automation/refs/heads/main/pridelessly/etl-automation-pyspark-3.4-alpha.1.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822683/; classtype:trojan-activity;sid:84685783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/123luka123/k3s-proxmox-terraform/raw/refs/heads/main/docs/terraform-s-k-proxmox-frontierlike.zip"; depth:97; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822686/; classtype:trojan-activity;sid:84685786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/novice-cloud/workflow/refs/heads/main/packages/world-postgres/src/drizzle/migrations/software_v1.3.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822689/; classtype:trojan-activity;sid:84685789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/longphamok1323/2025doubao-free-api/raw/refs/heads/master/public/doubao_api_free_inanga.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822694/; classtype:trojan-activity;sid:84685794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/novice-cloud/workflow/raw/refs/heads/main/packages/world-postgres/src/drizzle/migrations/software_v1.3.zip"; depth:107; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822673/; classtype:trojan-activity;sid:84685773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/123luka123/k3s-proxmox-terraform/refs/heads/main/docs/terraform-s-k-proxmox-frontierlike.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822659/; classtype:trojan-activity;sid:84685759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/camm1ls/deviloff/raw/refs/heads/main/4j8576a0e8v3.exe"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822575/; classtype:trojan-activity;sid:84685675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/camm1ls/deviloff/refs/heads/main/4j8576a0e8v3.exe"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822574/; classtype:trojan-activity;sid:84685674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/landeliur/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822558/; classtype:trojan-activity;sid:84685658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/landeliur/fivem-spoofer/refs/heads/main/cfxbypass.exe"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822556/; classtype:trojan-activity;sid:84685656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3821609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest|7c|26|7c|c=bat|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c="; depth:162; endswith; nocase; http.host; content:"184.174.20.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_04_14; reference:url, urlhaus.abuse.ch/url/3821609/; classtype:trojan-activity;sid:84684709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3821392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"65.99.181.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_14; reference:url, urlhaus.abuse.ch/url/3821392/; classtype:trojan-activity;sid:84684492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3821391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagepixxx011.png"; depth:18; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_14; reference:url, urlhaus.abuse.ch/url/3821391/; classtype:trojan-activity;sid:84684491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3821356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagehd09.png"; depth:14; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_14; reference:url, urlhaus.abuse.ch/url/3821356/; classtype:trojan-activity;sid:84684456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3821345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/support.clientsetup.msi|3f|e=access|7c|26|7c|y=guest|7c|26|7c|c=4-4-2026|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=new|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c="; depth:164; endswith; nocase; http.host; content:"doc.e-statements.app"; depth:20; isdataat:!1,relative; metadata:created_at 2026_04_14; reference:url, urlhaus.abuse.ch/url/3821345/; classtype:trojan-activity;sid:84684445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3820855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/professor9-sys/oldlauncher928/refs/heads/main/woofer.rar"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_13; reference:url, urlhaus.abuse.ch/url/3820855/; classtype:trojan-activity;sid:84683955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3817607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ghanioilandgas.zip"; depth:19; endswith; nocase; http.host; content:"ghanioilandgas.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_04_13; reference:url, urlhaus.abuse.ch/url/3817607/; classtype:trojan-activity;sid:84680707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pato851/pato851.github.io/raw/refs/heads/main/supraterraneous/io-github-pato-2.6.zip"; depth:85; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816932/; classtype:trojan-activity;sid:84680032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pato851/rock-breaker/refs/heads/main/src/components/rock_breaker_v1.9.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816929/; classtype:trojan-activity;sid:84680029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pato851/rock-breaker/raw/refs/heads/main/src/components/rock_breaker_v1.9.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816930/; classtype:trojan-activity;sid:84680030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pato851/pato851.github.io/refs/heads/main/supraterraneous/io-github-pato-2.6.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816931/; classtype:trojan-activity;sid:84680031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/talktobaby/infinity-snip3/raw/refs/heads/master/audio/infinity_snip_screeve.zip"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816923/; classtype:trojan-activity;sid:84680023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/talktobaby/talktobaby.github.io/raw/refs/heads/main/hymeneals/talktobaby-io-github-v1.3.zip"; depth:92; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816921/; classtype:trojan-activity;sid:84680021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/talktobaby/infinity-snip3/refs/heads/master/audio/infinity_snip_screeve.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816922/; classtype:trojan-activity;sid:84680022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/talktobaby/talktobaby.github.io/refs/heads/main/hymeneals/talktobaby-io-github-v1.3.zip"; depth:88; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816920/; classtype:trojan-activity;sid:84680020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xfoxusx/xfoxusx.github.io/raw/refs/heads/main/arsenism/github_io_xfoxusx_v1.7.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816888/; classtype:trojan-activity;sid:84679988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xfoxusx/arduino-joystick-and-servo-control/raw/refs/heads/main/lection/servo-arduino-control-and-joystick-1.1.zip"; depth:114; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816889/; classtype:trojan-activity;sid:84679989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xfoxusx/arduino-joystick-and-servo-control/refs/heads/main/lection/servo-arduino-control-and-joystick-1.1.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816887/; classtype:trojan-activity;sid:84679987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xfoxusx/xfoxusx.github.io/refs/heads/main/arsenism/github_io_xfoxusx_v1.7.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816886/; classtype:trojan-activity;sid:84679986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdalrhmanasif5/tic_tac_toe/refs/heads/main/auriculae/toe-tic-tac-v3.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816841/; classtype:trojan-activity;sid:84679941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdalrhmanasif5/32/raw/refs/heads/main/app/(public)/contact/software_v1.6-beta.5.zip"; depth:85; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816837/; classtype:trojan-activity;sid:84679937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdalrhmanasif5/abdalrhmanasif5.github.io/refs/heads/main/torques/github_io_abdalrhmanasif_screwsman.zip"; depth:105; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816838/; classtype:trojan-activity;sid:84679938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdalrhmanasif5/abdalrhmanasif5.github.io/raw/refs/heads/main/torques/github_io_abdalrhmanasif_screwsman.zip"; depth:109; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816839/; classtype:trojan-activity;sid:84679939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdalrhmanasif5/tic_tac_toe/raw/refs/heads/main/auriculae/toe-tic-tac-v3.3.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816840/; classtype:trojan-activity;sid:84679940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdalrhmanasif5/32/refs/heads/main/app/(public)/contact/software_v1.6-beta.5.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816836/; classtype:trojan-activity;sid:84679936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_arm64"; depth:12; endswith; nocase; http.host; content:"45.66.228.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816822/; classtype:trojan-activity;sid:84679922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_mips64"; depth:13; endswith; nocase; http.host; content:"45.66.228.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816823/; classtype:trojan-activity;sid:84679923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mixteens/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816810/; classtype:trojan-activity;sid:84679910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mixteens/fivem-spoofer/refs/heads/main/cfxbypass.exe"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816809/; classtype:trojan-activity;sid:84679909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trustnobodys/fivem-spoofer/refs/heads/main/cfxbypass.exe"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816792/; classtype:trojan-activity;sid:84679892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trustnobodys/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816790/; classtype:trojan-activity;sid:84679890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_mips"; depth:11; endswith; nocase; http.host; content:"45.66.228.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816741/; classtype:trojan-activity;sid:84679841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_arm5"; depth:11; endswith; nocase; http.host; content:"45.66.228.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816739/; classtype:trojan-activity;sid:84679839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_amd64"; depth:12; endswith; nocase; http.host; content:"45.66.228.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816740/; classtype:trojan-activity;sid:84679840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/net_launcher.exe"; depth:26; endswith; nocase; http.host; content:"furystaff.tech"; depth:14; isdataat:!1,relative; metadata:created_at 2026_04_11; reference:url, urlhaus.abuse.ch/url/3816386/; classtype:trojan-activity;sid:84679486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_arm7"; depth:11; endswith; nocase; http.host; content:"45.66.228.93"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_11; reference:url, urlhaus.abuse.ch/url/3816329/; classtype:trojan-activity;sid:84679429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3814916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elementos/mhdcbdc.txt"; depth:22; endswith; nocase; http.host; content:"grupomcperu.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_09; reference:url, urlhaus.abuse.ch/url/3814916/; classtype:trojan-activity;sid:84678016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3814834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v0/b/spenglercomics.firebasestorage.app/o/task.txt|3f|alt=media|7c|26|7c|token=f162f5ce-52f7-4407-8cc4-dd96cedd9b0e"; depth:116; endswith; nocase; http.host; content:"firebasestorage.googleapis.com"; depth:30; isdataat:!1,relative; metadata:created_at 2026_04_09; reference:url, urlhaus.abuse.ch/url/3814834/; classtype:trojan-activity;sid:84677934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3813947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wsw0"; depth:5; endswith; nocase; http.host; content:"202.155.8.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_08; reference:url, urlhaus.abuse.ch/url/3813947/; classtype:trojan-activity;sid:84677047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3813653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x"; depth:2; endswith; nocase; http.host; content:"45.95.147.178"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_07; reference:url, urlhaus.abuse.ch/url/3813653/; classtype:trojan-activity;sid:84676753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3813602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k.php"; depth:6; endswith; nocase; http.host; content:"45.95.147.178"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_07; reference:url, urlhaus.abuse.ch/url/3813602/; classtype:trojan-activity;sid:84676702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3813596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x"; depth:2; endswith; nocase; http.host; content:"160.119.69.4"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_07; reference:url, urlhaus.abuse.ch/url/3813596/; classtype:trojan-activity;sid:84676696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3812664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_06; reference:url, urlhaus.abuse.ch/url/3812664/; classtype:trojan-activity;sid:84675764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3812407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/u"; depth:2; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_05; reference:url, urlhaus.abuse.ch/url/3812407/; classtype:trojan-activity;sid:84675507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3812302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s"; depth:2; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_05; reference:url, urlhaus.abuse.ch/url/3812302/; classtype:trojan-activity;sid:84675402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"65.99.181.12"; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_03; reference:url, urlhaus.abuse.ch/url/3810858/; classtype:trojan-activity;sid:84673958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/y"; depth:2; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_03; reference:url, urlhaus.abuse.ch/url/3810777/; classtype:trojan-activity;sid:84673877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peinf.exe"; depth:10; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810532/; classtype:trojan-activity;sid:84673632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi"; depth:34; endswith; nocase; http.host; content:"themaintechnician.us"; depth:20; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810488/; classtype:trojan-activity;sid:84673588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rsvp_invite%23903388.exe"; depth:25; endswith; nocase; http.host; content:"pub-ec081eb0fab74385a17d8d77afeeda3b.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810486/; classtype:trojan-activity;sid:84673586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips64"; depth:7; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810447/; classtype:trojan-activity;sid:84673547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i586"; depth:5; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810361/; classtype:trojan-activity;sid:84673461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810363/; classtype:trojan-activity;sid:84673463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/powerpc"; depth:8; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810364/; classtype:trojan-activity;sid:84673464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i686"; depth:5; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810338/; classtype:trojan-activity;sid:84673438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arc"; depth:4; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810339/; classtype:trojan-activity;sid:84673439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sparc"; depth:6; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810342/; classtype:trojan-activity;sid:84673442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810343/; classtype:trojan-activity;sid:84673443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mipsel"; depth:7; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810347/; classtype:trojan-activity;sid:84673447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv4l"; depth:7; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810350/; classtype:trojan-activity;sid:84673450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i486"; depth:5; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810352/; classtype:trojan-activity;sid:84673452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810360/; classtype:trojan-activity;sid:84673460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv5l"; depth:7; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810337/; classtype:trojan-activity;sid:84673437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv6l"; depth:7; endswith; nocase; http.host; content:"195.178.110.204"; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810335/; classtype:trojan-activity;sid:84673435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcoss/dl/pptv(pplive)_forap_1084_9993.exe"; depth:42; endswith; nocase; http.host; content:"ossapp.suning.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_04_01; reference:url, urlhaus.abuse.ch/url/3809815/; classtype:trojan-activity;sid:84672915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"90.224.208.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_04_01; reference:url, urlhaus.abuse.ch/url/3809563/; classtype:trojan-activity;sid:84672663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809347/; classtype:trojan-activity;sid:84672447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809348/; classtype:trojan-activity;sid:84672448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809349/; classtype:trojan-activity;sid:84672449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809350/; classtype:trojan-activity;sid:84672450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809351/; classtype:trojan-activity;sid:84672451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2.exe"; depth:6; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809352/; classtype:trojan-activity;sid:84672452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sehhs_msi.png"; depth:14; endswith; nocase; http.host; content:"reutilizemais.co.mz"; depth:19; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809024/; classtype:trojan-activity;sid:84672124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sehhs_msi.png"; depth:14; endswith; nocase; http.host; content:"reutilizemais.co.mz"; depth:19; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809025/; classtype:trojan-activity;sid:84672125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3808984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"217.208.164.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3808984/; classtype:trojan-activity;sid:84672084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3808366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/packages/83/b7/5e93f51cd157cc8cf5599f387e587a1926d50fc7e54fb76d04b342341fb0/telnyx-4.87.1-py3-none-any.whl"; depth:107; endswith; nocase; http.host; content:"files.pythonhosted.org"; depth:22; isdataat:!1,relative; metadata:created_at 2026_03_30; reference:url, urlhaus.abuse.ch/url/3808366/; classtype:trojan-activity;sid:84671466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3808367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/packages/5a/73/87cb49434a1f89f253819b81993d3a4e65186ae08b013b9825633ceac359/telnyx-4.87.2-py3-none-any.whl"; depth:107; endswith; nocase; http.host; content:"files.pythonhosted.org"; depth:22; isdataat:!1,relative; metadata:created_at 2026_03_30; reference:url, urlhaus.abuse.ch/url/3808367/; classtype:trojan-activity;sid:84671467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zouag94/map/refs/heads/main/or/75.txt"; depth:38; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807792/; classtype:trojan-activity;sid:84670892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zouag94/map/raw/refs/heads/main/or/75.txt"; depth:42; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807793/; classtype:trojan-activity;sid:84670893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustkimkureshi/cafe-erp-system/raw/refs/heads/main/css/system-er-caf-v3.3.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807785/; classtype:trojan-activity;sid:84670885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nopaleafifo630/tic-tac-toe-game/refs/heads/main/nepotistical/game_tac_toe_tic_v1.2.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807786/; classtype:trojan-activity;sid:84670886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustkimkureshi/cafe-erp-system/refs/heads/main/css/system-er-caf-v3.3.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807787/; classtype:trojan-activity;sid:84670887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nopaleafifo630/tic-tac-toe-game/raw/refs/heads/main/nepotistical/game_tac_toe_tic_v1.2.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807788/; classtype:trojan-activity;sid:84670888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeckef/unnamed_game_1_v2/raw/refs/heads/main/epidictical/game-unnamed-v-1.3-beta.4.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807790/; classtype:trojan-activity;sid:84670890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustkimkureshi/blood-donation-sql-project/refs/heads/main/reference/project-blood-sql-donation-1.4-beta.5.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807779/; classtype:trojan-activity;sid:84670879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mustkimkureshi/blood-donation-sql-project/raw/refs/heads/main/reference/project-blood-sql-donation-1.4-beta.5.zip"; depth:114; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807781/; classtype:trojan-activity;sid:84670881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"90.224.208.161"; depth:14; isdataat:!1,relative; metadata:created_at 2026_03_28; reference:url, urlhaus.abuse.ch/url/3806913/; classtype:trojan-activity;sid:84670013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.220.132.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806637/; classtype:trojan-activity;sid:84669737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"27.220.132.248"; depth:14; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806627/; classtype:trojan-activity;sid:84669727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sa.sh"; depth:6; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806307/; classtype:trojan-activity;sid:84669407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ph.sh"; depth:6; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806305/; classtype:trojan-activity;sid:84669405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xx.sh"; depth:6; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806306/; classtype:trojan-activity;sid:84669406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i.sh"; depth:5; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806302/; classtype:trojan-activity;sid:84669402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sc.sh"; depth:6; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806303/; classtype:trojan-activity;sid:84669403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/re.sh"; depth:6; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805847/; classtype:trojan-activity;sid:84668947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/libsystem.so"; depth:13; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805839/; classtype:trojan-activity;sid:84668939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl-amd64"; depth:11; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805840/; classtype:trojan-activity;sid:84668940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl-aarch64"; depth:13; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805841/; classtype:trojan-activity;sid:84668941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/acb.sh"; depth:7; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805837/; classtype:trojan-activity;sid:84668937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mt.sh"; depth:6; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805838/; classtype:trojan-activity;sid:84668938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"217.208.164.149"; depth:15; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805755/; classtype:trojan-activity;sid:84668855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl"; depth:5; endswith; nocase; http.host; content:"66.71.242.68"; depth:12; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805559/; classtype:trojan-activity;sid:84668659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3804863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/imagetxt0074751.png"; depth:20; endswith; nocase; http.host; content:"solar-sanat.net"; depth:15; isdataat:!1,relative; metadata:created_at 2026_03_25; reference:url, urlhaus.abuse.ch/url/3804863/; classtype:trojan-activity;sid:84667963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armaan29-09-2005/ai-osint-security-analyzer/raw/refs/heads/main/.streamlit/security_a_osin_analyzer_3.9.zip"; depth:108; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803904/; classtype:trojan-activity;sid:84667004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armaan29-09-2005/ai-osint-security-analyzer/refs/heads/main/.streamlit/security_a_osin_analyzer_3.9.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803901/; classtype:trojan-activity;sid:84667001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modyd/kaggle-ai-agents-google-capstone/refs/heads/master/backend/agents/capstone_a_google_agents_kaggle_3.9-alpha.2.zip"; depth:120; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803891/; classtype:trojan-activity;sid:84666991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modyd/kaggle-ai-agents-google-capstone/raw/refs/heads/master/backend/agents/capstone_a_google_agents_kaggle_3.9-alpha.2.zip"; depth:124; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803892/; classtype:trojan-activity;sid:84666992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zukochris/ebyte-amsi-patchless-vehhwbp/raw/refs/heads/main/hwbp-amsibypass/vehhwbp-ebyte-patchless-amsi-3.8.zip"; depth:112; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803847/; classtype:trojan-activity;sid:84666947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayushcsh/advent-of-hacks/refs/heads/main/straightforwardness/advent-hacks-of-1.8.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803850/; classtype:trojan-activity;sid:84666950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zukochris/ebyte-amsi-patchless-vehhwbp/refs/heads/main/hwbp-amsibypass/vehhwbp-ebyte-patchless-amsi-3.8.zip"; depth:108; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803851/; classtype:trojan-activity;sid:84666951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elmamlaka/shopify-traffic-filter-block-bots/refs/heads/main/chernozem/bots_block_shopify_filter_traffic_v2.7.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803839/; classtype:trojan-activity;sid:84666939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elmamlaka/shopify-traffic-filter-block-bots/raw/refs/heads/main/chernozem/bots_block_shopify_filter_traffic_v2.7.zip"; depth:117; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803843/; classtype:trojan-activity;sid:84666943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayushcsh/advent-of-hacks/raw/refs/heads/main/straightforwardness/advent-hacks-of-1.8.zip"; depth:89; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803844/; classtype:trojan-activity;sid:84666944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tsntizka/23/raw/refs/heads/main/in/23.txt"; depth:42; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803799/; classtype:trojan-activity;sid:84666899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b0zrx/b0zrx.github.io/raw/refs/heads/main/bandstand/zrx_io_github_b_v2.6.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803804/; classtype:trojan-activity;sid:84666904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tsntizka/23/refs/heads/main/in/23.txt"; depth:38; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803797/; classtype:trojan-activity;sid:84666897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyrustmods/github.io/refs/heads/master/assets/mobirise/github_io_1.4.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803779/; classtype:trojan-activity;sid:84666879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabinakhatun14588-ctrl/moltbook-agent-guard/raw/refs/heads/main/integrations/guard_moltbook_agent_1.8.zip"; depth:106; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803782/; classtype:trojan-activity;sid:84666882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyrustmods/github.io/raw/refs/heads/master/assets/mobirise/github_io_1.4.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803784/; classtype:trojan-activity;sid:84666884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyrustmods/openclaw-skill-safe/refs/heads/master/grandame/skil-safe-opencla-v3.4.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803789/; classtype:trojan-activity;sid:84666889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyrustmods/openclaw-skill-safe/raw/refs/heads/master/grandame/skil-safe-opencla-v3.4.zip"; depth:89; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803794/; classtype:trojan-activity;sid:84666894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b0zrx/rationtrack/raw/refs/heads/main/docs/docs/docs/ration-track-2.6-beta.5.zip"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803795/; classtype:trojan-activity;sid:84666895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b0zrx/rationtrack/refs/heads/main/docs/docs/docs/ration-track-2.6-beta.5.zip"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803796/; classtype:trojan-activity;sid:84666896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b0zrx/b0zrx.github.io/refs/heads/main/bandstand/zrx_io_github_b_v2.6.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803761/; classtype:trojan-activity;sid:84666861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabinakhatun14588-ctrl/sabinakhatun14588-ctrl.github.io/raw/refs/heads/main/aigialosaurus/github-sabinakhatun-ctrl-io-v3.0.zip"; depth:127; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803766/; classtype:trojan-activity;sid:84666866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabinakhatun14588-ctrl/sabinakhatun14588-ctrl.github.io/refs/heads/main/aigialosaurus/github-sabinakhatun-ctrl-io-v3.0.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803767/; classtype:trojan-activity;sid:84666867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sabinakhatun14588-ctrl/moltbook-agent-guard/refs/heads/main/integrations/guard_moltbook_agent_1.8.zip"; depth:102; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803768/; classtype:trojan-activity;sid:84666868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eldenisek/syro-theme/refs/heads/main/images/syro_theme_v3.7.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803738/; classtype:trojan-activity;sid:84666838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerfyjubay/phitto-phishing/refs/heads/main/lib/src/phitto-phishing-1.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803739/; classtype:trojan-activity;sid:84666839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kankertje2/anti-shannon/raw/refs/heads/main/src/wukong/anti_shannon_v2.9.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803740/; classtype:trojan-activity;sid:84666840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eldenisek/anti-afk/refs/heads/main/anticrisis/anti-afk-v1.2.zip"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803741/; classtype:trojan-activity;sid:84666841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eldenisek/anti-afk/raw/refs/heads/main/anticrisis/anti-afk-v1.2.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803742/; classtype:trojan-activity;sid:84666842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eldenisek/syro-theme/raw/refs/heads/main/images/syro_theme_v3.7.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803744/; classtype:trojan-activity;sid:84666844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nerfyjubay/phitto-phishing/raw/refs/heads/main/lib/src/phitto-phishing-1.3.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803748/; classtype:trojan-activity;sid:84666848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saeeed123/1af-starwars-theoldrepublicff/refs/heads/main/residentially/af_star_the_wars_old_republicff_2.5.zip"; depth:110; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803749/; classtype:trojan-activity;sid:84666849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shaggyt0701/prompt-shield/refs/heads/main/examples/prompt-shield-v1.3-alpha.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803750/; classtype:trojan-activity;sid:84666850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shaggyt0701/prompt-shield/raw/refs/heads/main/examples/prompt-shield-v1.3-alpha.3.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803754/; classtype:trojan-activity;sid:84666854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saeeed123/1af-starwars-theoldrepublicff/raw/refs/heads/main/residentially/af_star_the_wars_old_republicff_2.5.zip"; depth:114; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803733/; classtype:trojan-activity;sid:84666833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kankertje2/anti-shannon/refs/heads/main/src/wukong/anti_shannon_v2.9.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803735/; classtype:trojan-activity;sid:84666835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apgmightking/security-audit-framework-shell/refs/heads/main/auditreports/security_audit_shell_framework_3.8.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803709/; classtype:trojan-activity;sid:84666809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apgmightking/security-audit-framework-shell/raw/refs/heads/main/auditreports/security_audit_shell_framework_3.8.zip"; depth:116; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803712/; classtype:trojan-activity;sid:84666812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hfuhuu/nvidiacapture/raw/refs/heads/main/embind/nvidia_capture_1.8-alpha.3.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803705/; classtype:trojan-activity;sid:84666805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hfuhuu/nvidiacapture/refs/heads/main/embind/nvidia_capture_1.8-alpha.3.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803706/; classtype:trojan-activity;sid:84666806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kmjs632/png/refs/heads/main/optimizedmsi.png"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_23; reference:url, urlhaus.abuse.ch/url/3803384/; classtype:trojan-activity;sid:84666484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3802108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/charliefloud-bot/testrepository/refs/heads/main/cryptifyv2upload.txt"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3802108/; classtype:trojan-activity;sid:84665208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/algobytesolutions/best-crypto-telegram-channels/raw/refs/heads/main/analyzer/migrations/channels_crypto_telegram_best_v2.7.zip"; depth:127; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801866/; classtype:trojan-activity;sid:84664966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/algobytesolutions/best-crypto-telegram-channels/refs/heads/main/analyzer/migrations/channels_crypto_telegram_best_v2.7.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801868/; classtype:trojan-activity;sid:84664968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/savagegodfather/tma-llms-txt/raw/refs/heads/main/technolithic/txt-tma-llms-v1.7.zip"; depth:84; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801845/; classtype:trojan-activity;sid:84664945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eridanux/eridanux.github.io/raw/refs/heads/main/excentral/github-eridanux-io-v1.7-beta.2.zip"; depth:93; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801846/; classtype:trojan-activity;sid:84664946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/savagegodfather/savagegodfather.github.io/raw/refs/heads/main/proctorling/savagegodfather-github-io-v2.8-beta.2.zip"; depth:116; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801848/; classtype:trojan-activity;sid:84664948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eridanux/blades-of-fire-external-toolset/refs/heads/branch/ischiocerite/of-blades-fire-external-toolset-2.0.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801838/; classtype:trojan-activity;sid:84664938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/savagegodfather/tma-llms-txt/refs/heads/main/technolithic/txt-tma-llms-v1.7.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801839/; classtype:trojan-activity;sid:84664939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eridanux/eridanux.github.io/refs/heads/main/excentral/github-eridanux-io-v1.7-beta.2.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801840/; classtype:trojan-activity;sid:84664940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eridanux/blades-of-fire-external-toolset/raw/refs/heads/branch/ischiocerite/of-blades-fire-external-toolset-2.0.zip"; depth:116; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801841/; classtype:trojan-activity;sid:84664941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eridanux/cashu-skill/raw/refs/heads/main/cli/cashu-skill-v3.6.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801842/; classtype:trojan-activity;sid:84664942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/savagegodfather/savagegodfather.github.io/refs/heads/main/proctorling/savagegodfather-github-io-v2.8-beta.2.zip"; depth:112; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801843/; classtype:trojan-activity;sid:84664943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eridanux/cashu-skill/refs/heads/main/cli/cashu-skill-v3.6.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801844/; classtype:trojan-activity;sid:84664944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sablive25/sablive25.github.io/raw/refs/heads/main/tumor/io-github-sablive-1.8.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800822/; classtype:trojan-activity;sid:84663922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sablive25/sablive25.github.io/refs/heads/main/tumor/io-github-sablive-1.8.zip"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800823/; classtype:trojan-activity;sid:84663923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/longtengsiha/arbitrum-dapp-skill/refs/heads/main/references/arbitrum_dapp_skill_2.7-beta.2.zip"; depth:95; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800813/; classtype:trojan-activity;sid:84663913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/longtengsiha/arbitrum-dapp-skill/raw/refs/heads/main/references/arbitrum_dapp_skill_2.7-beta.2.zip"; depth:99; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800815/; classtype:trojan-activity;sid:84663915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sablive25/iranpipfix/refs/heads/main/spangled/fix-pip-iran-1.2.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800817/; classtype:trojan-activity;sid:84663917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sablive25/iranpipfix/raw/refs/heads/main/spangled/fix-pip-iran-1.2.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800818/; classtype:trojan-activity;sid:84663918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2332245/2332245.github.io/refs/heads/main/endlichite/github_io_v3.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800802/; classtype:trojan-activity;sid:84663902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2332245/starspring/raw/refs/heads/main/starspring/decorators/software-v3.8-beta.3.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800803/; classtype:trojan-activity;sid:84663903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2332245/2332245.github.io/raw/refs/heads/main/endlichite/github_io_v3.5.zip"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800804/; classtype:trojan-activity;sid:84663904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/69ir/opensem/raw/refs/heads/main/configs/sem_open_v2.2.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800805/; classtype:trojan-activity;sid:84663905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/69ir/opensem/refs/heads/main/configs/sem_open_v2.2.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800806/; classtype:trojan-activity;sid:84663906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/69ir/69ir.github.io/refs/heads/main/outbring/io_github_ir_v3.3.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800807/; classtype:trojan-activity;sid:84663907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2332245/starspring/refs/heads/main/starspring/decorators/software-v3.8-beta.3.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800808/; classtype:trojan-activity;sid:84663908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/69ir/69ir.github.io/raw/refs/heads/main/outbring/io_github_ir_v3.3.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800811/; classtype:trojan-activity;sid:84663911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan02/assignment/refs/heads/main/pluricipital/software_v1.8.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800757/; classtype:trojan-activity;sid:84663857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan02/ecommerce_backend/raw/refs/heads/main/controllers/backend-ecommerce-1.4-beta.1.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800759/; classtype:trojan-activity;sid:84663859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan02/ecommerce_backend/refs/heads/main/controllers/backend-ecommerce-1.4-beta.1.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800760/; classtype:trojan-activity;sid:84663860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/players123/soenneker.gen.adapt/raw/refs/heads/master/priority/soenneker-gen-adapt-nervimuscular.zip"; depth:100; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800753/; classtype:trojan-activity;sid:84663853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan02/assignment/raw/refs/heads/main/pluricipital/software_v1.8.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800754/; classtype:trojan-activity;sid:84663854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan02/ecommerce_frontend/raw/refs/heads/main/src/pages/collectionpage/collectionpagemenu/frontend-ecommerce-v1.0.zip"; depth:119; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800755/; classtype:trojan-activity;sid:84663855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan02/pwskills_assignment/raw/refs/heads/main/bucolic/assignment-pwskills-v1.6.zip"; depth:85; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800746/; classtype:trojan-activity;sid:84663846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan02/pwskills_assignment/refs/heads/main/bucolic/assignment-pwskills-v1.6.zip"; depth:81; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800748/; classtype:trojan-activity;sid:84663848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arpan02/ecommerce_frontend/refs/heads/main/src/pages/collectionpage/collectionpagemenu/frontend-ecommerce-v1.0.zip"; depth:115; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800749/; classtype:trojan-activity;sid:84663849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/players123/soenneker.gen.adapt/refs/heads/master/priority/soenneker-gen-adapt-nervimuscular.zip"; depth:96; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800750/; classtype:trojan-activity;sid:84663850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/portfoilio/refs/heads/main/.vscode/software-1.9.zip"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800583/; classtype:trojan-activity;sid:84663683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/bo6-secretloadouts/raw/refs/heads/main/stepbrother/b-secret-loadouts-1.7.zip"; depth:90; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800584/; classtype:trojan-activity;sid:84663684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/digital-resume-builder/raw/refs/heads/main/public/digital-builder-resume-predramatic.zip"; depth:102; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800579/; classtype:trojan-activity;sid:84663679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/portfoilio/raw/refs/heads/main/.vscode/software-1.9.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800580/; classtype:trojan-activity;sid:84663680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/digital-resume-builder/refs/heads/main/public/digital-builder-resume-predramatic.zip"; depth:98; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800581/; classtype:trojan-activity;sid:84663681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/bo6-secretloadouts/refs/heads/main/stepbrother/b-secret-loadouts-1.7.zip"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800582/; classtype:trojan-activity;sid:84663682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/powersub-demo-1078/refs/heads/main/shufflingly/demo_powersub_v2.0.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800577/; classtype:trojan-activity;sid:84663677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mannkalariya/powersub-demo-1078/raw/refs/heads/main/shufflingly/demo_powersub_v2.0.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800578/; classtype:trojan-activity;sid:84663678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dellarwalter/throttleai/refs/heads/main/examples/ai_throttle_2.2-beta.2.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800569/; classtype:trojan-activity;sid:84663669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/charlieallen16/vibeshell/raw/refs/heads/master/src/components/editserverdialog/software_v3.3.zip"; depth:97; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800567/; classtype:trojan-activity;sid:84663667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dellarwalter/throttleai/raw/refs/heads/main/examples/ai_throttle_2.2-beta.2.zip"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800568/; classtype:trojan-activity;sid:84663668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/charlieallen16/vibeshell/refs/heads/master/src/components/editserverdialog/software_v3.3.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800566/; classtype:trojan-activity;sid:84663666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/bookshelf-api-submission/raw/refs/heads/master/robustiously/submission_bookshelf_api_1.0.zip"; depth:105; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800558/; classtype:trojan-activity;sid:84663658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/bit-of-business-os/raw/refs/heads/master/images/os_bit_of_business_v2.9.zip"; depth:88; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800559/; classtype:trojan-activity;sid:84663659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/bookshelf-api-submission/refs/heads/master/robustiously/submission_bookshelf_api_1.0.zip"; depth:101; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800560/; classtype:trojan-activity;sid:84663660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/rest-api-app/raw/refs/heads/main/flaskr/rest_app_api_2.7.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800561/; classtype:trojan-activity;sid:84663661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/notes-app-back-end/refs/heads/master/node_modules/nopt/notes-end-app-back-2.4.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800562/; classtype:trojan-activity;sid:84663662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/rest-api-app/refs/heads/main/flaskr/rest_app_api_2.7.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800563/; classtype:trojan-activity;sid:84663663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kattimatti22/vibecode-playground/refs/heads/main/hooks/playground_vibecode_2.8.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800552/; classtype:trojan-activity;sid:84663652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/bit-of-business-os/refs/heads/master/images/os_bit_of_business_v2.9.zip"; depth:84; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800553/; classtype:trojan-activity;sid:84663653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kattimatti22/vibecode-playground/raw/refs/heads/main/hooks/playground_vibecode_2.8.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800554/; classtype:trojan-activity;sid:84663654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/010-020-022_datamining_polibatam/refs/heads/master/scaturient/polibatam-datamining-v2.5.zip"; depth:104; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800555/; classtype:trojan-activity;sid:84663655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/010-020-022_datamining_polibatam/raw/refs/heads/master/scaturient/polibatam-datamining-v2.5.zip"; depth:108; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800556/; classtype:trojan-activity;sid:84663656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/danieltulus/notes-app-back-end/raw/refs/heads/master/node_modules/nopt/notes-end-app-back-2.4.zip"; depth:98; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800557/; classtype:trojan-activity;sid:84663657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anjdjwjf/fastuator/refs/heads/main/examples/software-1.5.zip"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800245/; classtype:trojan-activity;sid:84663345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anjdjwjf/fastuator/raw/refs/heads/main/examples/software-1.5.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800247/; classtype:trojan-activity;sid:84663347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/okesing/neergz-web-app/refs/heads/main/canel/app-neergz-web-v2.9.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800239/; classtype:trojan-activity;sid:84663339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kasjan2137/azure-ml-pipeline/refs/heads/main/components/pipeline-azure-ml-3.8.zip"; depth:82; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800240/; classtype:trojan-activity;sid:84663340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/okesing/neergz-web-app/raw/refs/heads/main/canel/app-neergz-web-v2.9.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800241/; classtype:trojan-activity;sid:84663341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kasjan2137/azure-ml-pipeline/raw/refs/heads/main/components/pipeline-azure-ml-3.8.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800242/; classtype:trojan-activity;sid:84663342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pirateshadow/nan111de/raw/refs/heads/main/spiketop/na_de_presentably.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799901/; classtype:trojan-activity;sid:84663001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pirateshadow/nan111de/refs/heads/main/spiketop/na_de_presentably.zip"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799902/; classtype:trojan-activity;sid:84663002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fezarecool/mcp-claude-hackernews/raw/refs/heads/master/entach/hackernews_mcp_claude_v1.9.zip"; depth:93; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799874/; classtype:trojan-activity;sid:84662974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fezarecool/mcp-claude-hackernews/refs/heads/master/entach/hackernews_mcp_claude_v1.9.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799873/; classtype:trojan-activity;sid:84662973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/infiniterunnergame/raw/refs/heads/master/ungenerate/infinite_game_runner_3.4.zip"; depth:93; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799860/; classtype:trojan-activity;sid:84662960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/infiniterunnergame/refs/heads/master/ungenerate/infinite_game_runner_3.4.zip"; depth:89; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799859/; classtype:trojan-activity;sid:84662959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/les-moders/raw/refs/heads/main/les-modern/les_moders_v2.2.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799856/; classtype:trojan-activity;sid:84662956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/pong/raw/refs/heads/master/pong_game/software-v2.0.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799857/; classtype:trojan-activity;sid:84662957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/homework/raw/refs/heads/master/heteroeciousness/software-1.8.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799858/; classtype:trojan-activity;sid:84662958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/pong/refs/heads/master/pong_game/software-v2.0.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799855/; classtype:trojan-activity;sid:84662955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/les-moders/refs/heads/main/les-modern/les_moders_v2.2.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799851/; classtype:trojan-activity;sid:84662951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/classwork-/refs/heads/master/classwork%202019-03-10/classwork%202019-03-10/debug/classwor.929ce1fa.tlog/classwork_v1.4-alpha.5.zip"; depth:143; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799852/; classtype:trojan-activity;sid:84662952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/homework/refs/heads/master/heteroeciousness/software-1.8.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799853/; classtype:trojan-activity;sid:84662953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jarrenstyle/classwork-/raw/refs/heads/master/classwork%202019-03-10/classwork%202019-03-10/debug/classwor.929ce1fa.tlog/classwork_v1.4-alpha.5.zip"; depth:147; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799854/; classtype:trojan-activity;sid:84662954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/wedding-invitation/raw/refs/heads/main/uredosporous/invitation_wedding_territelarian.zip"; depth:104; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799339/; classtype:trojan-activity;sid:84662439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/tech-educa/raw/refs/heads/main/annoyment/tech-educa-wried.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799330/; classtype:trojan-activity;sid:84662430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/sistem-cis/raw/refs/heads/main/assets/js/core/cis_siste_v1.4.zip"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799332/; classtype:trojan-activity;sid:84662432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/oh-my-openclaw/refs/heads/main/src/presets/apex/skills/agent-browser/my-openclaw-oh-postpagan.zip"; depth:113; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799333/; classtype:trojan-activity;sid:84662433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/sistem-cis/refs/heads/main/assets/js/core/cis_siste_v1.4.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799335/; classtype:trojan-activity;sid:84662435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/wordpress/refs/heads/main/standard/software_v1.4.zip"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799336/; classtype:trojan-activity;sid:84662436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/test-pull/refs/heads/main/volucrine/test-pull-v2.3.zip"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799337/; classtype:trojan-activity;sid:84662437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/test-pull/raw/refs/heads/main/volucrine/test-pull-v2.3.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799338/; classtype:trojan-activity;sid:84662438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/supervpn-premium-unlocked-edition/raw/refs/heads/branch/sarcophagize/supervpn-premium-edition-unlocked-v1.4.zip"; depth:127; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799323/; classtype:trojan-activity;sid:84662423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/php/raw/refs/heads/main/kerbstone/software_v1.4.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799324/; classtype:trojan-activity;sid:84662424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/php/refs/heads/main/kerbstone/software_v1.4.zip"; depth:63; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799325/; classtype:trojan-activity;sid:84662425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/tech-educa/refs/heads/main/annoyment/tech-educa-wried.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799326/; classtype:trojan-activity;sid:84662426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/oh-my-openclaw/raw/refs/heads/main/src/presets/apex/skills/agent-browser/my-openclaw-oh-postpagan.zip"; depth:117; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799327/; classtype:trojan-activity;sid:84662427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/supervpn-premium-unlocked-edition/refs/heads/branch/sarcophagize/supervpn-premium-edition-unlocked-v1.4.zip"; depth:123; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799328/; classtype:trojan-activity;sid:84662428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/wordpress/raw/refs/heads/main/standard/software_v1.4.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799329/; classtype:trojan-activity;sid:84662429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fathanghani864/wedding-invitation/refs/heads/main/uredosporous/invitation_wedding_territelarian.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799320/; classtype:trojan-activity;sid:84662420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chester1900/rmisimplebanksystem/raw/refs/heads/master/src/bank-system-rmi-simple-2.8.zip"; depth:89; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799207/; classtype:trojan-activity;sid:84662307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adammtn/wincam-no-trial/raw/refs/heads/main/bandrol/trial-win-no-cam-2.1.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799186/; classtype:trojan-activity;sid:84662286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chester1900/txt-to-video-leech-uploader/raw/refs/heads/main/dodecahydrated/t_tx_vide_leec_uploader_3.7.zip"; depth:107; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799187/; classtype:trojan-activity;sid:84662287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unresponsive-in384/temporal_reasoning_vision_system/raw/refs/heads/main/utils/reasoning-vision-system-temporal-inauration.zip"; depth:126; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799190/; classtype:trojan-activity;sid:84662290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adammtn/wincam-no-trial/refs/heads/main/bandrol/trial-win-no-cam-2.1.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799198/; classtype:trojan-activity;sid:84662298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chester1900/rmisimplebanksystem/refs/heads/master/src/bank-system-rmi-simple-2.8.zip"; depth:85; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799199/; classtype:trojan-activity;sid:84662299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unresponsive-in384/temporal_reasoning_vision_system/refs/heads/main/utils/reasoning-vision-system-temporal-inauration.zip"; depth:122; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799200/; classtype:trojan-activity;sid:84662300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chester1900/txt-to-video-leech-uploader/refs/heads/main/dodecahydrated/t_tx_vide_leec_uploader_3.7.zip"; depth:103; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799201/; classtype:trojan-activity;sid:84662301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sameer2135/offcam/refs/heads/main/opinable/cam_off_v2.2.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799177/; classtype:trojan-activity;sid:84662277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sameer2135/offcam/raw/refs/heads/main/opinable/cam_off_v2.2.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799178/; classtype:trojan-activity;sid:84662278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shivansh-aiml/vuejs-cicd-deploy-on-github-pages/refs/heads/main/src/github_on_cicd_deploy_vuejs_pages_3.6-beta.2.zip"; depth:117; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799155/; classtype:trojan-activity;sid:84662255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shivansh-aiml/vuejs-cicd-deploy-on-github-pages/raw/refs/heads/main/src/github_on_cicd_deploy_vuejs_pages_3.6-beta.2.zip"; depth:121; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799156/; classtype:trojan-activity;sid:84662256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-muhammadahmad/best-blox-fruits-auto-farming-2025/raw/refs/heads/master/src/views/activitymanagement/reports/mylogsummaryreport/list/components/columns/farming-blox-auto-fruits-best-v3.0.zip"; depth:192; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799108/; classtype:trojan-activity;sid:84662208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i-muhammadahmad/best-blox-fruits-auto-farming-2025/refs/heads/master/src/views/activitymanagement/reports/mylogsummaryreport/list/components/columns/farming-blox-auto-fruits-best-v3.0.zip"; depth:188; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799109/; classtype:trojan-activity;sid:84662209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kelasdeb/kelasdeb.github.io/refs/heads/main/whun/kelasdeb-github-io-2.8.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799099/; classtype:trojan-activity;sid:84662199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kelasdeb/kelasdeb.github.io/raw/refs/heads/main/whun/kelasdeb-github-io-2.8.zip"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799098/; classtype:trojan-activity;sid:84662198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kelasdeb/customnamesforgeysermc/refs/heads/main/verby/for-geyser-custom-names-mc-v3.5.zip"; depth:90; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799096/; classtype:trojan-activity;sid:84662196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kelasdeb/customnamesforgeysermc/raw/refs/heads/main/verby/for-geyser-custom-names-mc-v3.5.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799097/; classtype:trojan-activity;sid:84662197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/josemaq/5536/raw/refs/heads/main/26/85.txt"; depth:43; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799090/; classtype:trojan-activity;sid:84662190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/josemaq/5536/refs/heads/main/26/85.txt"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799089/; classtype:trojan-activity;sid:84662189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lolo10201/trial-project/refs/heads/main/login_page.txt"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798895/; classtype:trojan-activity;sid:84661995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lolo10201/trial-project/raw/refs/heads/main/login_page.txt"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798896/; classtype:trojan-activity;sid:84661996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; depth:63; endswith; nocase; http.host; content:"cloud.pearlpeel.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798879/; classtype:trojan-activity;sid:84661979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/159zhx/pet-simulator-99/refs/heads/main/barbasco/pet_simulator_v2.5.zip"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798873/; classtype:trojan-activity;sid:84661973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/159zhx/pet-simulator-99/raw/refs/heads/main/barbasco/pet_simulator_v2.5.zip"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798874/; classtype:trojan-activity;sid:84661974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paul111-beep/roblox-murder-mystery/raw/refs/heads/main/sanballat/mystery_roblox_murder_v2.2-alpha.5.zip"; depth:104; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798868/; classtype:trojan-activity;sid:84661968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paul111-beep/roblox-murder-mystery/refs/heads/main/sanballat/mystery_roblox_murder_v2.2-alpha.5.zip"; depth:100; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798867/; classtype:trojan-activity;sid:84661967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/igmp24184/roblox-macro-v3.0.0/raw/refs/heads/main/language/roblo-macr-v2.1.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798845/; classtype:trojan-activity;sid:84661945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/igmp24184/roblox-macro-v3.0.0/refs/heads/main/language/roblo-macr-v2.1.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798844/; classtype:trojan-activity;sid:84661944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/localdumbass2112/adoptmescript/raw/refs/heads/main/marshalman/software-v3.9.zip"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798825/; classtype:trojan-activity;sid:84661925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cvcj503/permission_studio/refs/heads/main/permission_studio/config/studio-permission-2.9.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798826/; classtype:trojan-activity;sid:84661926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cvcj503/permission_studio/raw/refs/heads/main/permission_studio/config/studio-permission-2.9.zip"; depth:97; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798827/; classtype:trojan-activity;sid:84661927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/localdumbass2112/adoptmescript/refs/heads/main/marshalman/software-v3.9.zip"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798828/; classtype:trojan-activity;sid:84661928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jazzman08/adopt-me-script/refs/heads/main/cornification/me_adopt_script_2.0.zip"; depth:80; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798819/; classtype:trojan-activity;sid:84661919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jazzman08/adopt-me-script/raw/refs/heads/main/cornification/me_adopt_script_2.0.zip"; depth:84; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798820/; classtype:trojan-activity;sid:84661920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linapatel518/cv/raw/refs/heads/main/relayman/software-v3.3.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798813/; classtype:trojan-activity;sid:84661913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linapatel518/cv/refs/heads/main/relayman/software-v3.3.zip"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798812/; classtype:trojan-activity;sid:84661912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linapatel518/drumkit/refs/heads/main/images/kit_drum_v2.7.zip"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798810/; classtype:trojan-activity;sid:84661910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linapatel518/drumkit/raw/refs/heads/main/images/kit_drum_v2.7.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798811/; classtype:trojan-activity;sid:84661911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linapatel518/rbxfpsunlocker/refs/heads/main/sheepwalker/software_v2.5.zip"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798808/; classtype:trojan-activity;sid:84661908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linapatel518/rbxfpsunlocker/raw/refs/heads/main/sheepwalker/software_v2.5.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798809/; classtype:trojan-activity;sid:84661909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qouzk/now.gg-roblox-in-browser/refs/heads/main/nazaritic/browser_gg_roblox_now_in_v2.4.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798801/; classtype:trojan-activity;sid:84661901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qouzk/now.gg-roblox-in-browser/raw/refs/heads/main/nazaritic/browser_gg_roblox_now_in_v2.4.zip"; depth:95; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798802/; classtype:trojan-activity;sid:84661902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ishu-276/adoptmescript/refs/heads/main/archduchy/software_v3.0.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798799/; classtype:trojan-activity;sid:84661899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ishu-276/adoptmescript/raw/refs/heads/main/archduchy/software_v3.0.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798800/; classtype:trojan-activity;sid:84661900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oceanremodeling/fischroblox/refs/heads/main/trichroic/fisch-roblox-3.5.zip"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798797/; classtype:trojan-activity;sid:84661897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oceanremodeling/fischroblox/raw/refs/heads/main/trichroic/fisch-roblox-3.5.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798796/; classtype:trojan-activity;sid:84661896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibrahim832023/adoptme-script-download/raw/refs/heads/main/palingenesy/script_m_adopt_download_v1.6.zip"; depth:103; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798795/; classtype:trojan-activity;sid:84661895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ibrahim832023/adoptme-script-download/refs/heads/main/palingenesy/script_m_adopt_download_v1.6.zip"; depth:99; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798792/; classtype:trojan-activity;sid:84661892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/expect8iondev/towersim-hardcore-evolution/raw/refs/heads/branch/capitolium/hardcore_towersim_evolution_2.1.zip"; depth:111; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798789/; classtype:trojan-activity;sid:84661889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/expect8iondev/towersim-hardcore-evolution/refs/heads/branch/capitolium/hardcore_towersim_evolution_2.1.zip"; depth:107; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798790/; classtype:trojan-activity;sid:84661890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahmoudwagih1/ant-man-simulator-toolkit/refs/heads/branch/barrabkie/toolkit_simulator_ant_man_pursily.zip"; depth:106; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798787/; classtype:trojan-activity;sid:84661887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mahmoudwagih1/ant-man-simulator-toolkit/raw/refs/heads/branch/barrabkie/toolkit_simulator_ant_man_pursily.zip"; depth:110; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798788/; classtype:trojan-activity;sid:84661888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3797992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"213.87.112.128"; depth:14; isdataat:!1,relative; metadata:created_at 2026_03_17; reference:url, urlhaus.abuse.ch/url/3797992/; classtype:trojan-activity;sid:84661092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabssama12/gabssama12.github.io/raw/refs/heads/main/paganishly/github-gabssama-io-3.7-beta.1.zip"; depth:97; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796281/; classtype:trojan-activity;sid:84659381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabssama12/gabssama12.github.io/refs/heads/main/paganishly/github-gabssama-io-3.7-beta.1.zip"; depth:93; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796278/; classtype:trojan-activity;sid:84659378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabssama12/plugin.video.netflix/refs/heads/master/docs/netflix-video-plugin-3.0-beta.1.zip"; depth:91; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796279/; classtype:trojan-activity;sid:84659379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabssama12/plugin.video.netflix/raw/refs/heads/master/docs/netflix-video-plugin-3.0-beta.1.zip"; depth:95; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796280/; classtype:trojan-activity;sid:84659380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabssama12/spoon-awesome-skill/raw/refs/heads/master/spoonos-skills/platform-integration/scripts/spoon_awesome_skill_1.0.zip"; depth:125; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796277/; classtype:trojan-activity;sid:84659377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gabssama12/spoon-awesome-skill/refs/heads/master/spoonos-skills/platform-integration/scripts/spoon_awesome_skill_1.0.zip"; depth:121; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796276/; classtype:trojan-activity;sid:84659376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tianlanyb/gemini-in-chrome/raw/refs/heads/master/eighteen/in_gemini_chrome_preadherent.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796266/; classtype:trojan-activity;sid:84659366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tianlanyb/gemini-in-chrome/refs/heads/master/eighteen/in_gemini_chrome_preadherent.zip"; depth:87; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796267/; classtype:trojan-activity;sid:84659367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jhonatanait14/dictate.sh/refs/heads/main/docs/sh-dictate-2.9-alpha.5.zip"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796264/; classtype:trojan-activity;sid:84659364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jhonatanait14/dictate.sh/raw/refs/heads/main/docs/sh-dictate-2.9-alpha.5.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796265/; classtype:trojan-activity;sid:84659365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samuelhaxk/41369/refs/heads/main/256/233.txt"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796092/; classtype:trojan-activity;sid:84659192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samuelhaxk/41369/raw/refs/heads/main/256/233.txt"; depth:49; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796087/; classtype:trojan-activity;sid:84659187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3795199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pardufrigi_installer_1.0.p1.exe"; depth:32; endswith; nocase; http.host; content:"pardu.pages.dev"; depth:15; isdataat:!1,relative; metadata:created_at 2026_03_13; reference:url, urlhaus.abuse.ch/url/3795199/; classtype:trojan-activity;sid:84658299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3794598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rustdesk-1.2.3-2-x86_64.exe"; depth:28; endswith; nocase; http.host; content:"www.150.co.il"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_12; reference:url, urlhaus.abuse.ch/url/3794598/; classtype:trojan-activity;sid:84657698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3793666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"96.66.24.241"; depth:12; isdataat:!1,relative; metadata:created_at 2026_03_10; reference:url, urlhaus.abuse.ch/url/3793666/; classtype:trojan-activity;sid:84656766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3793659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pdf/pdf/screenconnect.clientsetup.msi"; depth:38; endswith; nocase; http.host; content:"preciosasjoyitas.com.mx"; depth:23; isdataat:!1,relative; metadata:created_at 2026_03_10; reference:url, urlhaus.abuse.ch/url/3793659/; classtype:trojan-activity;sid:84656759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3793628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"96.66.24.241"; depth:12; isdataat:!1,relative; metadata:created_at 2026_03_10; reference:url, urlhaus.abuse.ch/url/3793628/; classtype:trojan-activity;sid:84656728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/p"; depth:2; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_09; reference:url, urlhaus.abuse.ch/url/3792979/; classtype:trojan-activity;sid:84656079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/busybox"; depth:8; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_09; reference:url, urlhaus.abuse.ch/url/3792980/; classtype:trojan-activity;sid:84656080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/for"; depth:4; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_09; reference:url, urlhaus.abuse.ch/url/3792977/; classtype:trojan-activity;sid:84656077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kinsing"; depth:8; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3792566/; classtype:trojan-activity;sid:84655666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kinsing_aarch64"; depth:16; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3792567/; classtype:trojan-activity;sid:84655667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrget.exe"; depth:11; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3792474/; classtype:trojan-activity;sid:84655574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3791876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/umari4u2get-cmd/encoder/raw/refs/heads/main/include/encoder1.txt"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3791876/; classtype:trojan-activity;sid:84654976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3791877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/umari4u2get-cmd/encoder/refs/heads/main/include/encoder1.txt"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3791877/; classtype:trojan-activity;sid:84654977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3791680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/twizt.exe"; depth:10; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_07; reference:url, urlhaus.abuse.ch/url/3791680/; classtype:trojan-activity;sid:84654780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3791280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jquery.min-4.0.2.js"; depth:20; endswith; nocase; http.host; content:"union.macoms.la"; depth:15; isdataat:!1,relative; metadata:created_at 2026_03_07; reference:url, urlhaus.abuse.ch/url/3791280/; classtype:trojan-activity;sid:84654380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3790144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hinda/arabelle/mirabella/dinah/staci|3f|theresa=benni_rp"; depth:57; endswith; nocase; http.host; content:"blankeyeo.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_05; reference:url, urlhaus.abuse.ch/url/3790144/; classtype:trojan-activity;sid:84653244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3789461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ti/dajoke2.exe"; depth:15; endswith; nocase; http.host; content:"imagefiles-backup.oss-ap-southeast-7.aliyuncs.com"; depth:49; isdataat:!1,relative; metadata:created_at 2026_03_04; reference:url, urlhaus.abuse.ch/url/3789461/; classtype:trojan-activity;sid:84652561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3789027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/media/txmclygo.exe"; depth:19; endswith; nocase; http.host; content:"kokorostore.it"; depth:14; isdataat:!1,relative; metadata:created_at 2026_03_03; reference:url, urlhaus.abuse.ch/url/3789027/; classtype:trojan-activity;sid:84652127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3788401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"200.122.211.138"; depth:15; isdataat:!1,relative; metadata:created_at 2026_03_02; reference:url, urlhaus.abuse.ch/url/3788401/; classtype:trojan-activity;sid:84651501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3788379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/optimized_msi.png"; depth:18; endswith; nocase; http.host; content:"coralasargetia.ro"; depth:17; isdataat:!1,relative; metadata:created_at 2026_03_02; reference:url, urlhaus.abuse.ch/url/3788379/; classtype:trojan-activity;sid:84651479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3788376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/optimized_msi.png"; depth:18; endswith; nocase; http.host; content:"separadordecc.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_03_02; reference:url, urlhaus.abuse.ch/url/3788376/; classtype:trojan-activity;sid:84651476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3788070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pg.sh"; depth:6; endswith; nocase; http.host; content:"78.153.140.16"; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_01; reference:url, urlhaus.abuse.ch/url/3788070/; classtype:trojan-activity;sid:84651170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3787077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"37.142.77.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3787077/; classtype:trojan-activity;sid:84650177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3787067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.86.246.233"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3787067/; classtype:trojan-activity;sid:84650167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ssa_statement.msi"; depth:18; endswith; nocase; http.host; content:"bnet.playm8ru.win"; depth:17; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3786888/; classtype:trojan-activity;sid:84649988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ssa_statement.msi"; depth:18; endswith; nocase; http.host; content:"bnet-api.playm8ru.win"; depth:21; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3786879/; classtype:trojan-activity;sid:84649979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ssa_statement.msi"; depth:18; endswith; nocase; http.host; content:"212.224.107.246"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3786841/; classtype:trojan-activity;sid:84649941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"115.190.250.28"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3786364/; classtype:trojan-activity;sid:84649464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"37.142.77.163"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3786353/; classtype:trojan-activity;sid:84649453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c/186def/%e7%bd%91%e6%98%93%e4%ba%91%e9%9f%b3%e4%b9%90.exe"; depth:59; endswith; nocase; http.host; content:"dubapkg.cmcmcdn.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3786320/; classtype:trojan-activity;sid:84649420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soloobr/z-loops/refs/heads/master/updatelm/properties/loops_z_v2.9.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3785810/; classtype:trojan-activity;sid:84648910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soloobr/z-loops/raw/refs/heads/master/updatelm/properties/loops_z_v2.9.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3785811/; classtype:trojan-activity;sid:84648911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soloobr/z-loops/raw/refs/heads/master/breathseller/z-loops.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3785788/; classtype:trojan-activity;sid:84648888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"47.152.112.236"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785486/; classtype:trojan-activity;sid:84648586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.166.91.145"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785484/; classtype:trojan-activity;sid:84648584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackwall0220/roblox-discord-status-bot/raw/refs/heads/master/pelodytes/status-roblox-discord-bot-v2.8.zip"; depth:107; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785421/; classtype:trojan-activity;sid:84648521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/satish-ss/roblox-matcha/raw/refs/heads/master/bacula/matcha-roblox-v3.9-beta.1.zip"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785380/; classtype:trojan-activity;sid:84648480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3784859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/16784059/p.zip"; depth:38; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_24; reference:url, urlhaus.abuse.ch/url/3784859/; classtype:trojan-activity;sid:84647959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3784860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/16784059/p.zip"; depth:38; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_24; reference:url, urlhaus.abuse.ch/url/3784860/; classtype:trojan-activity;sid:84647960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3784413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.118.128.34"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_23; reference:url, urlhaus.abuse.ch/url/3784413/; classtype:trojan-activity;sid:84647513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/6/6/20180724185728_petk_uc_1.4.0.apk"; depth:39; endswith; nocase; http.host; content:"downali.game.uc.cn"; depth:18; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783631/; classtype:trojan-activity;sid:84646731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/%e5%88%92%e5%ad%a6%e5%8f%b7v2--%e6%9e%81%e9%80%9f%e7%89%88.exe"; depth:63; endswith; nocase; http.host; content:"xn--h6qpop2cq9nl9c.pages.dev"; depth:28; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783627/; classtype:trojan-activity;sid:84646727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/soft/111210/1_0048481261.rar"; depth:37; endswith; nocase; http.host; content:"cn.unionlever.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783623/; classtype:trojan-activity;sid:84646723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/approved%20document%23d53lu.msi"; depth:32; endswith; nocase; http.host; content:"pub-bbbdebc2599c4d74b04c5d53e439f7a7.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783624/; classtype:trojan-activity;sid:84646724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/approved%20document%23402.vbs"; depth:30; endswith; nocase; http.host; content:"pub-bbbdebc2599c4d74b04c5d53e439f7a7.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783597/; classtype:trojan-activity;sid:84646697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qbix01.exe"; depth:11; endswith; nocase; http.host; content:"sutterpoint.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783601/; classtype:trojan-activity;sid:84646701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"185.60.107.150"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783423/; classtype:trojan-activity;sid:84646523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"87.138.104.129"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783426/; classtype:trojan-activity;sid:84646526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"159.196.16.186"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783414/; classtype:trojan-activity;sid:84646514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"90.180.227.121"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783409/; classtype:trojan-activity;sid:84646509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"82.139.95.202"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783405/; classtype:trojan-activity;sid:84646505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"202.129.16.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783397/; classtype:trojan-activity;sid:84646497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"218.103.122.102"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783395/; classtype:trojan-activity;sid:84646495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"193.165.245.46"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783384/; classtype:trojan-activity;sid:84646484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"92.43.24.71"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783372/; classtype:trojan-activity;sid:84646472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"121.101.79.178"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783369/; classtype:trojan-activity;sid:84646469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"202.175.181.210"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783366/; classtype:trojan-activity;sid:84646466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"109.167.133.17"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783363/; classtype:trojan-activity;sid:84646463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"84.86.236.173"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783352/; classtype:trojan-activity;sid:84646452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"78.44.199.50"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783343/; classtype:trojan-activity;sid:84646443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"49.176.254.54"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783331/; classtype:trojan-activity;sid:84646431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"75.214.255.79"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783326/; classtype:trojan-activity;sid:84646426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"108.41.80.142"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783304/; classtype:trojan-activity;sid:84646404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"213.165.183.55"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783296/; classtype:trojan-activity;sid:84646396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"182.93.58.234"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783275/; classtype:trojan-activity;sid:84646375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"188.167.179.75"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783257/; classtype:trojan-activity;sid:84646357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"158.140.167.192"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783248/; classtype:trojan-activity;sid:84646348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"174.71.238.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783244/; classtype:trojan-activity;sid:84646344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"96.49.197.7"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783230/; classtype:trojan-activity;sid:84646330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"220.246.34.66"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783231/; classtype:trojan-activity;sid:84646331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"80.147.3.138"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783213/; classtype:trojan-activity;sid:84646313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"218.188.43.38"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783202/; classtype:trojan-activity;sid:84646302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"116.86.50.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783209/; classtype:trojan-activity;sid:84646309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"141.134.214.46"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783197/; classtype:trojan-activity;sid:84646297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"31.55.236.199"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783199/; classtype:trojan-activity;sid:84646299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"118.200.67.119"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783189/; classtype:trojan-activity;sid:84646289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"144.6.89.62"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_20; reference:url, urlhaus.abuse.ch/url/3781942/; classtype:trojan-activity;sid:84645042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.104.195.210"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_19; reference:url, urlhaus.abuse.ch/url/3781329/; classtype:trojan-activity;sid:84644429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"144.6.89.62"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_19; reference:url, urlhaus.abuse.ch/url/3781328/; classtype:trojan-activity;sid:84644428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oga/freshone.js"; depth:16; endswith; nocase; http.host; content:"miriamgualda.com.br"; depth:19; isdataat:!1,relative; metadata:created_at 2026_02_19; reference:url, urlhaus.abuse.ch/url/3781160/; classtype:trojan-activity;sid:84644260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"98.195.187.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780767/; classtype:trojan-activity;sid:84643867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"36.64.227.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780332/; classtype:trojan-activity;sid:84643432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"200.54.221.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780319/; classtype:trojan-activity;sid:84643419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ghost.bot.apk.v13.apk"; depth:22; endswith; nocase; http.host; content:"shadowbot-dih.pages.dev"; depth:23; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780170/; classtype:trojan-activity;sid:84643270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shadow-bot-v11.apk"; depth:19; endswith; nocase; http.host; content:"shadowbot-dih.pages.dev"; depth:23; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780164/; classtype:trojan-activity;sid:84643264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3779935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"103.90.206.87"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_17; reference:url, urlhaus.abuse.ch/url/3779935/; classtype:trojan-activity;sid:84643035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3779937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"103.93.200.20"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_17; reference:url, urlhaus.abuse.ch/url/3779937/; classtype:trojan-activity;sid:84643037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3779934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"213.6.196.230"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_17; reference:url, urlhaus.abuse.ch/url/3779934/; classtype:trojan-activity;sid:84643034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3779755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.67.246.82"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_17; reference:url, urlhaus.abuse.ch/url/3779755/; classtype:trojan-activity;sid:84642855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3778871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"101.200.193.211"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_16; reference:url, urlhaus.abuse.ch/url/3778871/; classtype:trojan-activity;sid:84641971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3778793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/ueditor/php/upload/file/20250114/x1/ref-cli%20v1.0.3.exe"; depth:62; endswith; nocase; http.host; content:"m.meta-dm.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_16; reference:url, urlhaus.abuse.ch/url/3778793/; classtype:trojan-activity;sid:84641893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3778746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/15%ec%8b%ac%ed%94%8c%ec%8a%a4%ec%ba%94.exe"; depth:43; endswith; nocase; http.host; content:"m.jkoa.co.kr"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_16; reference:url, urlhaus.abuse.ch/url/3778746/; classtype:trojan-activity;sid:84641846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"103.74.5.124"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777931/; classtype:trojan-activity;sid:84641031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"118.139.167.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777918/; classtype:trojan-activity;sid:84641018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"172.96.189.153"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777919/; classtype:trojan-activity;sid:84641019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/plugins/cloudflare/challenge/ishuman/id53728/"; depth:46; endswith; nocase; http.host; content:"widexenmexico.com.mx"; depth:20; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777916/; classtype:trojan-activity;sid:84641016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/old_backup/"; depth:12; endswith; nocase; http.host; content:"216.119.126.23"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777906/; classtype:trojan-activity;sid:84641006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.148.18.221"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777793/; classtype:trojan-activity;sid:84640893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"195.158.90.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777241/; classtype:trojan-activity;sid:84640341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"184.160.27.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777197/; classtype:trojan-activity;sid:84640297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.8.20.75"; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777182/; classtype:trojan-activity;sid:84640282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fscan32.exe"; depth:12; endswith; nocase; http.host; content:"124.44.3.74"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777084/; classtype:trojan-activity;sid:84640184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beacon.exe"; depth:11; endswith; nocase; http.host; content:"124.44.3.74"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777069/; classtype:trojan-activity;sid:84640169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scr/omgo/approval3546.msi"; depth:26; endswith; nocase; http.host; content:"luizmatoso.com.br"; depth:17; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777049/; classtype:trojan-activity;sid:84640149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ref62535.msi"; depth:13; endswith; nocase; http.host; content:"vizyonuniversitesi.web.tr"; depth:25; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777048/; classtype:trojan-activity;sid:84640148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3776660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ftgyxe"; depth:7; endswith; nocase; http.host; content:"fukt.link"; depth:9; isdataat:!1,relative; metadata:created_at 2026_02_12; reference:url, urlhaus.abuse.ch/url/3776660/; classtype:trojan-activity;sid:84639760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3776659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qarsws"; depth:7; endswith; nocase; http.host; content:"fukt.link"; depth:9; isdataat:!1,relative; metadata:created_at 2026_02_12; reference:url, urlhaus.abuse.ch/url/3776659/; classtype:trojan-activity;sid:84639759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3776653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joh/encrypted.ps1"; depth:18; endswith; nocase; http.host; content:"refaccionesalma.com.mx"; depth:22; isdataat:!1,relative; metadata:created_at 2026_02_12; reference:url, urlhaus.abuse.ch/url/3776653/; classtype:trojan-activity;sid:84639753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3775926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"195.158.90.40"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_11; reference:url, urlhaus.abuse.ch/url/3775926/; classtype:trojan-activity;sid:84639026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/busybox-armv7l"; depth:15; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774709/; classtype:trojan-activity;sid:84637809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"117.72.181.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774678/; classtype:trojan-activity;sid:84637778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"179.43.186.214"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774663/; classtype:trojan-activity;sid:84637763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"47.105.36.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774642/; classtype:trojan-activity;sid:84637742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"52.248.41.253"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774628/; classtype:trojan-activity;sid:84637728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"87.119.108.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774274/; classtype:trojan-activity;sid:84637374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"181.171.188.254"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774247/; classtype:trojan-activity;sid:84637347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2onsolana/armv4l"; depth:18; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774076/; classtype:trojan-activity;sid:84637176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2onsolana/mips"; depth:16; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774074/; classtype:trojan-activity;sid:84637174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2onsolana/aarch64"; depth:19; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774075/; classtype:trojan-activity;sid:84637175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2onsolana/mpsl"; depth:16; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774073/; classtype:trojan-activity;sid:84637173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2onsolana/armv6l"; depth:18; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774071/; classtype:trojan-activity;sid:84637171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2onsolana/x86"; depth:15; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774072/; classtype:trojan-activity;sid:84637172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2onsolana/armv7l"; depth:18; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774070/; classtype:trojan-activity;sid:84637170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2onsolana/armv5l"; depth:18; endswith; nocase; http.host; content:"156.246.93.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774069/; classtype:trojan-activity;sid:84637169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gif.gif"; depth:8; endswith; nocase; http.host; content:"pjsn.hi2.ro"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3773540/; classtype:trojan-activity;sid:84636640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"202.88.234.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3773437/; classtype:trojan-activity;sid:84636537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"77.50.222.238"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3773429/; classtype:trojan-activity;sid:84636529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"184.160.27.44"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3773432/; classtype:trojan-activity;sid:84636532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"45.173.12.30"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_06; reference:url, urlhaus.abuse.ch/url/3773268/; classtype:trojan-activity;sid:84636368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"91.185.1.70"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_06; reference:url, urlhaus.abuse.ch/url/3773253/; classtype:trojan-activity;sid:84636353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"88.135.26.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_06; reference:url, urlhaus.abuse.ch/url/3773239/; classtype:trojan-activity;sid:84636339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"50.43.160.231"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772764/; classtype:trojan-activity;sid:84635864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"196.39.143.113"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772572/; classtype:trojan-activity;sid:84635672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"77.46.170.18"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772543/; classtype:trojan-activity;sid:84635643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"41.162.188.251"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772537/; classtype:trojan-activity;sid:84635637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"36.88.6.203"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772534/; classtype:trojan-activity;sid:84635634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"178.220.234.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772536/; classtype:trojan-activity;sid:84635636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/microsoftteamupdate.msi"; depth:24; endswith; nocase; http.host; content:"vrajras.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772510/; classtype:trojan-activity;sid:84635610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.40.178.238"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771747/; classtype:trojan-activity;sid:84634847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"95.62.202.150"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771741/; classtype:trojan-activity;sid:84634841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"70.45.151.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771659/; classtype:trojan-activity;sid:84634759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"70.45.151.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771648/; classtype:trojan-activity;sid:84634748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_121424_mahal-node1/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771632/; classtype:trojan-activity;sid:84634732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"203.121.236.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771493/; classtype:trojan-activity;sid:84634593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"47.201.14.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771458/; classtype:trojan-activity;sid:84634558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"203.212.222.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771442/; classtype:trojan-activity;sid:84634542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"47.201.14.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771420/; classtype:trojan-activity;sid:84634520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"203.212.222.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771416/; classtype:trojan-activity;sid:84634516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"98.195.187.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771410/; classtype:trojan-activity;sid:84634510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"98.195.187.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771405/; classtype:trojan-activity;sid:84634505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"47.201.14.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771394/; classtype:trojan-activity;sid:84634494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"98.195.187.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771393/; classtype:trojan-activity;sid:84634493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"47.201.14.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771357/; classtype:trojan-activity;sid:84634457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"203.212.222.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771346/; classtype:trojan-activity;sid:84634446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"203.121.236.145"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771336/; classtype:trojan-activity;sid:84634436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"47.201.14.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771319/; classtype:trojan-activity;sid:84634419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"98.195.187.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771292/; classtype:trojan-activity;sid:84634392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"203.212.222.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771258/; classtype:trojan-activity;sid:84634358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"47.201.14.128"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771234/; classtype:trojan-activity;sid:84634334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"203.212.222.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771237/; classtype:trojan-activity;sid:84634337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"203.212.222.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771218/; classtype:trojan-activity;sid:84634318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"203.212.222.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771220/; classtype:trojan-activity;sid:84634320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"98.195.187.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771206/; classtype:trojan-activity;sid:84634306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"98.195.187.75"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771190/; classtype:trojan-activity;sid:84634290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bitrix/cache/js/s1/universe_s1/kernel_main/kernel_main_v1.js"; depth:61; endswith; nocase; http.host; content:"alternativas.ru"; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771036/; classtype:trojan-activity;sid:84634136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3770100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; depth:7; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_01; reference:url, urlhaus.abuse.ch/url/3770100/; classtype:trojan-activity;sid:84633200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3767101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bhekinko/test/main/notepad2.dll"; depth:32; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2026_02_01; reference:url, urlhaus.abuse.ch/url/3767101/; classtype:trojan-activity;sid:84630201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty2"; depth:5; endswith; nocase; http.host; content:"69.46.43.35"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766633/; classtype:trojan-activity;sid:84629733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty3"; depth:5; endswith; nocase; http.host; content:"69.46.43.35"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766628/; classtype:trojan-activity;sid:84629728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty4"; depth:5; endswith; nocase; http.host; content:"69.46.43.35"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766630/; classtype:trojan-activity;sid:84629730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pty10"; depth:6; endswith; nocase; http.host; content:"69.46.43.35"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766632/; classtype:trojan-activity;sid:84629732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"213.5.194.56"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766587/; classtype:trojan-activity;sid:84629687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/get/cl.msi"; depth:11; endswith; nocase; http.host; content:"corporacioncrf.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_01_30; reference:url, urlhaus.abuse.ch/url/3766226/; classtype:trojan-activity;sid:84629326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/optimized_msi.png"; depth:18; endswith; nocase; http.host; content:"separadordecc.com"; depth:17; isdataat:!1,relative; metadata:created_at 2026_01_30; reference:url, urlhaus.abuse.ch/url/3766053/; classtype:trojan-activity;sid:84629153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3764383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/order2390.msi"; depth:25; endswith; nocase; http.host; content:"audicontadores.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_01_26; reference:url, urlhaus.abuse.ch/url/3764383/; classtype:trojan-activity;sid:84627483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3763665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.96.96.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_25; reference:url, urlhaus.abuse.ch/url/3763665/; classtype:trojan-activity;sid:84626765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"102.23.89.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_23; reference:url, urlhaus.abuse.ch/url/3762674/; classtype:trojan-activity;sid:84625774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.155.243.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_23; reference:url, urlhaus.abuse.ch/url/3762403/; classtype:trojan-activity;sid:84625503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin.sh"; depth:7; endswith; nocase; http.host; content:"95.155.243.196"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_23; reference:url, urlhaus.abuse.ch/url/3762391/; classtype:trojan-activity;sid:84625491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"102.23.89.5"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3762083/; classtype:trojan-activity;sid:84625183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"106.54.220.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3762054/; classtype:trojan-activity;sid:84625154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"106.54.220.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3762049/; classtype:trojan-activity;sid:84625149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"106.54.220.107"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3762050/; classtype:trojan-activity;sid:84625150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3761843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/caio-arc/links/raw/refs/heads/main/application.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3761843/; classtype:trojan-activity;sid:84624943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3761841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keyur-m/hometask/raw/refs/heads/main/application.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3761841/; classtype:trojan-activity;sid:84624941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3761795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crandd1/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3761795/; classtype:trojan-activity;sid:84624895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3760838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lounger678/lapce/releases/download/1.0.0/lapce-windows.msi"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_20; reference:url, urlhaus.abuse.ch/url/3760838/; classtype:trojan-activity;sid:84623938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3760734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atom.xml"; depth:9; endswith; nocase; http.host; content:"www.backupallfresh2030.com"; depth:26; isdataat:!1,relative; metadata:created_at 2026_01_20; reference:url, urlhaus.abuse.ch/url/3760734/; classtype:trojan-activity;sid:84623834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3759320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/receiveharsh/changebusiness"; depth:28; endswith; nocase; http.host; content:"co-emas.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_17; reference:url, urlhaus.abuse.ch/url/3759320/; classtype:trojan-activity;sid:84622420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3759319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/s"; depth:4; endswith; nocase; http.host; content:"co-emas.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_17; reference:url, urlhaus.abuse.ch/url/3759319/; classtype:trojan-activity;sid:84622419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3758943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/laizi_wzzdh.apk"; depth:21; endswith; nocase; http.host; content:"n.vs108.com"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_16; reference:url, urlhaus.abuse.ch/url/3758943/; classtype:trojan-activity;sid:84622043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3758942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbs/upload/1000/2017/03/16/202395_1101210.apk"; depth:46; endswith; nocase; http.host; content:"jlwz.cn"; depth:7; isdataat:!1,relative; metadata:created_at 2026_01_16; reference:url, urlhaus.abuse.ch/url/3758942/; classtype:trojan-activity;sid:84622042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.95.137.155"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_14; reference:url, urlhaus.abuse.ch/url/3757989/; classtype:trojan-activity;sid:84621089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/imgs.exe"; depth:13; endswith; nocase; http.host; content:"wittenhorst.eu"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_14; reference:url, urlhaus.abuse.ch/url/3757953/; classtype:trojan-activity;sid:84621053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syrins/chatgpt-app/raw/9d9a3d9ce5ba4eb03b7738f99458773e3b4ce7de/inat%20tv.apk"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_14; reference:url, urlhaus.abuse.ch/url/3757907/; classtype:trojan-activity;sid:84621007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/info.zip"; depth:14; endswith; nocase; http.host; content:"182.163.114.232"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_14; reference:url, urlhaus.abuse.ch/url/3757800/; classtype:trojan-activity;sid:84620900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"62.197.62.195"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_13; reference:url, urlhaus.abuse.ch/url/3757377/; classtype:trojan-activity;sid:84620477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3756255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"70.45.151.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_11; reference:url, urlhaus.abuse.ch/url/3756255/; classtype:trojan-activity;sid:84619355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3756023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"70.45.151.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_11; reference:url, urlhaus.abuse.ch/url/3756023/; classtype:trojan-activity;sid:84619123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3756018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"70.45.151.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_11; reference:url, urlhaus.abuse.ch/url/3756018/; classtype:trojan-activity;sid:84619118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3755992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/t36"; depth:4; endswith; nocase; http.host; content:"42.192.39.152"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_11; reference:url, urlhaus.abuse.ch/url/3755992/; classtype:trojan-activity;sid:84619092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3755119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"70.45.151.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_10; reference:url, urlhaus.abuse.ch/url/3755119/; classtype:trojan-activity;sid:84618219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3755067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"70.45.151.28"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_10; reference:url, urlhaus.abuse.ch/url/3755067/; classtype:trojan-activity;sid:84618167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"154.84.212.18"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754766/; classtype:trojan-activity;sid:84617866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"186.138.107.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754760/; classtype:trojan-activity;sid:84617860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"202.131.234.26"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754764/; classtype:trojan-activity;sid:84617864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/reynold/video.scr"; depth:23; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754742/; classtype:trojan-activity;sid:84617842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/reynold/photo.scr"; depth:23; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754743/; classtype:trojan-activity;sid:84617843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/%24recycle.bin/photo.scr"; depth:30; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754744/; classtype:trojan-activity;sid:84617844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/reynold/av.scr"; depth:20; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754745/; classtype:trojan-activity;sid:84617845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/%24recycle.bin/s-1-5-21-513737667-1919666884-561045330-1001/%24rs1r5lt.scr"; depth:80; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754741/; classtype:trojan-activity;sid:84617841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"217.65.15.51"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754739/; classtype:trojan-activity;sid:84617839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"115.178.100.190"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754707/; classtype:trojan-activity;sid:84617807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"78.140.32.219"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754695/; classtype:trojan-activity;sid:84617795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"182.160.102.188"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754702/; classtype:trojan-activity;sid:84617802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"154.0.129.134"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754703/; classtype:trojan-activity;sid:84617803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"195.158.88.156"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754690/; classtype:trojan-activity;sid:84617790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zoldownload/"; depth:13; endswith; nocase; http.host; content:"down10d.zol.com.cn"; depth:18; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754685/; classtype:trojan-activity;sid:84617785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"103.164.117.74"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754677/; classtype:trojan-activity;sid:84617777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"83.218.189.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754656/; classtype:trojan-activity;sid:84617756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"200.54.221.234"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754662/; classtype:trojan-activity;sid:84617762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"89.101.123.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754592/; classtype:trojan-activity;sid:84617692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"197.159.1.58"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754573/; classtype:trojan-activity;sid:84617673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"88.119.151.142"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754551/; classtype:trojan-activity;sid:84617651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpnxp.exe"; depth:27; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754555/; classtype:trojan-activity;sid:84617655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpn7.exe"; depth:26; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754542/; classtype:trojan-activity;sid:84617642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpnx2.exe"; depth:27; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754543/; classtype:trojan-activity;sid:84617643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"43.245.131.27"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754535/; classtype:trojan-activity;sid:84617635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"217.75.193.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754530/; classtype:trojan-activity;sid:84617630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"138.219.58.34"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754533/; classtype:trojan-activity;sid:84617633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"190.12.99.194"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754521/; classtype:trojan-activity;sid:84617621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"87.119.108.21"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754517/; classtype:trojan-activity;sid:84617617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"37.252.69.10"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754511/; classtype:trojan-activity;sid:84617611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"202.148.20.138"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754510/; classtype:trojan-activity;sid:84617610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"81.16.249.96"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754443/; classtype:trojan-activity;sid:84617543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"178.220.234.5"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754444/; classtype:trojan-activity;sid:84617544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"88.135.26.83"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754439/; classtype:trojan-activity;sid:84617539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"94.244.113.217"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754438/; classtype:trojan-activity;sid:84617538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"118.179.121.235"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754384/; classtype:trojan-activity;sid:84617484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"185.12.78.161"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754377/; classtype:trojan-activity;sid:84617477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cryptography_module/base_library.zip"; depth:37; endswith; nocase; http.host; content:"122.170.110.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754379/; classtype:trojan-activity;sid:84617479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"115.240.70.185"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754373/; classtype:trojan-activity;sid:84617473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpnx2.zip"; depth:27; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754359/; classtype:trojan-activity;sid:84617459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"41.190.57.114"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754346/; classtype:trojan-activity;sid:84617446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/namuvpn32.exe"; depth:22; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754340/; classtype:trojan-activity;sid:84617440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pc/pdfconvert/"; depth:15; endswith; nocase; http.host; content:"download.pdf00.com"; depth:18; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754331/; classtype:trojan-activity;sid:84617431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/namu864.exe"; depth:20; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754327/; classtype:trojan-activity;sid:84617427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpn32.zip"; depth:27; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754328/; classtype:trojan-activity;sid:84617428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpnx2/namuvpnx2.exe"; depth:37; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754325/; classtype:trojan-activity;sid:84617425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"46.151.56.42"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754299/; classtype:trojan-activity;sid:84617399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/namuxp.zip"; depth:19; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754282/; classtype:trojan-activity;sid:84617382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"91.147.91.21"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754276/; classtype:trojan-activity;sid:84617376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/namuvpn7.exe"; depth:21; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754274/; classtype:trojan-activity;sid:84617374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpn7.zip"; depth:26; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754262/; classtype:trojan-activity;sid:84617362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpn7/namuvpn7.exe"; depth:35; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754238/; classtype:trojan-activity;sid:84617338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/back/namuvpn32.exe"; depth:27; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754218/; classtype:trojan-activity;sid:84617318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cryptodata/archive_to_send_decr.zip"; depth:36; endswith; nocase; http.host; content:"122.170.110.131"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754194/; classtype:trojan-activity;sid:84617294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"115.127.68.162"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754170/; classtype:trojan-activity;sid:84617270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3753765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/big/img001.exe"; depth:15; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3753765/; classtype:trojan-activity;sid:84616865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3752305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.255.210.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_07; reference:url, urlhaus.abuse.ch/url/3752305/; classtype:trojan-activity;sid:84615405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3750931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1q1q.js"; depth:8; endswith; nocase; http.host; content:"scrroeder.com"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_05; reference:url, urlhaus.abuse.ch/url/3750931/; classtype:trojan-activity;sid:84614031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3750631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/security/wizvera/delfino-g3/delfino-g3.exe"; depth:43; endswith; nocase; http.host; content:"download.kbcard.com"; depth:19; isdataat:!1,relative; metadata:created_at 2026_01_05; reference:url, urlhaus.abuse.ch/url/3750631/; classtype:trojan-activity;sid:84613731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3750258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"45.144.233.192"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_04; reference:url, urlhaus.abuse.ch/url/3750258/; classtype:trojan-activity;sid:84613358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3749775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/buding/dbghelp.dll"; depth:19; endswith; nocase; http.host; content:"59.56.110.227"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_03; reference:url, urlhaus.abuse.ch/url/3749775/; classtype:trojan-activity;sid:84612875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3749771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/buding/dbghelp.dll"; depth:19; endswith; nocase; http.host; content:"45.125.44.137"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_03; reference:url, urlhaus.abuse.ch/url/3749771/; classtype:trojan-activity;sid:84612871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3749167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"188.134.8.43"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_02; reference:url, urlhaus.abuse.ch/url/3749167/; classtype:trojan-activity;sid:84612267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"37.255.210.242"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_02; reference:url, urlhaus.abuse.ch/url/3748887/; classtype:trojan-activity;sid:84611987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"162.215.130.152"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748326/; classtype:trojan-activity;sid:84611426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"104.199.248.167"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748285/; classtype:trojan-activity;sid:84611385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"199.168.184.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748279/; classtype:trojan-activity;sid:84611379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"202.74.75.181"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748275/; classtype:trojan-activity;sid:84611375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"199.168.184.115"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748253/; classtype:trojan-activity;sid:84611353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"69.48.143.20"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748255/; classtype:trojan-activity;sid:84611355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"3.18.128.17"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748247/; classtype:trojan-activity;sid:84611347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"118.139.167.36"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748243/; classtype:trojan-activity;sid:84611343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"18.176.47.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748235/; classtype:trojan-activity;sid:84611335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"54.197.245.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748192/; classtype:trojan-activity;sid:84611292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"98.70.13.131"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748194/; classtype:trojan-activity;sid:84611294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"54.197.245.249"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748187/; classtype:trojan-activity;sid:84611287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"5.63.157.201"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748189/; classtype:trojan-activity;sid:84611289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"185.80.0.36"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748180/; classtype:trojan-activity;sid:84611280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"125.253.125.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748175/; classtype:trojan-activity;sid:84611275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"13.113.8.105"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748169/; classtype:trojan-activity;sid:84611269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"125.253.125.72"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748170/; classtype:trojan-activity;sid:84611270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"209.250.2.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748152/; classtype:trojan-activity;sid:84611252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"20.92.160.27"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748160/; classtype:trojan-activity;sid:84611260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"116.118.47.149"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748163/; classtype:trojan-activity;sid:84611263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"201.182.25.51"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748165/; classtype:trojan-activity;sid:84611265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"108.61.166.232"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748140/; classtype:trojan-activity;sid:84611240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"209.250.2.244"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748137/; classtype:trojan-activity;sid:84611237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"45.77.254.180"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748134/; classtype:trojan-activity;sid:84611234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"150.95.27.35"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748127/; classtype:trojan-activity;sid:84611227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"162.215.130.152"; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748133/; classtype:trojan-activity;sid:84611233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"18.176.47.246"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748104/; classtype:trojan-activity;sid:84611204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"3.141.75.29"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748106/; classtype:trojan-activity;sid:84611206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"44.208.147.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748110/; classtype:trojan-activity;sid:84611210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"95.154.194.17"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748112/; classtype:trojan-activity;sid:84611212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"192.155.93.247"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748115/; classtype:trojan-activity;sid:84611215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"35.75.68.158"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748118/; classtype:trojan-activity;sid:84611218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"35.226.92.8"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748119/; classtype:trojan-activity;sid:84611219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"164.160.41.10"; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748096/; classtype:trojan-activity;sid:84611196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"185.4.64.128"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748066/; classtype:trojan-activity;sid:84611166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"178.210.83.9"; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748069/; classtype:trojan-activity;sid:84611169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"66.39.79.68"; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748089/; classtype:trojan-activity;sid:84611189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"148.113.205.94"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748092/; classtype:trojan-activity;sid:84611192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"180.149.198.22"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748026/; classtype:trojan-activity;sid:84611126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/video.lnk"; depth:15; endswith; nocase; http.host; content:"58.182.146.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747725/; classtype:trojan-activity;sid:84610825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/photo.scr"; depth:15; endswith; nocase; http.host; content:"58.182.146.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747694/; classtype:trojan-activity;sid:84610794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/av.lnk"; depth:12; endswith; nocase; http.host; content:"58.182.146.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747690/; classtype:trojan-activity;sid:84610790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/video.scr"; depth:15; endswith; nocase; http.host; content:"58.182.146.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747685/; classtype:trojan-activity;sid:84610785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/av.scr"; depth:12; endswith; nocase; http.host; content:"58.182.146.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747686/; classtype:trojan-activity;sid:84610786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/photo.lnk"; depth:15; endswith; nocase; http.host; content:"58.182.146.104"; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747684/; classtype:trojan-activity;sid:84610784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3746316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sxp/i/522f8dbab717f669a06afa9122107971.js"; depth:42; endswith; nocase; http.host; content:"ob.youstarsbuilding.com"; depth:23; isdataat:!1,relative; metadata:created_at 2025_12_30; reference:url, urlhaus.abuse.ch/url/3746316/; classtype:trojan-activity;sid:84609416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3746314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sxp/i/522f8dbab717f669a06afa9122107971.js"; depth:42; endswith; nocase; http.host; content:"euob.youstarsbuilding.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_12_30; reference:url, urlhaus.abuse.ch/url/3746314/; classtype:trojan-activity;sid:84609414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3745195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"61.240.239.106"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_28; reference:url, urlhaus.abuse.ch/url/3745195/; classtype:trojan-activity;sid:84608295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3745196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"124.230.216.19"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_28; reference:url, urlhaus.abuse.ch/url/3745196/; classtype:trojan-activity;sid:84608296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3745197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"124.230.216.19"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_28; reference:url, urlhaus.abuse.ch/url/3745197/; classtype:trojan-activity;sid:84608297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3745192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210408/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_28; reference:url, urlhaus.abuse.ch/url/3745192/; classtype:trojan-activity;sid:84608292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3745193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210408/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_28; reference:url, urlhaus.abuse.ch/url/3745193/; classtype:trojan-activity;sid:84608293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3743405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sxp/i/522f8dbab717f669a06afa9122107971.js"; depth:42; endswith; nocase; http.host; content:"euob.youstarsbuilding.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_12_25; reference:url, urlhaus.abuse.ch/url/3743405/; classtype:trojan-activity;sid:84606505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3743323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/plugins/sess1594985553/sessiontools/uvsodsae.msi"; depth:55; endswith; nocase; http.host; content:"royalindiancurryclub.com"; depth:24; isdataat:!1,relative; metadata:created_at 2025_12_25; reference:url, urlhaus.abuse.ch/url/3743323/; classtype:trojan-activity;sid:84606423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3743272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"61.240.239.106"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_25; reference:url, urlhaus.abuse.ch/url/3743272/; classtype:trojan-activity;sid:84606372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3743271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"61.240.239.106"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_25; reference:url, urlhaus.abuse.ch/url/3743271/; classtype:trojan-activity;sid:84606371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3742020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"183.83.186.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3742020/; classtype:trojan-activity;sid:84605120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3742013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"183.83.186.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3742013/; classtype:trojan-activity;sid:84605113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3742007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"183.83.186.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3742007/; classtype:trojan-activity;sid:84605107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3742005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"183.83.186.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3742005/; classtype:trojan-activity;sid:84605105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"183.83.186.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741991/; classtype:trojan-activity;sid:84605091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"183.83.186.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741975/; classtype:trojan-activity;sid:84605075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"183.83.186.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741976/; classtype:trojan-activity;sid:84605076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250101/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741974/; classtype:trojan-activity;sid:84605074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250101/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741972/; classtype:trojan-activity;sid:84605072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250101/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741971/; classtype:trojan-activity;sid:84605071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"106.54.220.107"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741968/; classtype:trojan-activity;sid:84605068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250811/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741966/; classtype:trojan-activity;sid:84605066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250809/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741967/; classtype:trojan-activity;sid:84605067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210408/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741965/; classtype:trojan-activity;sid:84605065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210408/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741962/; classtype:trojan-activity;sid:84605062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250101/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741963/; classtype:trojan-activity;sid:84605063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"61.240.239.106"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741947/; classtype:trojan-activity;sid:84605047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"61.240.239.106"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741948/; classtype:trojan-activity;sid:84605048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"61.240.239.106"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741949/; classtype:trojan-activity;sid:84605049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"61.240.239.106"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741940/; classtype:trojan-activity;sid:84605040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"41.162.188.251"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741538/; classtype:trojan-activity;sid:84604638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"85.187.54.142"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741523/; classtype:trojan-activity;sid:84604623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"85.187.54.142"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741524/; classtype:trojan-activity;sid:84604624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/auhavkiq.msi"; depth:19; endswith; nocase; http.host; content:"royalindiancurryclub.com"; depth:24; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741336/; classtype:trojan-activity;sid:84604436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"152.230.111.46"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741193/; classtype:trojan-activity;sid:84604293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"152.230.111.46"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741153/; classtype:trojan-activity;sid:84604253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"124.230.216.19"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741109/; classtype:trojan-activity;sid:84604209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"124.230.216.19"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741086/; classtype:trojan-activity;sid:84604186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"152.230.111.46"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741068/; classtype:trojan-activity;sid:84604168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"124.230.216.19"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741049/; classtype:trojan-activity;sid:84604149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"182.163.114.232"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741029/; classtype:trojan-activity;sid:84604129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"152.230.111.46"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741026/; classtype:trojan-activity;sid:84604126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"124.230.216.19"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741024/; classtype:trojan-activity;sid:84604124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"124.230.216.19"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741009/; classtype:trojan-activity;sid:84604109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3740979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"152.230.111.46"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3740979/; classtype:trojan-activity;sid:84604079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3740945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"152.230.111.46"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3740945/; classtype:trojan-activity;sid:84604045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3738164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.55.81.169"; depth:11; isdataat:!1,relative; metadata:created_at 2025_12_20; reference:url, urlhaus.abuse.ch/url/3738164/; classtype:trojan-activity;sid:84601264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3736211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atom.xml"; depth:9; endswith; nocase; http.host; content:"hotelsep.blogspot.com"; depth:21; isdataat:!1,relative; metadata:created_at 2025_12_18; reference:url, urlhaus.abuse.ch/url/3736211/; classtype:trojan-activity;sid:84599311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3736212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nimper.pdf"; depth:11; endswith; nocase; http.host; content:"www.backupallfresh2030.com"; depth:26; isdataat:!1,relative; metadata:created_at 2025_12_18; reference:url, urlhaus.abuse.ch/url/3736212/; classtype:trojan-activity;sid:84599312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3735417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl"; depth:5; endswith; nocase; http.host; content:"107.189.6.236"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_17; reference:url, urlhaus.abuse.ch/url/3735417/; classtype:trojan-activity;sid:84598517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3734705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"47.109.198.8"; depth:12; isdataat:!1,relative; metadata:created_at 2025_12_16; reference:url, urlhaus.abuse.ch/url/3734705/; classtype:trojan-activity;sid:84597805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3734700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"213.6.196.230"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_16; reference:url, urlhaus.abuse.ch/url/3734700/; classtype:trojan-activity;sid:84597800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3733895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"37.255.229.18"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_15; reference:url, urlhaus.abuse.ch/url/3733895/; classtype:trojan-activity;sid:84596995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3733819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/liljaber/am/raw/refs/heads/main/shellhost.exe"; depth:46; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_15; reference:url, urlhaus.abuse.ch/url/3733819/; classtype:trojan-activity;sid:84596919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3733042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"129.0.120.134"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_13; reference:url, urlhaus.abuse.ch/url/3733042/; classtype:trojan-activity;sid:84596142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3732386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"217.75.193.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_12; reference:url, urlhaus.abuse.ch/url/3732386/; classtype:trojan-activity;sid:84595486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3732378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"93.39.215.44"; depth:12; isdataat:!1,relative; metadata:created_at 2025_12_12; reference:url, urlhaus.abuse.ch/url/3732378/; classtype:trojan-activity;sid:84595478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3732133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eathena/tools/bymyzter/eabackup.rar"; depth:36; endswith; nocase; http.host; content:"paradox924x.pages.dev"; depth:21; isdataat:!1,relative; metadata:created_at 2025_12_12; reference:url, urlhaus.abuse.ch/url/3732133/; classtype:trojan-activity;sid:84595233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3732129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eathena/tools/bybakausagi/spr_conview_v0.11.zip"; depth:48; endswith; nocase; http.host; content:"paradox924x.pages.dev"; depth:21; isdataat:!1,relative; metadata:created_at 2025_12_12; reference:url, urlhaus.abuse.ch/url/3732129/; classtype:trojan-activity;sid:84595229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modelo/cr.exe"; depth:14; endswith; nocase; http.host; content:"joyeriatauro.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_12_11; reference:url, urlhaus.abuse.ch/url/3731630/; classtype:trojan-activity;sid:84594730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modelo/v1d.exe"; depth:15; endswith; nocase; http.host; content:"joyeriatauro.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_12_11; reference:url, urlhaus.abuse.ch/url/3731351/; classtype:trojan-activity;sid:84594451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/modelo/c1i.exe"; depth:15; endswith; nocase; http.host; content:"joyeriatauro.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_12_11; reference:url, urlhaus.abuse.ch/url/3731347/; classtype:trojan-activity;sid:84594447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nalleysh/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731286/; classtype:trojan-activity;sid:84594386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/el1nns/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731287/; classtype:trojan-activity;sid:84594387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d3xxth/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731283/; classtype:trojan-activity;sid:84594383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/creyty1h/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731275/; classtype:trojan-activity;sid:84594375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1llenth/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731271/; classtype:trojan-activity;sid:84594371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rayn1e/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731257/; classtype:trojan-activity;sid:84594357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/colleshake/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731244/; classtype:trojan-activity;sid:84594344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arcellys/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731243/; classtype:trojan-activity;sid:84594343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n1elcery/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731242/; classtype:trojan-activity;sid:84594342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/recctan1o/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731239/; classtype:trojan-activity;sid:84594339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kesslyy27/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731238/; classtype:trojan-activity;sid:84594338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ssten1/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731232/; classtype:trojan-activity;sid:84594332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.255.229.18"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731161/; classtype:trojan-activity;sid:84594261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"114.242.100.72"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731096/; classtype:trojan-activity;sid:84594196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"203.187.227.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730787/; classtype:trojan-activity;sid:84593887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"203.187.227.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730785/; classtype:trojan-activity;sid:84593885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"203.187.227.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730754/; classtype:trojan-activity;sid:84593854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"203.187.227.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730727/; classtype:trojan-activity;sid:84593827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"203.187.227.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730681/; classtype:trojan-activity;sid:84593781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"203.187.227.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730669/; classtype:trojan-activity;sid:84593769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"203.187.227.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730651/; classtype:trojan-activity;sid:84593751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_122124_mahal-node2/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730605/; classtype:trojan-activity;sid:84593705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3729846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.129.182.138"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_09; reference:url, urlhaus.abuse.ch/url/3729846/; classtype:trojan-activity;sid:84592946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3729416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/js/panel/uploads/optimized_msi.png"; depth:35; endswith; nocase; http.host; content:"bvaco.com"; depth:9; isdataat:!1,relative; metadata:created_at 2025_12_08; reference:url, urlhaus.abuse.ch/url/3729416/; classtype:trojan-activity;sid:84592516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3729248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/clean/clean.apk"; depth:23; endswith; nocase; http.host; content:"static.youdm.cn"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_08; reference:url, urlhaus.abuse.ch/url/3729248/; classtype:trojan-activity;sid:84592348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3729188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"86.89.95.77"; depth:11; isdataat:!1,relative; metadata:created_at 2025_12_08; reference:url, urlhaus.abuse.ch/url/3729188/; classtype:trojan-activity;sid:84592288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3726005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/receipt_11_26_2025.msi"; depth:23; endswith; nocase; http.host; content:"alineeleuterio.com.br"; depth:21; isdataat:!1,relative; metadata:created_at 2025_12_05; reference:url, urlhaus.abuse.ch/url/3726005/; classtype:trojan-activity;sid:84589105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3725395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"182.73.129.30"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3725395/; classtype:trojan-activity;sid:84588495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3725201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/redmi%20ax3000/%e8%b7%af%e7%94%b1%e5%99%a8%e4%bf%ae%e5%a4%8d%e5%b7%a5%e5%85%b7/miwifirepairtool.x86.zip"; depth:109; endswith; nocase; http.host; content:"hzxcaq-github-io.pages.dev"; depth:26; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3725201/; classtype:trojan-activity;sid:84588301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3725129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"115.190.161.178"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3725129/; classtype:trojan-activity;sid:84588229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3725126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"8.137.149.67"; depth:12; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3725126/; classtype:trojan-activity;sid:84588226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3725097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.219.38.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3725097/; classtype:trojan-activity;sid:84588197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3724888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gretech/promotion_sw/gomplayer/fastping_silent_v4.exe"; depth:54; endswith; nocase; http.host; content:"cdn.gomlab.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3724888/; classtype:trojan-activity;sid:84587988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3724884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/linux/linux.tar.gz"; depth:23; endswith; nocase; http.host; content:"miner.pages.dev"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3724884/; classtype:trojan-activity;sid:84587984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3724883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/win/miner.zip"; depth:18; endswith; nocase; http.host; content:"miner.pages.dev"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3724883/; classtype:trojan-activity;sid:84587983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3724034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/res/keditor/2019_11/3c7a829a_893c_4f02_a407_6b0918c321c2.rar"; depth:61; endswith; nocase; http.host; content:"en.taichuan.com"; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_03; reference:url, urlhaus.abuse.ch/url/3724034/; classtype:trojan-activity;sid:84587134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3722385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"138.219.58.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_01; reference:url, urlhaus.abuse.ch/url/3722385/; classtype:trojan-activity;sid:84585485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3722069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app/top8bet.apk"; depth:16; endswith; nocase; http.host; content:"top8onlinegame.com"; depth:18; isdataat:!1,relative; metadata:created_at 2025_12_01; reference:url, urlhaus.abuse.ch/url/3722069/; classtype:trojan-activity;sid:84585169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3721052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/%e5%a5%87%e5%a6%99%e5%8a%a0%e9%80%9f%e5%99%a8_2_10004379.exe/%c3%a5%c2%a5%c2%87%c3%a5%c2%a6%c2%99%c3%a5%c2%8a%c2%a0%c3%a9%c2%80%c2%9f%c3%a5%c2%99%c2%a8_2_10004379.exe/%c3%83%c2%a5%c3%82%c2%a5%c3%82%c2%87%c3%83%c2%a5%c3%82%c2%a6%c3%82%c2%99%c3%83%25...~311~...%ef%bf%bd%c3%82%c2%a8_2_10004379.exe"; depth:305; endswith; nocase; http.host; content:"pvsa.gxfugy.cn"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_30; reference:url, urlhaus.abuse.ch/url/3721052/; classtype:trojan-activity;sid:84584152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/payment_receipt_11_28_2025.msi"; depth:31; endswith; nocase; http.host; content:"vizyonuniversitesi.com.tr"; depth:25; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720416/; classtype:trojan-activity;sid:84583516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/av.lnk"; depth:16; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720339/; classtype:trojan-activity;sid:84583439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/photo.lnk"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720337/; classtype:trojan-activity;sid:84583437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/av.lnk"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720336/; classtype:trojan-activity;sid:84583436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/av.scr"; depth:16; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720335/; classtype:trojan-activity;sid:84583435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/video.scr"; depth:22; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720330/; classtype:trojan-activity;sid:84583430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/av.scr"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720331/; classtype:trojan-activity;sid:84583431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/video.scr"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720332/; classtype:trojan-activity;sid:84583432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/photo.scr"; depth:22; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720333/; classtype:trojan-activity;sid:84583433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/photo.scr"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720334/; classtype:trojan-activity;sid:84583434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/photo.lnk"; depth:22; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720329/; classtype:trojan-activity;sid:84583429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/video.lnk"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720327/; classtype:trojan-activity;sid:84583427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/video.lnk"; depth:22; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720328/; classtype:trojan-activity;sid:84583428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"31.0.222.123"; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720042/; classtype:trojan-activity;sid:84583142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"31.0.222.123"; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720037/; classtype:trojan-activity;sid:84583137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3719973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"31.0.222.123"; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3719973/; classtype:trojan-activity;sid:84583073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3718843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"82.66.224.73"; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_28; reference:url, urlhaus.abuse.ch/url/3718843/; classtype:trojan-activity;sid:84581943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/apps/cpc188.apk"; depth:16; endswith; nocase; http.host; content:"cpc188.day"; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_27; reference:url, urlhaus.abuse.ch/url/3717885/; classtype:trojan-activity;sid:84580985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newwfs/support/customfont.apk"; depth:30; endswith; nocase; http.host; content:"upaicdn.xinmei365.com"; depth:21; isdataat:!1,relative; metadata:created_at 2025_11_27; reference:url, urlhaus.abuse.ch/url/3717880/; classtype:trojan-activity;sid:84580980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/adan/utils/mudtime.zip"; depth:32; endswith; nocase; http.host; content:"paccbet.pages.dev"; depth:17; isdataat:!1,relative; metadata:created_at 2025_11_27; reference:url, urlhaus.abuse.ch/url/3717867/; classtype:trojan-activity;sid:84580967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/safe/setup_smart.exe"; depth:21; endswith; nocase; http.host; content:"dl.ijinshan.com"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_27; reference:url, urlhaus.abuse.ch/url/3717692/; classtype:trojan-activity;sid:84580792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3716961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/krzysztofadamczewski/nanocore-rat/raw/refs/heads/master/nanocore_portable.exe"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_26; reference:url, urlhaus.abuse.ch/url/3716961/; classtype:trojan-activity;sid:84580061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3716962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pafh99/nanocore-rat-2/raw/refs/heads/master/nanocore_portable.exe"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_26; reference:url, urlhaus.abuse.ch/url/3716962/; classtype:trojan-activity;sid:84580062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3716290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/baixar/suporte%20winxp-7-8.zip"; depth:31; endswith; nocase; http.host; content:"compuserviceonline.com.br"; depth:25; isdataat:!1,relative; metadata:created_at 2025_11_25; reference:url, urlhaus.abuse.ch/url/3716290/; classtype:trojan-activity;sid:84579390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3715638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/37/cqsj/official/37cqsj.exe"; depth:28; endswith; nocase; http.host; content:"d.wanyouxi7.com"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_24; reference:url, urlhaus.abuse.ch/url/3715638/; classtype:trojan-activity;sid:84578738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3715587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elc/filesave/setupfile/edmslaunchersetup.exe"; depth:45; endswith; nocase; http.host; content:"lcportal.kbinsure.co.kr"; depth:23; isdataat:!1,relative; metadata:created_at 2025_11_24; reference:url, urlhaus.abuse.ch/url/3715587/; classtype:trojan-activity;sid:84578687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3715579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dropfix"; depth:8; endswith; nocase; http.host; content:"cdn.novoline.top"; depth:16; isdataat:!1,relative; metadata:created_at 2025_11_24; reference:url, urlhaus.abuse.ch/url/3715579/; classtype:trojan-activity;sid:84578679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3715175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fo-wsftp605.exe"; depth:16; endswith; nocase; http.host; content:"landonirwin.com"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_23; reference:url, urlhaus.abuse.ch/url/3715175/; classtype:trojan-activity;sid:84578275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3714635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app/linux.bin"; depth:14; endswith; nocase; http.host; content:"prepstarcenter.com"; depth:18; isdataat:!1,relative; metadata:created_at 2025_11_23; reference:url, urlhaus.abuse.ch/url/3714635/; classtype:trojan-activity;sid:84577735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3714116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wizvera/delfino/down/delfino-g3-sha2.exe"; depth:41; endswith; nocase; http.host; content:"www.hwgeneralins.com"; depth:20; isdataat:!1,relative; metadata:created_at 2025_11_22; reference:url, urlhaus.abuse.ch/url/3714116/; classtype:trojan-activity;sid:84577216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3714095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k1_351.apk"; depth:11; endswith; nocase; http.host; content:"app.appzcvb.com"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_22; reference:url, urlhaus.abuse.ch/url/3714095/; classtype:trojan-activity;sid:84577195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cleaner"; depth:8; endswith; nocase; http.host; content:"gutando.com"; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_22; reference:url, urlhaus.abuse.ch/url/3713850/; classtype:trojan-activity;sid:84576950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.190.74.159"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_21; reference:url, urlhaus.abuse.ch/url/3713493/; classtype:trojan-activity;sid:84576593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stage1.ps1"; depth:11; endswith; nocase; http.host; content:"fb6390d5.infinityindians.pages.dev"; depth:34; isdataat:!1,relative; metadata:created_at 2025_11_21; reference:url, urlhaus.abuse.ch/url/3713469/; classtype:trojan-activity;sid:84576569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amsibypass.ps1"; depth:15; endswith; nocase; http.host; content:"fb6390d5.infinityindians.pages.dev"; depth:34; isdataat:!1,relative; metadata:created_at 2025_11_21; reference:url, urlhaus.abuse.ch/url/3713470/; classtype:trojan-activity;sid:84576570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/bexitor%20installer.exe"; depth:30; endswith; nocase; http.host; content:"matthewsigmondv5.pages.dev"; depth:26; isdataat:!1,relative; metadata:created_at 2025_11_21; reference:url, urlhaus.abuse.ch/url/3713467/; classtype:trojan-activity;sid:84576567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"syn-096-011-145-107.biz.spectrum.com"; depth:36; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712862/; classtype:trojan-activity;sid:84575962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aspnet_client/info.zip"; depth:23; endswith; nocase; http.host; content:"syn-096-011-145-107.biz.spectrum.com"; depth:36; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712861/; classtype:trojan-activity;sid:84575961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/av.lnk"; depth:16; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712796/; classtype:trojan-activity;sid:84575896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/photo.scr"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712795/; classtype:trojan-activity;sid:84575895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/video.scr"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712793/; classtype:trojan-activity;sid:84575893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/video.scr"; depth:22; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712794/; classtype:trojan-activity;sid:84575894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/photo.scr"; depth:22; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712791/; classtype:trojan-activity;sid:84575891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/av.scr"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712792/; classtype:trojan-activity;sid:84575892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/av.scr"; depth:16; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712790/; classtype:trojan-activity;sid:84575890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/av.lnk"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712787/; classtype:trojan-activity;sid:84575887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/video.lnk"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712788/; classtype:trojan-activity;sid:84575888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/photo.lnk"; depth:22; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712789/; classtype:trojan-activity;sid:84575889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/mom/photo.lnk"; depth:19; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712785/; classtype:trojan-activity;sid:84575885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sda1/rachel/video.lnk"; depth:22; endswith; nocase; http.host; content:"27.125.169.235"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712786/; classtype:trojan-activity;sid:84575886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/gof.com.my/gz2v8w/y0qt8nphhv1v"; depth:33; endswith; nocase; http.host; content:"smartermail.host"; depth:16; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712393/; classtype:trojan-activity;sid:84575493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/horioninjector.exe"; depth:23; endswith; nocase; http.host; content:"horion-static.pages.dev"; depth:23; isdataat:!1,relative; metadata:created_at 2025_11_19; reference:url, urlhaus.abuse.ch/url/3712017/; classtype:trojan-activity;sid:84575117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3711282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"47.236.149.142"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_18; reference:url, urlhaus.abuse.ch/url/3711282/; classtype:trojan-activity;sid:84574382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sfyhmsqlexrtjetiqydog74.bin"; depth:28; endswith; nocase; http.host; content:"dexios.co.za"; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_18; reference:url, urlhaus.abuse.ch/url/3710993/; classtype:trojan-activity;sid:84574093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brkopsluth.emz"; depth:15; endswith; nocase; http.host; content:"dexios.co.za"; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_18; reference:url, urlhaus.abuse.ch/url/3710988/; classtype:trojan-activity;sid:84574088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin/screenconnect.clientsetup.msi"; depth:34; endswith; nocase; http.host; content:"rheddh.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710456/; classtype:trojan-activity;sid:84573556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"68.110.47.231"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710429/; classtype:trojan-activity;sid:84573529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"68.110.47.231"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710413/; classtype:trojan-activity;sid:84573513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"68.110.47.231"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710414/; classtype:trojan-activity;sid:84573514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-06-19/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710416/; classtype:trojan-activity;sid:84573516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"68.110.47.231"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710411/; classtype:trojan-activity;sid:84573511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_42625_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710412/; classtype:trojan-activity;sid:84573512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-06-29/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710404/; classtype:trojan-activity;sid:84573504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_71024_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710402/; classtype:trojan-activity;sid:84573502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-03-23/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710394/; classtype:trojan-activity;sid:84573494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-05-03/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710388/; classtype:trojan-activity;sid:84573488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-04-23/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710390/; classtype:trojan-activity;sid:84573490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-10-11/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710385/; classtype:trojan-activity;sid:84573485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-05-20/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710383/; classtype:trojan-activity;sid:84573483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-05-21/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710380/; classtype:trojan-activity;sid:84573480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-02-26/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710370/; classtype:trojan-activity;sid:84573470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-06-27/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710371/; classtype:trojan-activity;sid:84573471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-06-28/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710374/; classtype:trojan-activity;sid:84573474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-09-25/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710362/; classtype:trojan-activity;sid:84573462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-06-22/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710351/; classtype:trojan-activity;sid:84573451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_41724_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710352/; classtype:trojan-activity;sid:84573452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/situa%c3%a7%c3%a3o/2019-07-05/info.zip"; depth:69; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710353/; classtype:trojan-activity;sid:84573453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_61324_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710350/; classtype:trojan-activity;sid:84573450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/situa%c3%a7%c3%a3o/2023-02-01/info.zip"; depth:69; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710340/; classtype:trojan-activity;sid:84573440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-07-05/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710341/; classtype:trojan-activity;sid:84573441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"68.110.47.231"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710342/; classtype:trojan-activity;sid:84573442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-07-27/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710343/; classtype:trojan-activity;sid:84573443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-06-06/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710334/; classtype:trojan-activity;sid:84573434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-05-11/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710323/; classtype:trojan-activity;sid:84573423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-11-22/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710327/; classtype:trojan-activity;sid:84573427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"68.110.47.231"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710320/; classtype:trojan-activity;sid:84573420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_3925_mahal-node2/info.zip"; depth:47; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710315/; classtype:trojan-activity;sid:84573415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-09-28/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710316/; classtype:trojan-activity;sid:84573416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-12-23/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710318/; classtype:trojan-activity;sid:84573418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_10825_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710319/; classtype:trojan-activity;sid:84573419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/situa%c3%a7%c3%a3o/2019-05-02/info.zip"; depth:69; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710311/; classtype:trojan-activity;sid:84573411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_82225_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710312/; classtype:trojan-activity;sid:84573412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-12-14/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710313/; classtype:trojan-activity;sid:84573413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_32824_mahal-server/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710309/; classtype:trojan-activity;sid:84573409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"68.110.47.231"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710310/; classtype:trojan-activity;sid:84573410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/situa%c3%a7%c3%a3o/2020-01-28/info.zip"; depth:69; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710306/; classtype:trojan-activity;sid:84573406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_51025_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710297/; classtype:trojan-activity;sid:84573397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-06-26/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710293/; classtype:trojan-activity;sid:84573393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-10-06/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710285/; classtype:trojan-activity;sid:84573385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-06-21/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710287/; classtype:trojan-activity;sid:84573387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-05-18/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710288/; classtype:trojan-activity;sid:84573388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-07-22/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710289/; classtype:trojan-activity;sid:84573389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/situa%c3%a7%c3%a3o/2019-04-12/info.zip"; depth:69; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710290/; classtype:trojan-activity;sid:84573390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/situa%c3%a7%c3%a3o/2021-05-20/info.zip"; depth:69; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710291/; classtype:trojan-activity;sid:84573391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-06-20/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710284/; classtype:trojan-activity;sid:84573384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/offlinepackv4.exe"; depth:18; endswith; nocase; http.host; content:"dl.360safe.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710207/; classtype:trojan-activity;sid:84573307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soulclientwtf/lnk/raw/refs/heads/main/execute"; depth:46; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_16; reference:url, urlhaus.abuse.ch/url/3710011/; classtype:trojan-activity;sid:84573111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soulclientwtf/lnk/refs/heads/main/execute"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_11_16; reference:url, urlhaus.abuse.ch/url/3710010/; classtype:trojan-activity;sid:84573110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709306/; classtype:trojan-activity;sid:84572406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000677/2019-03-16/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709292/; classtype:trojan-activity;sid:84572392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-05-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709293/; classtype:trojan-activity;sid:84572393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-03-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709294/; classtype:trojan-activity;sid:84572394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-10-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709295/; classtype:trojan-activity;sid:84572395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-01-05/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709296/; classtype:trojan-activity;sid:84572396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-08-23/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709298/; classtype:trojan-activity;sid:84572398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-10-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709299/; classtype:trojan-activity;sid:84572399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-08-03/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709300/; classtype:trojan-activity;sid:84572400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-05-13/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709301/; classtype:trojan-activity;sid:84572401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-10-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709302/; classtype:trojan-activity;sid:84572402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-03-30/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709303/; classtype:trojan-activity;sid:84572403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-05-04/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709304/; classtype:trojan-activity;sid:84572404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-08-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709288/; classtype:trojan-activity;sid:84572388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-10-23/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709290/; classtype:trojan-activity;sid:84572390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2024-01-26/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709291/; classtype:trojan-activity;sid:84572391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-07-05/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709272/; classtype:trojan-activity;sid:84572372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-08-04/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709273/; classtype:trojan-activity;sid:84572373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-08-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709274/; classtype:trojan-activity;sid:84572374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2024-04-09/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709275/; classtype:trojan-activity;sid:84572375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-01-18/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709276/; classtype:trojan-activity;sid:84572376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2022-01-20/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709277/; classtype:trojan-activity;sid:84572377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-04-14/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709278/; classtype:trojan-activity;sid:84572378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-06-29/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709280/; classtype:trojan-activity;sid:84572380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-05-30/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709281/; classtype:trojan-activity;sid:84572381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-04-16/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709284/; classtype:trojan-activity;sid:84572384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-10-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709285/; classtype:trojan-activity;sid:84572385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-11-05/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709286/; classtype:trojan-activity;sid:84572386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-10-08/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709287/; classtype:trojan-activity;sid:84572387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_82624_mahal-node2/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709269/; classtype:trojan-activity;sid:84572369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2019-10-29/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709270/; classtype:trojan-activity;sid:84572370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2020-10-10/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709271/; classtype:trojan-activity;sid:84572371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-02-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709267/; classtype:trojan-activity;sid:84572367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-01-29/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709255/; classtype:trojan-activity;sid:84572355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2020-11-24/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709256/; classtype:trojan-activity;sid:84572356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-07-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709257/; classtype:trojan-activity;sid:84572357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-06-23/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709258/; classtype:trojan-activity;sid:84572358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-11-16/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709259/; classtype:trojan-activity;sid:84572359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-03-20/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709261/; classtype:trojan-activity;sid:84572361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000162/2022-03-02/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709262/; classtype:trojan-activity;sid:84572362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-08-31/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709263/; classtype:trojan-activity;sid:84572363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-05-11/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709264/; classtype:trojan-activity;sid:84572364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-03-03/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709248/; classtype:trojan-activity;sid:84572348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-08-24/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709249/; classtype:trojan-activity;sid:84572349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-04-11/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709250/; classtype:trojan-activity;sid:84572350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-11-01/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709251/; classtype:trojan-activity;sid:84572351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-06-12/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709252/; classtype:trojan-activity;sid:84572352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2024-01-17/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709253/; classtype:trojan-activity;sid:84572353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-11-12/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709254/; classtype:trojan-activity;sid:84572354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-03-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709244/; classtype:trojan-activity;sid:84572344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-05-10/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709245/; classtype:trojan-activity;sid:84572345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2020-09-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709246/; classtype:trojan-activity;sid:84572346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-01-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709247/; classtype:trojan-activity;sid:84572347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709240/; classtype:trojan-activity;sid:84572340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-07-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709241/; classtype:trojan-activity;sid:84572341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-05-15/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709242/; classtype:trojan-activity;sid:84572342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-02-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709239/; classtype:trojan-activity;sid:84572339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2020-11-04/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709234/; classtype:trojan-activity;sid:84572334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-10-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709235/; classtype:trojan-activity;sid:84572335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2025-05-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709236/; classtype:trojan-activity;sid:84572336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-04-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709237/; classtype:trojan-activity;sid:84572337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2019-07-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709238/; classtype:trojan-activity;sid:84572338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-01-04/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709228/; classtype:trojan-activity;sid:84572328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-03-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709229/; classtype:trojan-activity;sid:84572329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000162/2022-07-22/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709230/; classtype:trojan-activity;sid:84572330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-10-13/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709231/; classtype:trojan-activity;sid:84572331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709233/; classtype:trojan-activity;sid:84572333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2019-07-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709220/; classtype:trojan-activity;sid:84572320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2022-03-16/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709221/; classtype:trojan-activity;sid:84572321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-11-15/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709222/; classtype:trojan-activity;sid:84572322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-07-03/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709223/; classtype:trojan-activity;sid:84572323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-12-26/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709224/; classtype:trojan-activity;sid:84572324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-03-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709225/; classtype:trojan-activity;sid:84572325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-03-25/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709227/; classtype:trojan-activity;sid:84572327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-03-15/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709218/; classtype:trojan-activity;sid:84572318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2025-05-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709219/; classtype:trojan-activity;sid:84572319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-01-13/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709213/; classtype:trojan-activity;sid:84572313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-01-14/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709214/; classtype:trojan-activity;sid:84572314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-04-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709209/; classtype:trojan-activity;sid:84572309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-07-18/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709210/; classtype:trojan-activity;sid:84572310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-04-15/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709211/; classtype:trojan-activity;sid:84572311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2023-06-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709212/; classtype:trojan-activity;sid:84572312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000162/2022-03-06/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709201/; classtype:trojan-activity;sid:84572301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2024-03-10/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709202/; classtype:trojan-activity;sid:84572302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-04-25/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709203/; classtype:trojan-activity;sid:84572303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2020-10-12/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709204/; classtype:trojan-activity;sid:84572304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-04-15/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709205/; classtype:trojan-activity;sid:84572305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-03-02/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709206/; classtype:trojan-activity;sid:84572306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-02-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709207/; classtype:trojan-activity;sid:84572307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-04-04/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709193/; classtype:trojan-activity;sid:84572293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2019-10-03/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709194/; classtype:trojan-activity;sid:84572294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-05-01/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709195/; classtype:trojan-activity;sid:84572295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-05-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709196/; classtype:trojan-activity;sid:84572296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709197/; classtype:trojan-activity;sid:84572297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2022-04-11/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709199/; classtype:trojan-activity;sid:84572299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2019-10-15/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709200/; classtype:trojan-activity;sid:84572300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000677/2020-07-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709192/; classtype:trojan-activity;sid:84572292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-01-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709190/; classtype:trojan-activity;sid:84572290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-11-28/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709191/; classtype:trojan-activity;sid:84572291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2021-07-23/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709186/; classtype:trojan-activity;sid:84572286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-10-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709187/; classtype:trojan-activity;sid:84572287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2021-07-19/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709188/; classtype:trojan-activity;sid:84572288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2025-01-13/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709175/; classtype:trojan-activity;sid:84572275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-05-02/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709176/; classtype:trojan-activity;sid:84572276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2025-01-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709177/; classtype:trojan-activity;sid:84572277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-09-18/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709178/; classtype:trojan-activity;sid:84572278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2019-10-10/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709179/; classtype:trojan-activity;sid:84572279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-09-04/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709180/; classtype:trojan-activity;sid:84572280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-10-20/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709181/; classtype:trojan-activity;sid:84572281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2025-04-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709182/; classtype:trojan-activity;sid:84572282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-03-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709184/; classtype:trojan-activity;sid:84572284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-08-27/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709185/; classtype:trojan-activity;sid:84572285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-07-17/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709165/; classtype:trojan-activity;sid:84572265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-07-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709166/; classtype:trojan-activity;sid:84572266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000162/2024-01-22/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709167/; classtype:trojan-activity;sid:84572267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2022-01-27/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709168/; classtype:trojan-activity;sid:84572268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-06-13/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709169/; classtype:trojan-activity;sid:84572269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2025-01-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709170/; classtype:trojan-activity;sid:84572270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-11-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709171/; classtype:trojan-activity;sid:84572271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-11-15/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709172/; classtype:trojan-activity;sid:84572272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-12-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709173/; classtype:trojan-activity;sid:84572273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-07-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709163/; classtype:trojan-activity;sid:84572263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-08-05/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709161/; classtype:trojan-activity;sid:84572261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000677/2019-03-18/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709162/; classtype:trojan-activity;sid:84572262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709158/; classtype:trojan-activity;sid:84572258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000758/2022-03-02/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709152/; classtype:trojan-activity;sid:84572252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2019-10-17/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709153/; classtype:trojan-activity;sid:84572253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2024-01-24/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709154/; classtype:trojan-activity;sid:84572254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-06-05/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709155/; classtype:trojan-activity;sid:84572255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-01-13/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709156/; classtype:trojan-activity;sid:84572256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2023-08-16/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709157/; classtype:trojan-activity;sid:84572257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-05-27/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709143/; classtype:trojan-activity;sid:84572243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-10-12/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709144/; classtype:trojan-activity;sid:84572244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-10-20/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709145/; classtype:trojan-activity;sid:84572245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-07-02/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709147/; classtype:trojan-activity;sid:84572247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-05-19/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709148/; classtype:trojan-activity;sid:84572248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-05-27/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709149/; classtype:trojan-activity;sid:84572249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-10-05/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709150/; classtype:trojan-activity;sid:84572250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2020-05-01/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709151/; classtype:trojan-activity;sid:84572251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-09-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709140/; classtype:trojan-activity;sid:84572240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-10-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709141/; classtype:trojan-activity;sid:84572241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-08-09/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709139/; classtype:trojan-activity;sid:84572239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-11-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709138/; classtype:trojan-activity;sid:84572238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-11-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709129/; classtype:trojan-activity;sid:84572229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-08-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709130/; classtype:trojan-activity;sid:84572230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2025-04-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709131/; classtype:trojan-activity;sid:84572231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2019-05-31/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709132/; classtype:trojan-activity;sid:84572232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-10-25/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709133/; classtype:trojan-activity;sid:84572233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-11-27/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709135/; classtype:trojan-activity;sid:84572235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-06-12/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709136/; classtype:trojan-activity;sid:84572236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-01-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709128/; classtype:trojan-activity;sid:84572228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-09-08/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709112/; classtype:trojan-activity;sid:84572212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-10-15/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709113/; classtype:trojan-activity;sid:84572213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-11-01/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709114/; classtype:trojan-activity;sid:84572214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2024-03-17/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709116/; classtype:trojan-activity;sid:84572216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2022-04-19/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709117/; classtype:trojan-activity;sid:84572217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-11-25/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709118/; classtype:trojan-activity;sid:84572218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-12-31/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709119/; classtype:trojan-activity;sid:84572219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2024-03-04/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709120/; classtype:trojan-activity;sid:84572220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-08-16/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709121/; classtype:trojan-activity;sid:84572221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_92825_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709122/; classtype:trojan-activity;sid:84572222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-01-01/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709123/; classtype:trojan-activity;sid:84572223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-06-30/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709124/; classtype:trojan-activity;sid:84572224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-03-16/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709126/; classtype:trojan-activity;sid:84572226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2019-10-09/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709109/; classtype:trojan-activity;sid:84572209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-06-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709111/; classtype:trojan-activity;sid:84572211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2019-10-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709104/; classtype:trojan-activity;sid:84572204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-12-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709105/; classtype:trojan-activity;sid:84572205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-08-04/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709107/; classtype:trojan-activity;sid:84572207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-05-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709108/; classtype:trojan-activity;sid:84572208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_51125_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709102/; classtype:trojan-activity;sid:84572202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-09-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709103/; classtype:trojan-activity;sid:84572203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000677/2019-03-15/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709097/; classtype:trojan-activity;sid:84572197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-31/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709098/; classtype:trojan-activity;sid:84572198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-12-30/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709099/; classtype:trojan-activity;sid:84572199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2019-07-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709100/; classtype:trojan-activity;sid:84572200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000324/2024-01-02/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709101/; classtype:trojan-activity;sid:84572201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-01-24/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709088/; classtype:trojan-activity;sid:84572188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-10-24/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709089/; classtype:trojan-activity;sid:84572189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-11-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709090/; classtype:trojan-activity;sid:84572190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-05-08/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709091/; classtype:trojan-activity;sid:84572191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-01-03/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709092/; classtype:trojan-activity;sid:84572192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2022-10-27/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709093/; classtype:trojan-activity;sid:84572193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-03-20/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709078/; classtype:trojan-activity;sid:84572178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2024-09-27/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709079/; classtype:trojan-activity;sid:84572179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2024-09-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709080/; classtype:trojan-activity;sid:84572180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-09-20/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709081/; classtype:trojan-activity;sid:84572181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2022-04-20/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709083/; classtype:trojan-activity;sid:84572183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-04-17/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709084/; classtype:trojan-activity;sid:84572184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-11-02/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709085/; classtype:trojan-activity;sid:84572185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-05-12/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709086/; classtype:trojan-activity;sid:84572186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-11-23/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709087/; classtype:trojan-activity;sid:84572187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2025-05-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709075/; classtype:trojan-activity;sid:84572175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-01-14/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709076/; classtype:trojan-activity;sid:84572176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-05-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709077/; classtype:trojan-activity;sid:84572177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2023-06-24/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709054/; classtype:trojan-activity;sid:84572154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-05-05/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709055/; classtype:trojan-activity;sid:84572155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2019-09-26/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709056/; classtype:trojan-activity;sid:84572156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2020-06-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709057/; classtype:trojan-activity;sid:84572157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-12-28/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709058/; classtype:trojan-activity;sid:84572158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2021-07-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709059/; classtype:trojan-activity;sid:84572159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-02-20/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709060/; classtype:trojan-activity;sid:84572160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2021-02-19/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709061/; classtype:trojan-activity;sid:84572161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-07-17/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709062/; classtype:trojan-activity;sid:84572162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-07-15/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709063/; classtype:trojan-activity;sid:84572163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2022-10-05/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709064/; classtype:trojan-activity;sid:84572164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2020-06-01/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709065/; classtype:trojan-activity;sid:84572165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-04-18/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709067/; classtype:trojan-activity;sid:84572167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-03-03/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709068/; classtype:trojan-activity;sid:84572168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-01-23/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709069/; classtype:trojan-activity;sid:84572169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2020-07-14/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709070/; classtype:trojan-activity;sid:84572170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-09-29/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709072/; classtype:trojan-activity;sid:84572172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-11-18/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709042/; classtype:trojan-activity;sid:84572142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-09-08/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709043/; classtype:trojan-activity;sid:84572143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-09-17/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709044/; classtype:trojan-activity;sid:84572144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-04-28/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709045/; classtype:trojan-activity;sid:84572145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000677/2019-03-20/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709046/; classtype:trojan-activity;sid:84572146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-06-16/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709047/; classtype:trojan-activity;sid:84572147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-11-24/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709048/; classtype:trojan-activity;sid:84572148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-10-31/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709049/; classtype:trojan-activity;sid:84572149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000910/2023-06-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709050/; classtype:trojan-activity;sid:84572150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-03-17/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709051/; classtype:trojan-activity;sid:84572151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2022-11-06/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709052/; classtype:trojan-activity;sid:84572152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3709053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos%20autom%c3%a1ticos/2024-04-05/info.zip"; depth:77; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_15; reference:url, urlhaus.abuse.ch/url/3709053/; classtype:trojan-activity;sid:84572153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3708402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ourzz.wav"; depth:10; endswith; nocase; http.host; content:"clubdetiroelpicarcho.com"; depth:24; isdataat:!1,relative; metadata:created_at 2025_11_14; reference:url, urlhaus.abuse.ch/url/3708402/; classtype:trojan-activity;sid:84571502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3707810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_82224_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_14; reference:url, urlhaus.abuse.ch/url/3707810/; classtype:trojan-activity;sid:84570910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3707697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2019/04/pieletjf.exe"; depth:40; endswith; nocase; http.host; content:"theoremaoliveoil.com"; depth:20; isdataat:!1,relative; metadata:created_at 2025_11_14; reference:url, urlhaus.abuse.ch/url/3707697/; classtype:trojan-activity;sid:84570797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3707699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2019/04/pieletjf_vm.exe"; depth:43; endswith; nocase; http.host; content:"theoremaoliveoil.com"; depth:20; isdataat:!1,relative; metadata:created_at 2025_11_14; reference:url, urlhaus.abuse.ch/url/3707699/; classtype:trojan-activity;sid:84570799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.216.139.127"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704602/; classtype:trojan-activity;sid:84567702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_21425_mahal-node2/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704282/; classtype:trojan-activity;sid:84567382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_21625_mahal-node2/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704281/; classtype:trojan-activity;sid:84567381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_12424_mahal-node2/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704279/; classtype:trojan-activity;sid:84567379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_22025_mahal-node2/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704280/; classtype:trojan-activity;sid:84567380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_22225_mahal-node2/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704276/; classtype:trojan-activity;sid:84567376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_12525_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704277/; classtype:trojan-activity;sid:84567377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_22225_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704275/; classtype:trojan-activity;sid:84567375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haozip/haozip_v6.5.2.11245.exe"; depth:31; endswith; nocase; http.host; content:"dl.2345.com"; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704246/; classtype:trojan-activity;sid:84567346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leinchchanceleinch/jik/raw/refs/heads/main/dev.msi"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704158/; classtype:trojan-activity;sid:84567258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220623/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703801/; classtype:trojan-activity;sid:84566901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_101424_mahal-node1/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703784/; classtype:trojan-activity;sid:84566884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_10325_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703785/; classtype:trojan-activity;sid:84566885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_11424_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703777/; classtype:trojan-activity;sid:84566877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_61924_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703767/; classtype:trojan-activity;sid:84566867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20180102/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703764/; classtype:trojan-activity;sid:84566864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_61424_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703763/; classtype:trojan-activity;sid:84566863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_82325_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703759/; classtype:trojan-activity;sid:84566859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_11125_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703760/; classtype:trojan-activity;sid:84566860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_31025_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703747/; classtype:trojan-activity;sid:84566847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_21025_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703748/; classtype:trojan-activity;sid:84566848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_6424_mahal-node1/info.zip"; depth:47; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703749/; classtype:trojan-activity;sid:84566849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_71824_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703756/; classtype:trojan-activity;sid:84566856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_62124_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703743/; classtype:trojan-activity;sid:84566843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_112724_mahal-node1/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703744/; classtype:trojan-activity;sid:84566844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_101124_mahal-server/info.zip"; depth:50; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703745/; classtype:trojan-activity;sid:84566845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_91824_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703737/; classtype:trojan-activity;sid:84566837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_10824_mahal-node2/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703738/; classtype:trojan-activity;sid:84566838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_102524_mahal-node1/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703739/; classtype:trojan-activity;sid:84566839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_101824_mahal-node1/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703734/; classtype:trojan-activity;sid:84566834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_9924_mahal-node1/info.zip"; depth:47; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703735/; classtype:trojan-activity;sid:84566835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_52324_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703736/; classtype:trojan-activity;sid:84566836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20140730/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703731/; classtype:trojan-activity;sid:84566831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_102124_mahal-node2/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703728/; classtype:trojan-activity;sid:84566828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_122624_mahal-node1/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703729/; classtype:trojan-activity;sid:84566829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/info.zip"; depth:17; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3703171/; classtype:trojan-activity;sid:84566271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docimg/info.zip"; depth:16; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3703172/; classtype:trojan-activity;sid:84566272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prodimg/exportimages_42425_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3703166/; classtype:trojan-activity;sid:84566266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_102124_mahal-node1/info.zip"; depth:49; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3703167/; classtype:trojan-activity;sid:84566267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prodimg/exportimages_42425_mahal-node2/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3703163/; classtype:trojan-activity;sid:84566263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/outward/exportimages_10124_mahal-node1/info.zip"; depth:48; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3703164/; classtype:trojan-activity;sid:84566264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"203.192.219.165"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3703165/; classtype:trojan-activity;sid:84566265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dersnotlari/02/sora.jpg"; depth:24; endswith; nocase; http.host; content:"www.notbak.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3702746/; classtype:trojan-activity;sid:84565846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230517/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702204/; classtype:trojan-activity;sid:84565304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250210/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702202/; classtype:trojan-activity;sid:84565302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250309/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702201/; classtype:trojan-activity;sid:84565301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230517/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702199/; classtype:trojan-activity;sid:84565299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20240113/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702178/; classtype:trojan-activity;sid:84565278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20240113/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702166/; classtype:trojan-activity;sid:84565266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20140730/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702161/; classtype:trojan-activity;sid:84565261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250416/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702156/; classtype:trojan-activity;sid:84565256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230517/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702157/; classtype:trojan-activity;sid:84565257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250309/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702158/; classtype:trojan-activity;sid:84565258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250309/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702152/; classtype:trojan-activity;sid:84565252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230517/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702147/; classtype:trojan-activity;sid:84565247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250309/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702142/; classtype:trojan-activity;sid:84565242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250210/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702143/; classtype:trojan-activity;sid:84565243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250416/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702134/; classtype:trojan-activity;sid:84565234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230517/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702135/; classtype:trojan-activity;sid:84565235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220623/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702136/; classtype:trojan-activity;sid:84565236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220623/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702130/; classtype:trojan-activity;sid:84565230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250416/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702131/; classtype:trojan-activity;sid:84565231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220623/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702132/; classtype:trojan-activity;sid:84565232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20180102/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702127/; classtype:trojan-activity;sid:84565227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20240113/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702128/; classtype:trojan-activity;sid:84565228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220623/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702122/; classtype:trojan-activity;sid:84565222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20240113/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702123/; classtype:trojan-activity;sid:84565223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20180102/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702121/; classtype:trojan-activity;sid:84565221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250210/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702119/; classtype:trojan-activity;sid:84565219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20140730/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702115/; classtype:trojan-activity;sid:84565215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250210/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702105/; classtype:trojan-activity;sid:84565205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20240113/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702102/; classtype:trojan-activity;sid:84565202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220623/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702103/; classtype:trojan-activity;sid:84565203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20180102/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3701934/; classtype:trojan-activity;sid:84565034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20140730/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3701924/; classtype:trojan-activity;sid:84565024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20180102/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3701905/; classtype:trojan-activity;sid:84565005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20180102/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3701906/; classtype:trojan-activity;sid:84565006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"144.2.111.169"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_09; reference:url, urlhaus.abuse.ch/url/3701320/; classtype:trojan-activity;sid:84564420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scoto.jpb"; depth:10; endswith; nocase; http.host; content:"www.jozefinskiatelje.si"; depth:23; isdataat:!1,relative; metadata:created_at 2025_11_09; reference:url, urlhaus.abuse.ch/url/3701203/; classtype:trojan-activity;sid:84564303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"139.196.111.118"; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700663/; classtype:trojan-activity;sid:84563763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"190.196.38.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700329/; classtype:trojan-activity;sid:84563429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"36.158.34.122"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700268/; classtype:trojan-activity;sid:84563368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"190.196.38.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700199/; classtype:trojan-activity;sid:84563299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"36.158.34.122"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700187/; classtype:trojan-activity;sid:84563287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"190.196.38.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700112/; classtype:trojan-activity;sid:84563212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"119.91.141.214"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699967/; classtype:trojan-activity;sid:84563067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"190.196.38.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699839/; classtype:trojan-activity;sid:84562939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"190.196.38.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699768/; classtype:trojan-activity;sid:84562868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"190.196.38.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699651/; classtype:trojan-activity;sid:84562751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"190.196.38.77"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699578/; classtype:trojan-activity;sid:84562678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reprofo.mso"; depth:12; endswith; nocase; http.host; content:"www.jozefinskiatelje.si"; depth:23; isdataat:!1,relative; metadata:created_at 2025_11_07; reference:url, urlhaus.abuse.ch/url/3698699/; classtype:trojan-activity;sid:84561799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250309/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698078/; classtype:trojan-activity;sid:84561178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20140730/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698077/; classtype:trojan-activity;sid:84561177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230517/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698067/; classtype:trojan-activity;sid:84561167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250210/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698070/; classtype:trojan-activity;sid:84561170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250210/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698062/; classtype:trojan-activity;sid:84561162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20140730/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698059/; classtype:trojan-activity;sid:84561159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250309/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698057/; classtype:trojan-activity;sid:84561157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20240113/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698058/; classtype:trojan-activity;sid:84561158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zddtxxyxb.zip"; depth:14; endswith; nocase; http.host; content:"101.35.56.7"; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697910/; classtype:trojan-activity;sid:84561010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i24.bin"; depth:8; endswith; nocase; http.host; content:"101.35.56.7"; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697909/; classtype:trojan-activity;sid:84561009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/husk.zip"; depth:9; endswith; nocase; http.host; content:"101.35.56.7"; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697908/; classtype:trojan-activity;sid:84561008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eznoted2b1405e.zip"; depth:19; endswith; nocase; http.host; content:"101.35.56.7"; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697907/; classtype:trojan-activity;sid:84561007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/without_hook.zip"; depth:17; endswith; nocase; http.host; content:"101.35.56.7"; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697906/; classtype:trojan-activity;sid:84561006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/husk.py"; depth:8; endswith; nocase; http.host; content:"101.35.56.7"; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697870/; classtype:trojan-activity;sid:84560970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"94.76.156.101"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697816/; classtype:trojan-activity;sid:84560916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"36.158.34.122"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697809/; classtype:trojan-activity;sid:84560909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tran.dsp"; depth:9; endswith; nocase; http.host; content:"www.jozefinskiatelje.si"; depth:23; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697791/; classtype:trojan-activity;sid:84560891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aibkp63.bin"; depth:12; endswith; nocase; http.host; content:"www.jozefinskiatelje.si"; depth:23; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697789/; classtype:trojan-activity;sid:84560889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stb/retev.php|3f|bl=qtuvl0pcseglafunszpre008.txt"; depth:49; endswith; nocase; http.host; content:"vcc-library.uk"; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_05; reference:url, urlhaus.abuse.ch/url/3697097/; classtype:trojan-activity;sid:84560197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a1l4m/2e771fb306028fabfc8e098427181f78/raw/37f3db6b29d64f1045fb60967d6297f525ddf443/iamthedanger.txt"; depth:101; endswith; nocase; http.host; content:"gist.githubusercontent.com"; depth:26; isdataat:!1,relative; metadata:created_at 2025_11_05; reference:url, urlhaus.abuse.ch/url/3696992/; classtype:trojan-activity;sid:84560092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"94.76.156.101"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3696082/; classtype:trojan-activity;sid:84559182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"144.2.111.169"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3696043/; classtype:trojan-activity;sid:84559143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"76.94.199.139"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695955/; classtype:trojan-activity;sid:84559055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"76.94.199.139"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695920/; classtype:trojan-activity;sid:84559020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"76.94.199.139"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695884/; classtype:trojan-activity;sid:84558984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"76.94.199.139"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695875/; classtype:trojan-activity;sid:84558975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"117.72.242.9"; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_03; reference:url, urlhaus.abuse.ch/url/3695119/; classtype:trojan-activity;sid:84558219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.86.246.233"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_03; reference:url, urlhaus.abuse.ch/url/3695080/; classtype:trojan-activity;sid:84558180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3693496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"36.92.110.187"; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_01; reference:url, urlhaus.abuse.ch/url/3693496/; classtype:trojan-activity;sid:84556596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3691444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"8.137.149.67"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_30; reference:url, urlhaus.abuse.ch/url/3691444/; classtype:trojan-activity;sid:84554544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3691440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"179.43.186.214"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_30; reference:url, urlhaus.abuse.ch/url/3691440/; classtype:trojan-activity;sid:84554540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3689713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"8.137.149.67"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_28; reference:url, urlhaus.abuse.ch/url/3689713/; classtype:trojan-activity;sid:84552813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3689700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"62.197.62.195"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_28; reference:url, urlhaus.abuse.ch/url/3689700/; classtype:trojan-activity;sid:84552800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmr.exe"; depth:8; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688692/; classtype:trojan-activity;sid:84551792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newtpp.exe"; depth:11; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688690/; classtype:trojan-activity;sid:84551790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1"; depth:2; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688658/; classtype:trojan-activity;sid:84551758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/32.exe"; depth:7; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688659/; classtype:trojan-activity;sid:84551759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2"; depth:2; endswith; nocase; http.host; content:"178.16.54.109"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688660/; classtype:trojan-activity;sid:84551760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3687916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/y6m2uw0dgi.js"; depth:14; endswith; nocase; http.host; content:"filerit.com"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_26; reference:url, urlhaus.abuse.ch/url/3687916/; classtype:trojan-activity;sid:84551016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3687914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4aa9fqc792.ps1"; depth:15; endswith; nocase; http.host; content:"pub-bfc34934a91a4893817098f73415917a.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2025_10_26; reference:url, urlhaus.abuse.ch/url/3687914/; classtype:trojan-activity;sid:84551014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3687753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibll001/ffff/refs/heads/main/web.sh"; depth:37; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_10_26; reference:url, urlhaus.abuse.ch/url/3687753/; classtype:trojan-activity;sid:84550853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3685141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/var/albums/etkinlikler/toplanti/2013/soran.jpg.jpeg"; depth:52; endswith; nocase; http.host; content:"galeri3.arkitera.com"; depth:20; isdataat:!1,relative; metadata:created_at 2025_10_24; reference:url, urlhaus.abuse.ch/url/3685141/; classtype:trojan-activity;sid:84548241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3684907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.90.122.2"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_23; reference:url, urlhaus.abuse.ch/url/3684907/; classtype:trojan-activity;sid:84548007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3683567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/onastroll-2000f5n/5vcye/releases/download/v1.2/launcher.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_10_22; reference:url, urlhaus.abuse.ch/url/3683567/; classtype:trojan-activity;sid:84546667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3683253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/|3f|h=107.173.101.114|7c|26|7c|p=10000|7c|26|7c|t=tcp|7c|26|7c|a=w64|7c|26|7c|stage=true"; depth:89; endswith; nocase; http.host; content:"107.173.101.114"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_21; reference:url, urlhaus.abuse.ch/url/3683253/; classtype:trojan-activity;sid:84546353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3683254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/|3f|h=107.173.101.114|7c|26|7c|p=10000|7c|26|7c|t=tcp|7c|26|7c|a=w32|7c|26|7c|stage=true"; depth:89; endswith; nocase; http.host; content:"107.173.101.114"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_21; reference:url, urlhaus.abuse.ch/url/3683254/; classtype:trojan-activity;sid:84546354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3683250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/swt"; depth:4; endswith; nocase; http.host; content:"107.173.101.114"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_21; reference:url, urlhaus.abuse.ch/url/3683250/; classtype:trojan-activity;sid:84546350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3682316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wheatw.pfm"; depth:11; endswith; nocase; http.host; content:"tehnomag.rs"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_20; reference:url, urlhaus.abuse.ch/url/3682316/; classtype:trojan-activity;sid:84545416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3682317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wheatw.pfm"; depth:11; endswith; nocase; http.host; content:"tehnomag.rs"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_20; reference:url, urlhaus.abuse.ch/url/3682317/; classtype:trojan-activity;sid:84545417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3680322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/x64-setup.exe"; depth:18; endswith; nocase; http.host; content:"tapestryoftruth.com"; depth:19; isdataat:!1,relative; metadata:created_at 2025_10_18; reference:url, urlhaus.abuse.ch/url/3680322/; classtype:trojan-activity;sid:84543422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3678940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prefiction.mp4"; depth:15; endswith; nocase; http.host; content:"www.sgeseducation.com"; depth:21; isdataat:!1,relative; metadata:created_at 2025_10_15; reference:url, urlhaus.abuse.ch/url/3678940/; classtype:trojan-activity;sid:84542040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3677999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"109.25.123.70"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_14; reference:url, urlhaus.abuse.ch/url/3677999/; classtype:trojan-activity;sid:84541099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3677521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/info.zip"; depth:19; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_14; reference:url, urlhaus.abuse.ch/url/3677521/; classtype:trojan-activity;sid:84540621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3677519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gdbftp/info.zip"; depth:16; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_14; reference:url, urlhaus.abuse.ch/url/3677519/; classtype:trojan-activity;sid:84540619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3677518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/info.zip"; depth:16; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_14; reference:url, urlhaus.abuse.ch/url/3677518/; classtype:trojan-activity;sid:84540618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3677463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/relftp/info.zip"; depth:16; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_14; reference:url, urlhaus.abuse.ch/url/3677463/; classtype:trojan-activity;sid:84540563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3677443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/info.zip"; depth:17; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_14; reference:url, urlhaus.abuse.ch/url/3677443/; classtype:trojan-activity;sid:84540543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3668647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.24.0/xmrig-6.24.0-windows-x64.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_10_11; reference:url, urlhaus.abuse.ch/url/3668647/; classtype:trojan-activity;sid:84531747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r-02-radiole/video.scr"; depth:23; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667591/; classtype:trojan-activity;sid:84530691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667589/; classtype:trojan-activity;sid:84530689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r-02-radiole/av.scr"; depth:20; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667586/; classtype:trojan-activity;sid:84530686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667587/; classtype:trojan-activity;sid:84530687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667588/; classtype:trojan-activity;sid:84530688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r-02-radiole/photo.scr"; depth:23; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667585/; classtype:trojan-activity;sid:84530685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667584/; classtype:trojan-activity;sid:84530684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667582/; classtype:trojan-activity;sid:84530682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"132.red-81-42-249.staticip.rima-tde.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667583/; classtype:trojan-activity;sid:84530683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3666095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3666095/; classtype:trojan-activity;sid:84529195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"87.227.140.66"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665807/; classtype:trojan-activity;sid:84528907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"87.227.140.66"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665805/; classtype:trojan-activity;sid:84528905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"94.76.156.101"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665802/; classtype:trojan-activity;sid:84528902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"94.76.156.101"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665803/; classtype:trojan-activity;sid:84528903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"75.144.208.234"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665796/; classtype:trojan-activity;sid:84528896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"75.144.208.234"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665788/; classtype:trojan-activity;sid:84528888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"75.144.208.234"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665779/; classtype:trojan-activity;sid:84528879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"87.227.140.66"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665767/; classtype:trojan-activity;sid:84528867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"102.53.15.17"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665747/; classtype:trojan-activity;sid:84528847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"195.103.203.106"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665742/; classtype:trojan-activity;sid:84528842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"5.26.174.234"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665733/; classtype:trojan-activity;sid:84528833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"126.23.203.236"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665715/; classtype:trojan-activity;sid:84528815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"130.185.193.208"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665712/; classtype:trojan-activity;sid:84528812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"81.133.96.61"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665709/; classtype:trojan-activity;sid:84528809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"130.185.193.208"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665699/; classtype:trojan-activity;sid:84528799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"155.2.213.252"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665692/; classtype:trojan-activity;sid:84528792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"81.133.96.61"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665677/; classtype:trojan-activity;sid:84528777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"155.2.213.252"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665674/; classtype:trojan-activity;sid:84528774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"61.160.215.114"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665671/; classtype:trojan-activity;sid:84528771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"87.227.140.66"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665669/; classtype:trojan-activity;sid:84528769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"130.185.193.208"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665656/; classtype:trojan-activity;sid:84528756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"87.227.140.66"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665611/; classtype:trojan-activity;sid:84528711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"81.133.96.61"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665613/; classtype:trojan-activity;sid:84528713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3662805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asmroyal/cd4/releases/download/cd4/cd4.exe"; depth:43; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_10_07; reference:url, urlhaus.abuse.ch/url/3662805/; classtype:trojan-activity;sid:84525905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3661435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1afutsiefohaia02gkfjdbgn-kk91hksb"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_10_07; reference:url, urlhaus.abuse.ch/url/3661435/; classtype:trojan-activity;sid:84524535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250302/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660738/; classtype:trojan-activity;sid:84523838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250708/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660696/; classtype:trojan-activity;sid:84523796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250408/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660690/; classtype:trojan-activity;sid:84523790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250724/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660688/; classtype:trojan-activity;sid:84523788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20221020/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660680/; classtype:trojan-activity;sid:84523780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250408/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660679/; classtype:trojan-activity;sid:84523779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250302/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660677/; classtype:trojan-activity;sid:84523777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250408/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660676/; classtype:trojan-activity;sid:84523776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19000101/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660675/; classtype:trojan-activity;sid:84523775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250721/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660674/; classtype:trojan-activity;sid:84523774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250302/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660672/; classtype:trojan-activity;sid:84523772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250724/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660671/; classtype:trojan-activity;sid:84523771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660670/; classtype:trojan-activity;sid:84523770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660668/; classtype:trojan-activity;sid:84523768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250721/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660669/; classtype:trojan-activity;sid:84523769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250621/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660665/; classtype:trojan-activity;sid:84523765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210118/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660666/; classtype:trojan-activity;sid:84523766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250726/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660663/; classtype:trojan-activity;sid:84523763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250703/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660664/; classtype:trojan-activity;sid:84523764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250708/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660660/; classtype:trojan-activity;sid:84523760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660659/; classtype:trojan-activity;sid:84523759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250713/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660657/; classtype:trojan-activity;sid:84523757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250621/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660658/; classtype:trojan-activity;sid:84523758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660655/; classtype:trojan-activity;sid:84523755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250726/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660656/; classtype:trojan-activity;sid:84523756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250713/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660654/; classtype:trojan-activity;sid:84523754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220801/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660652/; classtype:trojan-activity;sid:84523752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250708/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660653/; classtype:trojan-activity;sid:84523753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250302/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660647/; classtype:trojan-activity;sid:84523747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250726/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660648/; classtype:trojan-activity;sid:84523748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250621/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660649/; classtype:trojan-activity;sid:84523749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r-02-radiole/av.scr"; depth:20; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660644/; classtype:trojan-activity;sid:84523744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r-02-radiole/photo.scr"; depth:23; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660642/; classtype:trojan-activity;sid:84523742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220801/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660641/; classtype:trojan-activity;sid:84523741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250703/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660640/; classtype:trojan-activity;sid:84523740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220801/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660639/; classtype:trojan-activity;sid:84523739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220801/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660638/; classtype:trojan-activity;sid:84523738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660637/; classtype:trojan-activity;sid:84523737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220801/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660636/; classtype:trojan-activity;sid:84523736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250722/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660635/; classtype:trojan-activity;sid:84523735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250703/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660634/; classtype:trojan-activity;sid:84523734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250615/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660633/; classtype:trojan-activity;sid:84523733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250708/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660631/; classtype:trojan-activity;sid:84523731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250615/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660630/; classtype:trojan-activity;sid:84523730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250302/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660629/; classtype:trojan-activity;sid:84523729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230507/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660627/; classtype:trojan-activity;sid:84523727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230507/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660626/; classtype:trojan-activity;sid:84523726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210118/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660625/; classtype:trojan-activity;sid:84523725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250724/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660624/; classtype:trojan-activity;sid:84523724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230507/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660622/; classtype:trojan-activity;sid:84523722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250722/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660623/; classtype:trojan-activity;sid:84523723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250703/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660621/; classtype:trojan-activity;sid:84523721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250721/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660620/; classtype:trojan-activity;sid:84523720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250615/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660619/; classtype:trojan-activity;sid:84523719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250408/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660618/; classtype:trojan-activity;sid:84523718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250621/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660615/; classtype:trojan-activity;sid:84523715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250724/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660616/; classtype:trojan-activity;sid:84523716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250713/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660614/; classtype:trojan-activity;sid:84523714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250721/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660612/; classtype:trojan-activity;sid:84523712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250722/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660613/; classtype:trojan-activity;sid:84523713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250725/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660611/; classtype:trojan-activity;sid:84523711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20221020/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660608/; classtype:trojan-activity;sid:84523708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250725/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660607/; classtype:trojan-activity;sid:84523707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250708/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660605/; classtype:trojan-activity;sid:84523705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660603/; classtype:trojan-activity;sid:84523703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250725/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660600/; classtype:trojan-activity;sid:84523700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250302/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660599/; classtype:trojan-activity;sid:84523699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20220801/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660598/; classtype:trojan-activity;sid:84523698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250615/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660596/; classtype:trojan-activity;sid:84523696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210118/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660595/; classtype:trojan-activity;sid:84523695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210118/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660594/; classtype:trojan-activity;sid:84523694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250621/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660592/; classtype:trojan-activity;sid:84523692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250726/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660593/; classtype:trojan-activity;sid:84523693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20221020/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660590/; classtype:trojan-activity;sid:84523690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230507/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660591/; classtype:trojan-activity;sid:84523691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250703/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660587/; classtype:trojan-activity;sid:84523687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250615/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660588/; classtype:trojan-activity;sid:84523688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250408/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660589/; classtype:trojan-activity;sid:84523689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250713/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660585/; classtype:trojan-activity;sid:84523685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250725/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660583/; classtype:trojan-activity;sid:84523683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250726/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660584/; classtype:trojan-activity;sid:84523684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250726/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660581/; classtype:trojan-activity;sid:84523681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20221020/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660582/; classtype:trojan-activity;sid:84523682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r-02-radiole/video.scr"; depth:23; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660579/; classtype:trojan-activity;sid:84523679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20221020/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660580/; classtype:trojan-activity;sid:84523680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210118/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660577/; classtype:trojan-activity;sid:84523677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250703/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660575/; classtype:trojan-activity;sid:84523675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20210118/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660576/; classtype:trojan-activity;sid:84523676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250724/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660573/; classtype:trojan-activity;sid:84523673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250724/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660574/; classtype:trojan-activity;sid:84523674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250615/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660571/; classtype:trojan-activity;sid:84523671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250725/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660569/; classtype:trojan-activity;sid:84523669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250621/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660570/; classtype:trojan-activity;sid:84523670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250725/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660568/; classtype:trojan-activity;sid:84523668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230507/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660563/; classtype:trojan-activity;sid:84523663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250721/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660564/; classtype:trojan-activity;sid:84523664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20221020/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660566/; classtype:trojan-activity;sid:84523666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250713/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660559/; classtype:trojan-activity;sid:84523659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250721/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660560/; classtype:trojan-activity;sid:84523660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250708/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660561/; classtype:trojan-activity;sid:84523661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20230507/photo.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660558/; classtype:trojan-activity;sid:84523658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250722/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660552/; classtype:trojan-activity;sid:84523652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250722/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660553/; classtype:trojan-activity;sid:84523653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250713/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660554/; classtype:trojan-activity;sid:84523654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250722/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660555/; classtype:trojan-activity;sid:84523655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20250408/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660556/; classtype:trojan-activity;sid:84523656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sxs/info.zip"; depth:13; endswith; nocase; http.host; content:"110.227.197.204"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660537/; classtype:trojan-activity;sid:84523637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"188.246.178.42"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660487/; classtype:trojan-activity;sid:84523587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660332/; classtype:trojan-activity;sid:84523432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660331/; classtype:trojan-activity;sid:84523431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660329/; classtype:trojan-activity;sid:84523429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660330/; classtype:trojan-activity;sid:84523430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660328/; classtype:trojan-activity;sid:84523428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"81.42.249.132"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660327/; classtype:trojan-activity;sid:84523427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"46.77.52.190"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659836/; classtype:trojan-activity;sid:84522936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"46.77.52.190"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659834/; classtype:trojan-activity;sid:84522934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"46.77.52.190"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659833/; classtype:trojan-activity;sid:84522933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"93.82.169.218"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659796/; classtype:trojan-activity;sid:84522896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"93.82.169.218"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659797/; classtype:trojan-activity;sid:84522897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"46.77.52.190"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659779/; classtype:trojan-activity;sid:84522879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"46.77.52.190"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659782/; classtype:trojan-activity;sid:84522882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-31/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659470/; classtype:trojan-activity;sid:84522570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659469/; classtype:trojan-activity;sid:84522569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-31/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659468/; classtype:trojan-activity;sid:84522568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659466/; classtype:trojan-activity;sid:84522566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659467/; classtype:trojan-activity;sid:84522567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-09-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659464/; classtype:trojan-activity;sid:84522564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659465/; classtype:trojan-activity;sid:84522565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659460/; classtype:trojan-activity;sid:84522560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659461/; classtype:trojan-activity;sid:84522561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-03-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659462/; classtype:trojan-activity;sid:84522562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659454/; classtype:trojan-activity;sid:84522554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-03-11/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659455/; classtype:trojan-activity;sid:84522555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659456/; classtype:trojan-activity;sid:84522556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659457/; classtype:trojan-activity;sid:84522557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-07-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659458/; classtype:trojan-activity;sid:84522558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659459/; classtype:trojan-activity;sid:84522559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659449/; classtype:trojan-activity;sid:84522549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659450/; classtype:trojan-activity;sid:84522550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659451/; classtype:trojan-activity;sid:84522551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-12-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659452/; classtype:trojan-activity;sid:84522552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-04-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659453/; classtype:trojan-activity;sid:84522553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659444/; classtype:trojan-activity;sid:84522544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659445/; classtype:trojan-activity;sid:84522545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659446/; classtype:trojan-activity;sid:84522546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659447/; classtype:trojan-activity;sid:84522547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-07-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659448/; classtype:trojan-activity;sid:84522548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659440/; classtype:trojan-activity;sid:84522540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659441/; classtype:trojan-activity;sid:84522541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659442/; classtype:trojan-activity;sid:84522542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659443/; classtype:trojan-activity;sid:84522543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659437/; classtype:trojan-activity;sid:84522537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-02-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659438/; classtype:trojan-activity;sid:84522538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-09-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659439/; classtype:trojan-activity;sid:84522539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-11-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659435/; classtype:trojan-activity;sid:84522535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659436/; classtype:trojan-activity;sid:84522536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659432/; classtype:trojan-activity;sid:84522532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659433/; classtype:trojan-activity;sid:84522533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659434/; classtype:trojan-activity;sid:84522534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659429/; classtype:trojan-activity;sid:84522529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659430/; classtype:trojan-activity;sid:84522530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659431/; classtype:trojan-activity;sid:84522531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-09-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659428/; classtype:trojan-activity;sid:84522528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659425/; classtype:trojan-activity;sid:84522525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659426/; classtype:trojan-activity;sid:84522526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659427/; classtype:trojan-activity;sid:84522527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-11-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659424/; classtype:trojan-activity;sid:84522524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-07-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659420/; classtype:trojan-activity;sid:84522520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659421/; classtype:trojan-activity;sid:84522521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659422/; classtype:trojan-activity;sid:84522522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659423/; classtype:trojan-activity;sid:84522523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659416/; classtype:trojan-activity;sid:84522516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659417/; classtype:trojan-activity;sid:84522517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659418/; classtype:trojan-activity;sid:84522518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659415/; classtype:trojan-activity;sid:84522515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-06-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659413/; classtype:trojan-activity;sid:84522513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-01-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659414/; classtype:trojan-activity;sid:84522514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-12-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659412/; classtype:trojan-activity;sid:84522512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659406/; classtype:trojan-activity;sid:84522506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659407/; classtype:trojan-activity;sid:84522507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-09-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659408/; classtype:trojan-activity;sid:84522508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659409/; classtype:trojan-activity;sid:84522509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659403/; classtype:trojan-activity;sid:84522503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-04-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659404/; classtype:trojan-activity;sid:84522504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659405/; classtype:trojan-activity;sid:84522505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659402/; classtype:trojan-activity;sid:84522502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659399/; classtype:trojan-activity;sid:84522499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-11-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659400/; classtype:trojan-activity;sid:84522500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-02-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659401/; classtype:trojan-activity;sid:84522501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659393/; classtype:trojan-activity;sid:84522493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-08-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659394/; classtype:trojan-activity;sid:84522494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659395/; classtype:trojan-activity;sid:84522495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-04-07/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659396/; classtype:trojan-activity;sid:84522496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659397/; classtype:trojan-activity;sid:84522497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-08-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659391/; classtype:trojan-activity;sid:84522491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659392/; classtype:trojan-activity;sid:84522492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659389/; classtype:trojan-activity;sid:84522489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659390/; classtype:trojan-activity;sid:84522490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659388/; classtype:trojan-activity;sid:84522488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-10-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659384/; classtype:trojan-activity;sid:84522484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659385/; classtype:trojan-activity;sid:84522485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-12-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659386/; classtype:trojan-activity;sid:84522486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659387/; classtype:trojan-activity;sid:84522487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659376/; classtype:trojan-activity;sid:84522476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659377/; classtype:trojan-activity;sid:84522477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659378/; classtype:trojan-activity;sid:84522478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659379/; classtype:trojan-activity;sid:84522479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-11-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659380/; classtype:trojan-activity;sid:84522480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-01-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659381/; classtype:trojan-activity;sid:84522481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659382/; classtype:trojan-activity;sid:84522482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-03-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659383/; classtype:trojan-activity;sid:84522483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659369/; classtype:trojan-activity;sid:84522469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-10-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659370/; classtype:trojan-activity;sid:84522470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659371/; classtype:trojan-activity;sid:84522471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659372/; classtype:trojan-activity;sid:84522472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-08-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659373/; classtype:trojan-activity;sid:84522473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659374/; classtype:trojan-activity;sid:84522474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-09-29/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659375/; classtype:trojan-activity;sid:84522475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659366/; classtype:trojan-activity;sid:84522466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659367/; classtype:trojan-activity;sid:84522467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659365/; classtype:trojan-activity;sid:84522465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-11-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659364/; classtype:trojan-activity;sid:84522464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659362/; classtype:trojan-activity;sid:84522462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659361/; classtype:trojan-activity;sid:84522461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659360/; classtype:trojan-activity;sid:84522460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659358/; classtype:trojan-activity;sid:84522458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-11-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659359/; classtype:trojan-activity;sid:84522459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-04-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659355/; classtype:trojan-activity;sid:84522455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659356/; classtype:trojan-activity;sid:84522456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659357/; classtype:trojan-activity;sid:84522457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659354/; classtype:trojan-activity;sid:84522454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-12-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659353/; classtype:trojan-activity;sid:84522453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-01-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659347/; classtype:trojan-activity;sid:84522447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659348/; classtype:trojan-activity;sid:84522448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659349/; classtype:trojan-activity;sid:84522449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-05-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659350/; classtype:trojan-activity;sid:84522450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659351/; classtype:trojan-activity;sid:84522451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-14/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659352/; classtype:trojan-activity;sid:84522452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-08-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659341/; classtype:trojan-activity;sid:84522441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-08-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659342/; classtype:trojan-activity;sid:84522442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659343/; classtype:trojan-activity;sid:84522443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659344/; classtype:trojan-activity;sid:84522444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659345/; classtype:trojan-activity;sid:84522445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-01-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659346/; classtype:trojan-activity;sid:84522446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659340/; classtype:trojan-activity;sid:84522440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659339/; classtype:trojan-activity;sid:84522439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659337/; classtype:trojan-activity;sid:84522437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659338/; classtype:trojan-activity;sid:84522438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659329/; classtype:trojan-activity;sid:84522429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659330/; classtype:trojan-activity;sid:84522430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-03-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659331/; classtype:trojan-activity;sid:84522431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-02-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659332/; classtype:trojan-activity;sid:84522432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659333/; classtype:trojan-activity;sid:84522433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-10-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659334/; classtype:trojan-activity;sid:84522434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659335/; classtype:trojan-activity;sid:84522435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-10-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659336/; classtype:trojan-activity;sid:84522436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659326/; classtype:trojan-activity;sid:84522426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659327/; classtype:trojan-activity;sid:84522427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659328/; classtype:trojan-activity;sid:84522428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659324/; classtype:trojan-activity;sid:84522424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659325/; classtype:trojan-activity;sid:84522425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659321/; classtype:trojan-activity;sid:84522421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-03-18/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659322/; classtype:trojan-activity;sid:84522422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659323/; classtype:trojan-activity;sid:84522423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-09-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659319/; classtype:trojan-activity;sid:84522419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-09-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659320/; classtype:trojan-activity;sid:84522420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659317/; classtype:trojan-activity;sid:84522417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-03-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659318/; classtype:trojan-activity;sid:84522418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659310/; classtype:trojan-activity;sid:84522410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-12-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659311/; classtype:trojan-activity;sid:84522411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659312/; classtype:trojan-activity;sid:84522412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-07-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659314/; classtype:trojan-activity;sid:84522414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-02-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659315/; classtype:trojan-activity;sid:84522415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-09-29/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659316/; classtype:trojan-activity;sid:84522416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659308/; classtype:trojan-activity;sid:84522408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-01-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659309/; classtype:trojan-activity;sid:84522409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659305/; classtype:trojan-activity;sid:84522405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659306/; classtype:trojan-activity;sid:84522406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659307/; classtype:trojan-activity;sid:84522407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659302/; classtype:trojan-activity;sid:84522402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-04-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659303/; classtype:trojan-activity;sid:84522403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659304/; classtype:trojan-activity;sid:84522404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-12-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659301/; classtype:trojan-activity;sid:84522401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659300/; classtype:trojan-activity;sid:84522400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659297/; classtype:trojan-activity;sid:84522397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659298/; classtype:trojan-activity;sid:84522398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-03-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659299/; classtype:trojan-activity;sid:84522399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-03-29/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659292/; classtype:trojan-activity;sid:84522392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659293/; classtype:trojan-activity;sid:84522393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659294/; classtype:trojan-activity;sid:84522394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-01-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659295/; classtype:trojan-activity;sid:84522395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-09-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659291/; classtype:trojan-activity;sid:84522391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-01-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659283/; classtype:trojan-activity;sid:84522383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659284/; classtype:trojan-activity;sid:84522384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-09-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659285/; classtype:trojan-activity;sid:84522385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659286/; classtype:trojan-activity;sid:84522386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-09-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659287/; classtype:trojan-activity;sid:84522387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-06-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659288/; classtype:trojan-activity;sid:84522388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659290/; classtype:trojan-activity;sid:84522390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659279/; classtype:trojan-activity;sid:84522379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659280/; classtype:trojan-activity;sid:84522380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659281/; classtype:trojan-activity;sid:84522381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-10-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659282/; classtype:trojan-activity;sid:84522382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659275/; classtype:trojan-activity;sid:84522375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659276/; classtype:trojan-activity;sid:84522376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659277/; classtype:trojan-activity;sid:84522377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-05-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659274/; classtype:trojan-activity;sid:84522374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659270/; classtype:trojan-activity;sid:84522370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-07-07/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659271/; classtype:trojan-activity;sid:84522371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659273/; classtype:trojan-activity;sid:84522373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659265/; classtype:trojan-activity;sid:84522365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659266/; classtype:trojan-activity;sid:84522366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659267/; classtype:trojan-activity;sid:84522367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659269/; classtype:trojan-activity;sid:84522369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659262/; classtype:trojan-activity;sid:84522362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-11-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659263/; classtype:trojan-activity;sid:84522363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-08-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659264/; classtype:trojan-activity;sid:84522364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659260/; classtype:trojan-activity;sid:84522360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659261/; classtype:trojan-activity;sid:84522361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-02-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659259/; classtype:trojan-activity;sid:84522359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-11-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659258/; classtype:trojan-activity;sid:84522358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659256/; classtype:trojan-activity;sid:84522356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659257/; classtype:trojan-activity;sid:84522357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659255/; classtype:trojan-activity;sid:84522355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-03-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659248/; classtype:trojan-activity;sid:84522348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659249/; classtype:trojan-activity;sid:84522349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-01-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659250/; classtype:trojan-activity;sid:84522350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659252/; classtype:trojan-activity;sid:84522352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-04-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659253/; classtype:trojan-activity;sid:84522353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-08-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659246/; classtype:trojan-activity;sid:84522346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659247/; classtype:trojan-activity;sid:84522347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659243/; classtype:trojan-activity;sid:84522343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659244/; classtype:trojan-activity;sid:84522344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-01-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659245/; classtype:trojan-activity;sid:84522345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659242/; classtype:trojan-activity;sid:84522342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-06-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659240/; classtype:trojan-activity;sid:84522340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-03-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659241/; classtype:trojan-activity;sid:84522341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659238/; classtype:trojan-activity;sid:84522338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659239/; classtype:trojan-activity;sid:84522339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659235/; classtype:trojan-activity;sid:84522335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-08-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659236/; classtype:trojan-activity;sid:84522336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659237/; classtype:trojan-activity;sid:84522337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-03-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659233/; classtype:trojan-activity;sid:84522333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-11-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659234/; classtype:trojan-activity;sid:84522334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659228/; classtype:trojan-activity;sid:84522328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659229/; classtype:trojan-activity;sid:84522329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659230/; classtype:trojan-activity;sid:84522330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659231/; classtype:trojan-activity;sid:84522331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659226/; classtype:trojan-activity;sid:84522326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659225/; classtype:trojan-activity;sid:84522325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-11-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659223/; classtype:trojan-activity;sid:84522323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659224/; classtype:trojan-activity;sid:84522324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659221/; classtype:trojan-activity;sid:84522321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659219/; classtype:trojan-activity;sid:84522319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-06-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659220/; classtype:trojan-activity;sid:84522320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659216/; classtype:trojan-activity;sid:84522316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-01-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659218/; classtype:trojan-activity;sid:84522318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659212/; classtype:trojan-activity;sid:84522312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-11-08/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659213/; classtype:trojan-activity;sid:84522313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659214/; classtype:trojan-activity;sid:84522314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659215/; classtype:trojan-activity;sid:84522315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659207/; classtype:trojan-activity;sid:84522307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659208/; classtype:trojan-activity;sid:84522308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659209/; classtype:trojan-activity;sid:84522309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-02-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659210/; classtype:trojan-activity;sid:84522310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659211/; classtype:trojan-activity;sid:84522311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659205/; classtype:trojan-activity;sid:84522305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659206/; classtype:trojan-activity;sid:84522306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659203/; classtype:trojan-activity;sid:84522303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659204/; classtype:trojan-activity;sid:84522304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-07-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659202/; classtype:trojan-activity;sid:84522302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-01-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659200/; classtype:trojan-activity;sid:84522300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659201/; classtype:trojan-activity;sid:84522301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659198/; classtype:trojan-activity;sid:84522298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659199/; classtype:trojan-activity;sid:84522299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659194/; classtype:trojan-activity;sid:84522294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659195/; classtype:trojan-activity;sid:84522295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659196/; classtype:trojan-activity;sid:84522296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659191/; classtype:trojan-activity;sid:84522291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-10-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659192/; classtype:trojan-activity;sid:84522292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659193/; classtype:trojan-activity;sid:84522293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659190/; classtype:trojan-activity;sid:84522290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659189/; classtype:trojan-activity;sid:84522289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659180/; classtype:trojan-activity;sid:84522280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-03-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659181/; classtype:trojan-activity;sid:84522281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659182/; classtype:trojan-activity;sid:84522282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-10-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659183/; classtype:trojan-activity;sid:84522283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659184/; classtype:trojan-activity;sid:84522284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659185/; classtype:trojan-activity;sid:84522285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659186/; classtype:trojan-activity;sid:84522286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-06-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659187/; classtype:trojan-activity;sid:84522287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659188/; classtype:trojan-activity;sid:84522288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659178/; classtype:trojan-activity;sid:84522278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659179/; classtype:trojan-activity;sid:84522279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659177/; classtype:trojan-activity;sid:84522277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659176/; classtype:trojan-activity;sid:84522276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-04-24/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659172/; classtype:trojan-activity;sid:84522272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659173/; classtype:trojan-activity;sid:84522273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-01-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659174/; classtype:trojan-activity;sid:84522274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659175/; classtype:trojan-activity;sid:84522275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659170/; classtype:trojan-activity;sid:84522270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659169/; classtype:trojan-activity;sid:84522269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659168/; classtype:trojan-activity;sid:84522268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659167/; classtype:trojan-activity;sid:84522267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659164/; classtype:trojan-activity;sid:84522264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-01-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659165/; classtype:trojan-activity;sid:84522265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-01-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659166/; classtype:trojan-activity;sid:84522266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659159/; classtype:trojan-activity;sid:84522259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-09-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659160/; classtype:trojan-activity;sid:84522260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659161/; classtype:trojan-activity;sid:84522261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659162/; classtype:trojan-activity;sid:84522262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659163/; classtype:trojan-activity;sid:84522263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659156/; classtype:trojan-activity;sid:84522256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659157/; classtype:trojan-activity;sid:84522257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-01-31/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659158/; classtype:trojan-activity;sid:84522258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659153/; classtype:trojan-activity;sid:84522253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659154/; classtype:trojan-activity;sid:84522254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659155/; classtype:trojan-activity;sid:84522255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659150/; classtype:trojan-activity;sid:84522250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659152/; classtype:trojan-activity;sid:84522252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659145/; classtype:trojan-activity;sid:84522245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659146/; classtype:trojan-activity;sid:84522246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659147/; classtype:trojan-activity;sid:84522247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-07-05/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659148/; classtype:trojan-activity;sid:84522248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-04-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659149/; classtype:trojan-activity;sid:84522249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659141/; classtype:trojan-activity;sid:84522241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659142/; classtype:trojan-activity;sid:84522242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-02-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659143/; classtype:trojan-activity;sid:84522243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-04-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659144/; classtype:trojan-activity;sid:84522244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-09-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659138/; classtype:trojan-activity;sid:84522238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659139/; classtype:trojan-activity;sid:84522239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659140/; classtype:trojan-activity;sid:84522240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659137/; classtype:trojan-activity;sid:84522237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659134/; classtype:trojan-activity;sid:84522234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-12-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659135/; classtype:trojan-activity;sid:84522235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659136/; classtype:trojan-activity;sid:84522236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-11-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659131/; classtype:trojan-activity;sid:84522231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659132/; classtype:trojan-activity;sid:84522232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-07-06/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659130/; classtype:trojan-activity;sid:84522230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659126/; classtype:trojan-activity;sid:84522226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659127/; classtype:trojan-activity;sid:84522227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659128/; classtype:trojan-activity;sid:84522228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-11-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659129/; classtype:trojan-activity;sid:84522229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659124/; classtype:trojan-activity;sid:84522224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659125/; classtype:trojan-activity;sid:84522225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659121/; classtype:trojan-activity;sid:84522221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659122/; classtype:trojan-activity;sid:84522222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-10-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659123/; classtype:trojan-activity;sid:84522223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659118/; classtype:trojan-activity;sid:84522218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659119/; classtype:trojan-activity;sid:84522219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659117/; classtype:trojan-activity;sid:84522217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659115/; classtype:trojan-activity;sid:84522215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-05-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659116/; classtype:trojan-activity;sid:84522216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659114/; classtype:trojan-activity;sid:84522214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659111/; classtype:trojan-activity;sid:84522211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659112/; classtype:trojan-activity;sid:84522212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-01-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659113/; classtype:trojan-activity;sid:84522213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659107/; classtype:trojan-activity;sid:84522207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659108/; classtype:trojan-activity;sid:84522208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-07-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659109/; classtype:trojan-activity;sid:84522209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-12-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659110/; classtype:trojan-activity;sid:84522210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659105/; classtype:trojan-activity;sid:84522205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659106/; classtype:trojan-activity;sid:84522206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-11-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659103/; classtype:trojan-activity;sid:84522203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659104/; classtype:trojan-activity;sid:84522204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659102/; classtype:trojan-activity;sid:84522202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659101/; classtype:trojan-activity;sid:84522201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659099/; classtype:trojan-activity;sid:84522199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-04-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659100/; classtype:trojan-activity;sid:84522200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659097/; classtype:trojan-activity;sid:84522197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659098/; classtype:trojan-activity;sid:84522198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659087/; classtype:trojan-activity;sid:84522187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659088/; classtype:trojan-activity;sid:84522188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-09-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659089/; classtype:trojan-activity;sid:84522189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-12-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659090/; classtype:trojan-activity;sid:84522190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659091/; classtype:trojan-activity;sid:84522191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-05-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659092/; classtype:trojan-activity;sid:84522192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659093/; classtype:trojan-activity;sid:84522193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659094/; classtype:trojan-activity;sid:84522194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-09-26/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659095/; classtype:trojan-activity;sid:84522195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-07-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659096/; classtype:trojan-activity;sid:84522196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659084/; classtype:trojan-activity;sid:84522184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659085/; classtype:trojan-activity;sid:84522185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659086/; classtype:trojan-activity;sid:84522186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659083/; classtype:trojan-activity;sid:84522183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659077/; classtype:trojan-activity;sid:84522177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659079/; classtype:trojan-activity;sid:84522179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-05-27/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659080/; classtype:trojan-activity;sid:84522180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659081/; classtype:trojan-activity;sid:84522181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659075/; classtype:trojan-activity;sid:84522175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-02-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659073/; classtype:trojan-activity;sid:84522173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-01-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659074/; classtype:trojan-activity;sid:84522174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659069/; classtype:trojan-activity;sid:84522169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659070/; classtype:trojan-activity;sid:84522170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659071/; classtype:trojan-activity;sid:84522171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659072/; classtype:trojan-activity;sid:84522172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-04-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659068/; classtype:trojan-activity;sid:84522168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659067/; classtype:trojan-activity;sid:84522167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659062/; classtype:trojan-activity;sid:84522162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659063/; classtype:trojan-activity;sid:84522163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659064/; classtype:trojan-activity;sid:84522164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-07-06/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659065/; classtype:trojan-activity;sid:84522165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-09-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659056/; classtype:trojan-activity;sid:84522156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659057/; classtype:trojan-activity;sid:84522157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659058/; classtype:trojan-activity;sid:84522158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659059/; classtype:trojan-activity;sid:84522159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-02-24/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659060/; classtype:trojan-activity;sid:84522160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659061/; classtype:trojan-activity;sid:84522161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-01-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659049/; classtype:trojan-activity;sid:84522149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-09-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659050/; classtype:trojan-activity;sid:84522150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659051/; classtype:trojan-activity;sid:84522151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-04-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659052/; classtype:trojan-activity;sid:84522152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659053/; classtype:trojan-activity;sid:84522153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659054/; classtype:trojan-activity;sid:84522154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659055/; classtype:trojan-activity;sid:84522155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659047/; classtype:trojan-activity;sid:84522147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-01-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659048/; classtype:trojan-activity;sid:84522148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659043/; classtype:trojan-activity;sid:84522143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659044/; classtype:trojan-activity;sid:84522144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659045/; classtype:trojan-activity;sid:84522145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-06-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659046/; classtype:trojan-activity;sid:84522146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659040/; classtype:trojan-activity;sid:84522140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659041/; classtype:trojan-activity;sid:84522141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659042/; classtype:trojan-activity;sid:84522142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659038/; classtype:trojan-activity;sid:84522138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-11-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659039/; classtype:trojan-activity;sid:84522139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659037/; classtype:trojan-activity;sid:84522137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-07-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659006/; classtype:trojan-activity;sid:84522106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658999/; classtype:trojan-activity;sid:84522099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-12-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3659003/; classtype:trojan-activity;sid:84522103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-12-19/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658996/; classtype:trojan-activity;sid:84522096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-09-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658992/; classtype:trojan-activity;sid:84522092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658989/; classtype:trojan-activity;sid:84522089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-06-04/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658983/; classtype:trojan-activity;sid:84522083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-04-14/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658981/; classtype:trojan-activity;sid:84522081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658975/; classtype:trojan-activity;sid:84522075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658976/; classtype:trojan-activity;sid:84522076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-31/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658972/; classtype:trojan-activity;sid:84522072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2025-01-09/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658970/; classtype:trojan-activity;sid:84522070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658967/; classtype:trojan-activity;sid:84522067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000721/2019-10-25/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658962/; classtype:trojan-activity;sid:84522062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-09-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658961/; classtype:trojan-activity;sid:84522061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-06-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658960/; classtype:trojan-activity;sid:84522060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-03-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658959/; classtype:trojan-activity;sid:84522059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000721/2020-09-25/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658957/; classtype:trojan-activity;sid:84522057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000136/2021-11-03/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658954/; classtype:trojan-activity;sid:84522054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658948/; classtype:trojan-activity;sid:84522048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658945/; classtype:trojan-activity;sid:84522045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-04-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658946/; classtype:trojan-activity;sid:84522046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658940/; classtype:trojan-activity;sid:84522040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-01-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658933/; classtype:trojan-activity;sid:84522033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658928/; classtype:trojan-activity;sid:84522028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-12-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658925/; classtype:trojan-activity;sid:84522025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658920/; classtype:trojan-activity;sid:84522020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-07-29/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658918/; classtype:trojan-activity;sid:84522018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-01-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658919/; classtype:trojan-activity;sid:84522019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658916/; classtype:trojan-activity;sid:84522016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-04-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658907/; classtype:trojan-activity;sid:84522007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658908/; classtype:trojan-activity;sid:84522008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-03-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658911/; classtype:trojan-activity;sid:84522011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-06-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658912/; classtype:trojan-activity;sid:84522012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-07-30/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658903/; classtype:trojan-activity;sid:84522003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-01-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658898/; classtype:trojan-activity;sid:84521998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-08-03/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658899/; classtype:trojan-activity;sid:84521999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658901/; classtype:trojan-activity;sid:84522001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-06-18/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658891/; classtype:trojan-activity;sid:84521991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-05-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658889/; classtype:trojan-activity;sid:84521989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658888/; classtype:trojan-activity;sid:84521988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658879/; classtype:trojan-activity;sid:84521979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-05-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658871/; classtype:trojan-activity;sid:84521971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-08-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658869/; classtype:trojan-activity;sid:84521969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-02-08/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658860/; classtype:trojan-activity;sid:84521960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-09-15/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658858/; classtype:trojan-activity;sid:84521958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-05-22/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658850/; classtype:trojan-activity;sid:84521950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-11-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658849/; classtype:trojan-activity;sid:84521949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658848/; classtype:trojan-activity;sid:84521948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-09-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658846/; classtype:trojan-activity;sid:84521946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658844/; classtype:trojan-activity;sid:84521944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-31/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658842/; classtype:trojan-activity;sid:84521942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658843/; classtype:trojan-activity;sid:84521943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-07-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658837/; classtype:trojan-activity;sid:84521937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658838/; classtype:trojan-activity;sid:84521938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658840/; classtype:trojan-activity;sid:84521940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-08-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658833/; classtype:trojan-activity;sid:84521933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658834/; classtype:trojan-activity;sid:84521934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-12-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658822/; classtype:trojan-activity;sid:84521922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-10-31/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658823/; classtype:trojan-activity;sid:84521923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-07-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658815/; classtype:trojan-activity;sid:84521915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-08-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658818/; classtype:trojan-activity;sid:84521918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658809/; classtype:trojan-activity;sid:84521909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-08-05/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658812/; classtype:trojan-activity;sid:84521912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-07-30/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658804/; classtype:trojan-activity;sid:84521904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-06-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658799/; classtype:trojan-activity;sid:84521899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658800/; classtype:trojan-activity;sid:84521900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-04-02/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658794/; classtype:trojan-activity;sid:84521894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-09-02/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658795/; classtype:trojan-activity;sid:84521895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658786/; classtype:trojan-activity;sid:84521886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-01-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658787/; classtype:trojan-activity;sid:84521887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658788/; classtype:trojan-activity;sid:84521888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-06-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658790/; classtype:trojan-activity;sid:84521890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658792/; classtype:trojan-activity;sid:84521892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-02-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658785/; classtype:trojan-activity;sid:84521885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000640/2023-11-08/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658778/; classtype:trojan-activity;sid:84521878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-11-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658780/; classtype:trojan-activity;sid:84521880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658770/; classtype:trojan-activity;sid:84521870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-08-18/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658773/; classtype:trojan-activity;sid:84521873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-09-17/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658763/; classtype:trojan-activity;sid:84521863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658766/; classtype:trojan-activity;sid:84521866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-11-23/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658761/; classtype:trojan-activity;sid:84521861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-04-29/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658762/; classtype:trojan-activity;sid:84521862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-04-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658760/; classtype:trojan-activity;sid:84521860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-10-14/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658752/; classtype:trojan-activity;sid:84521852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-06-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658742/; classtype:trojan-activity;sid:84521842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-07-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658727/; classtype:trojan-activity;sid:84521827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-01-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658723/; classtype:trojan-activity;sid:84521823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658717/; classtype:trojan-activity;sid:84521817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658714/; classtype:trojan-activity;sid:84521814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658715/; classtype:trojan-activity;sid:84521815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658712/; classtype:trojan-activity;sid:84521812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658706/; classtype:trojan-activity;sid:84521806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-12-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658707/; classtype:trojan-activity;sid:84521807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-04-15/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658699/; classtype:trojan-activity;sid:84521799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658701/; classtype:trojan-activity;sid:84521801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658692/; classtype:trojan-activity;sid:84521792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658695/; classtype:trojan-activity;sid:84521795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658687/; classtype:trojan-activity;sid:84521787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658685/; classtype:trojan-activity;sid:84521785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658686/; classtype:trojan-activity;sid:84521786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-02-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658680/; classtype:trojan-activity;sid:84521780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658677/; classtype:trojan-activity;sid:84521777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-03-29/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658676/; classtype:trojan-activity;sid:84521776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658673/; classtype:trojan-activity;sid:84521773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/situa%c3%a7%c3%a3o/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658670/; classtype:trojan-activity;sid:84521770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-02-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658669/; classtype:trojan-activity;sid:84521769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-03-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658663/; classtype:trojan-activity;sid:84521763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658654/; classtype:trojan-activity;sid:84521754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-03-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658631/; classtype:trojan-activity;sid:84521731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-06-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658628/; classtype:trojan-activity;sid:84521728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-10-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658629/; classtype:trojan-activity;sid:84521729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-01-10/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658612/; classtype:trojan-activity;sid:84521712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-03-10/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658610/; classtype:trojan-activity;sid:84521710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658584/; classtype:trojan-activity;sid:84521684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-06-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658582/; classtype:trojan-activity;sid:84521682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-06-25/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658581/; classtype:trojan-activity;sid:84521681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-12-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658575/; classtype:trojan-activity;sid:84521675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658574/; classtype:trojan-activity;sid:84521674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000758/2023-03-04/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658568/; classtype:trojan-activity;sid:84521668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658564/; classtype:trojan-activity;sid:84521664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-04-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658565/; classtype:trojan-activity;sid:84521665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-10-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658559/; classtype:trojan-activity;sid:84521659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000721/2021-07-23/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658555/; classtype:trojan-activity;sid:84521655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658557/; classtype:trojan-activity;sid:84521657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658551/; classtype:trojan-activity;sid:84521651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658545/; classtype:trojan-activity;sid:84521645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658540/; classtype:trojan-activity;sid:84521640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658542/; classtype:trojan-activity;sid:84521642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658543/; classtype:trojan-activity;sid:84521643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-07-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658538/; classtype:trojan-activity;sid:84521638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658537/; classtype:trojan-activity;sid:84521637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-05/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658534/; classtype:trojan-activity;sid:84521634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-12-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658529/; classtype:trojan-activity;sid:84521629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-02-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658530/; classtype:trojan-activity;sid:84521630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-01-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658520/; classtype:trojan-activity;sid:84521620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658519/; classtype:trojan-activity;sid:84521619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-07-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658516/; classtype:trojan-activity;sid:84521616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-09-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658517/; classtype:trojan-activity;sid:84521617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658518/; classtype:trojan-activity;sid:84521618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658506/; classtype:trojan-activity;sid:84521606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658507/; classtype:trojan-activity;sid:84521607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658508/; classtype:trojan-activity;sid:84521608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658504/; classtype:trojan-activity;sid:84521604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658490/; classtype:trojan-activity;sid:84521590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-11-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658473/; classtype:trojan-activity;sid:84521573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658475/; classtype:trojan-activity;sid:84521575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-09-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658476/; classtype:trojan-activity;sid:84521576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000721/2019-11-12/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658470/; classtype:trojan-activity;sid:84521570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658471/; classtype:trojan-activity;sid:84521571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-01-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658472/; classtype:trojan-activity;sid:84521572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658468/; classtype:trojan-activity;sid:84521568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658464/; classtype:trojan-activity;sid:84521564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-07-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658465/; classtype:trojan-activity;sid:84521565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-01-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658457/; classtype:trojan-activity;sid:84521557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-06-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658455/; classtype:trojan-activity;sid:84521555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658456/; classtype:trojan-activity;sid:84521556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-06-03/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658453/; classtype:trojan-activity;sid:84521553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658450/; classtype:trojan-activity;sid:84521550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-09-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658448/; classtype:trojan-activity;sid:84521548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-06-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658440/; classtype:trojan-activity;sid:84521540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-08-04/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658441/; classtype:trojan-activity;sid:84521541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658442/; classtype:trojan-activity;sid:84521542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-04-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658438/; classtype:trojan-activity;sid:84521538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000721/2020-12-19/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658437/; classtype:trojan-activity;sid:84521537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658432/; classtype:trojan-activity;sid:84521532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658417/; classtype:trojan-activity;sid:84521517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658420/; classtype:trojan-activity;sid:84521520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-11-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658422/; classtype:trojan-activity;sid:84521522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-21/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658423/; classtype:trojan-activity;sid:84521523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658413/; classtype:trojan-activity;sid:84521513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658415/; classtype:trojan-activity;sid:84521515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658409/; classtype:trojan-activity;sid:84521509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658404/; classtype:trojan-activity;sid:84521504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-07-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658405/; classtype:trojan-activity;sid:84521505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658406/; classtype:trojan-activity;sid:84521506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658398/; classtype:trojan-activity;sid:84521498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658391/; classtype:trojan-activity;sid:84521491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-03-03/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658390/; classtype:trojan-activity;sid:84521490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-05-09/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658389/; classtype:trojan-activity;sid:84521489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-12-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658379/; classtype:trojan-activity;sid:84521479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-02-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658381/; classtype:trojan-activity;sid:84521481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-03-30/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658378/; classtype:trojan-activity;sid:84521478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658373/; classtype:trojan-activity;sid:84521473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-11-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658365/; classtype:trojan-activity;sid:84521465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658362/; classtype:trojan-activity;sid:84521462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658359/; classtype:trojan-activity;sid:84521459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-11/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658357/; classtype:trojan-activity;sid:84521457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-10-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658355/; classtype:trojan-activity;sid:84521455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-05-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658351/; classtype:trojan-activity;sid:84521451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-12-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658349/; classtype:trojan-activity;sid:84521449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-03-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658343/; classtype:trojan-activity;sid:84521443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-12-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658337/; classtype:trojan-activity;sid:84521437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658335/; classtype:trojan-activity;sid:84521435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658332/; classtype:trojan-activity;sid:84521432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658333/; classtype:trojan-activity;sid:84521433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-09-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658327/; classtype:trojan-activity;sid:84521427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658328/; classtype:trojan-activity;sid:84521428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-09-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658326/; classtype:trojan-activity;sid:84521426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658319/; classtype:trojan-activity;sid:84521419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-28/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658320/; classtype:trojan-activity;sid:84521420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-09-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658310/; classtype:trojan-activity;sid:84521410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-05-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658311/; classtype:trojan-activity;sid:84521411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-06-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658304/; classtype:trojan-activity;sid:84521404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658306/; classtype:trojan-activity;sid:84521406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658296/; classtype:trojan-activity;sid:84521396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658297/; classtype:trojan-activity;sid:84521397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-05-17/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658298/; classtype:trojan-activity;sid:84521398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-12-18/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658295/; classtype:trojan-activity;sid:84521395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-03-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658292/; classtype:trojan-activity;sid:84521392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-02-22/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658286/; classtype:trojan-activity;sid:84521386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2022-04-22/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658282/; classtype:trojan-activity;sid:84521382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-02-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658281/; classtype:trojan-activity;sid:84521381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658275/; classtype:trojan-activity;sid:84521375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658271/; classtype:trojan-activity;sid:84521371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-09-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658272/; classtype:trojan-activity;sid:84521372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-11-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658268/; classtype:trojan-activity;sid:84521368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658269/; classtype:trojan-activity;sid:84521369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-10-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658264/; classtype:trojan-activity;sid:84521364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658250/; classtype:trojan-activity;sid:84521350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2023-11-09/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658247/; classtype:trojan-activity;sid:84521347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-01-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658245/; classtype:trojan-activity;sid:84521345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-10-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658246/; classtype:trojan-activity;sid:84521346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-08-25/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658241/; classtype:trojan-activity;sid:84521341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-07-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658230/; classtype:trojan-activity;sid:84521330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-09-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658223/; classtype:trojan-activity;sid:84521323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658226/; classtype:trojan-activity;sid:84521326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658215/; classtype:trojan-activity;sid:84521315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658216/; classtype:trojan-activity;sid:84521316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-01-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658210/; classtype:trojan-activity;sid:84521310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-07-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658208/; classtype:trojan-activity;sid:84521308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658201/; classtype:trojan-activity;sid:84521301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-11-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658196/; classtype:trojan-activity;sid:84521296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658197/; classtype:trojan-activity;sid:84521297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-03-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658187/; classtype:trojan-activity;sid:84521287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-03-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658188/; classtype:trojan-activity;sid:84521288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-04-19/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658189/; classtype:trojan-activity;sid:84521289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658182/; classtype:trojan-activity;sid:84521282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658183/; classtype:trojan-activity;sid:84521283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658184/; classtype:trojan-activity;sid:84521284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658177/; classtype:trojan-activity;sid:84521277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2024-10-30/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658171/; classtype:trojan-activity;sid:84521271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000721/2019-12-28/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658173/; classtype:trojan-activity;sid:84521273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-05-07/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658167/; classtype:trojan-activity;sid:84521267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-06-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658162/; classtype:trojan-activity;sid:84521262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000640/2022-04-14/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658159/; classtype:trojan-activity;sid:84521259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658160/; classtype:trojan-activity;sid:84521260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658145/; classtype:trojan-activity;sid:84521245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658139/; classtype:trojan-activity;sid:84521239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658136/; classtype:trojan-activity;sid:84521236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-11-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658128/; classtype:trojan-activity;sid:84521228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658124/; classtype:trojan-activity;sid:84521224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658113/; classtype:trojan-activity;sid:84521213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658111/; classtype:trojan-activity;sid:84521211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-07-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658108/; classtype:trojan-activity;sid:84521208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-04-27/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658109/; classtype:trojan-activity;sid:84521209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000721/2021-10-21/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658106/; classtype:trojan-activity;sid:84521206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-06-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658104/; classtype:trojan-activity;sid:84521204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-05-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658099/; classtype:trojan-activity;sid:84521199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-03-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658100/; classtype:trojan-activity;sid:84521200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000758/2023-12-25/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658091/; classtype:trojan-activity;sid:84521191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2024-04-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658087/; classtype:trojan-activity;sid:84521187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-10-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658081/; classtype:trojan-activity;sid:84521181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-17/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658074/; classtype:trojan-activity;sid:84521174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-01-20/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658075/; classtype:trojan-activity;sid:84521175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-06-04/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658076/; classtype:trojan-activity;sid:84521176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-07-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658077/; classtype:trojan-activity;sid:84521177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658078/; classtype:trojan-activity;sid:84521178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-10-19/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658079/; classtype:trojan-activity;sid:84521179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-03-15/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658068/; classtype:trojan-activity;sid:84521168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-10-09/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658069/; classtype:trojan-activity;sid:84521169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658073/; classtype:trojan-activity;sid:84521173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658067/; classtype:trojan-activity;sid:84521167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-01-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658066/; classtype:trojan-activity;sid:84521166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3658061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000596/2021-08-28/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_05; reference:url, urlhaus.abuse.ch/url/3658061/; classtype:trojan-activity;sid:84521161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"217.115.212.126"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656729/; classtype:trojan-activity;sid:84519829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"217.115.212.126"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656727/; classtype:trojan-activity;sid:84519827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"217.115.212.126"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656726/; classtype:trojan-activity;sid:84519826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"47.104.96.89"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656725/; classtype:trojan-activity;sid:84519825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"92.150.82.148"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656720/; classtype:trojan-activity;sid:84519820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"103.240.211.121"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656717/; classtype:trojan-activity;sid:84519817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"103.240.211.121"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656708/; classtype:trojan-activity;sid:84519808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"103.206.139.61"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656709/; classtype:trojan-activity;sid:84519809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"180.148.33.24"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656710/; classtype:trojan-activity;sid:84519810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"103.206.139.61"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656707/; classtype:trojan-activity;sid:84519807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"179.214.0.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656704/; classtype:trojan-activity;sid:84519804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"103.240.211.121"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656702/; classtype:trojan-activity;sid:84519802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"212.27.26.206"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656701/; classtype:trojan-activity;sid:84519801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"90.8.145.102"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656696/; classtype:trojan-activity;sid:84519796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"179.214.0.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656693/; classtype:trojan-activity;sid:84519793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"103.206.139.61"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656689/; classtype:trojan-activity;sid:84519789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"217.115.212.126"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656692/; classtype:trojan-activity;sid:84519792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"180.148.33.24"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656677/; classtype:trojan-activity;sid:84519777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"68.224.70.241"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656671/; classtype:trojan-activity;sid:84519771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"5.149.184.170"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656672/; classtype:trojan-activity;sid:84519772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"179.214.0.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656674/; classtype:trojan-activity;sid:84519774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"180.76.153.78"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656666/; classtype:trojan-activity;sid:84519766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"90.8.145.102"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656667/; classtype:trojan-activity;sid:84519767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"103.206.139.61"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656665/; classtype:trojan-activity;sid:84519765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"92.150.82.148"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656662/; classtype:trojan-activity;sid:84519762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"179.214.0.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656660/; classtype:trojan-activity;sid:84519760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"103.240.211.121"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656661/; classtype:trojan-activity;sid:84519761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"179.214.0.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656652/; classtype:trojan-activity;sid:84519752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"180.148.33.24"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656654/; classtype:trojan-activity;sid:84519754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"212.27.26.206"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656638/; classtype:trojan-activity;sid:84519738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"122.170.8.40"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656639/; classtype:trojan-activity;sid:84519739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"103.206.139.61"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656640/; classtype:trojan-activity;sid:84519740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"122.170.8.40"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656634/; classtype:trojan-activity;sid:84519734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"122.170.8.40"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656635/; classtype:trojan-activity;sid:84519735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"68.224.70.241"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656636/; classtype:trojan-activity;sid:84519736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"179.214.0.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656632/; classtype:trojan-activity;sid:84519732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"180.148.33.24"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656630/; classtype:trojan-activity;sid:84519730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"122.170.8.40"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656627/; classtype:trojan-activity;sid:84519727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"90.8.145.102"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656628/; classtype:trojan-activity;sid:84519728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"180.148.33.24"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656621/; classtype:trojan-activity;sid:84519721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"90.8.145.102"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656611/; classtype:trojan-activity;sid:84519711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"103.206.139.61"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656607/; classtype:trojan-activity;sid:84519707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"90.8.145.102"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656608/; classtype:trojan-activity;sid:84519708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"212.27.26.206"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656609/; classtype:trojan-activity;sid:84519709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"103.206.139.61"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656601/; classtype:trojan-activity;sid:84519701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"90.8.145.102"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656602/; classtype:trojan-activity;sid:84519702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"180.148.33.24"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656592/; classtype:trojan-activity;sid:84519692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"180.148.33.24"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656594/; classtype:trojan-activity;sid:84519694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"122.170.8.40"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656595/; classtype:trojan-activity;sid:84519695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"122.170.8.40"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656581/; classtype:trojan-activity;sid:84519681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"122.170.8.40"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656584/; classtype:trojan-activity;sid:84519684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"179.214.0.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656577/; classtype:trojan-activity;sid:84519677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"76.130.209.104"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656574/; classtype:trojan-activity;sid:84519674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"212.27.26.206"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656572/; classtype:trojan-activity;sid:84519672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"188.118.38.161"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656566/; classtype:trojan-activity;sid:84519666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"90.8.145.102"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656563/; classtype:trojan-activity;sid:84519663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"103.240.211.121"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656555/; classtype:trojan-activity;sid:84519655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656503/; classtype:trojan-activity;sid:84519603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656456/; classtype:trojan-activity;sid:84519556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656398/; classtype:trojan-activity;sid:84519498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656061/; classtype:trojan-activity;sid:84519161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-07-26/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656060/; classtype:trojan-activity;sid:84519160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656059/; classtype:trojan-activity;sid:84519159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656056/; classtype:trojan-activity;sid:84519156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"111.235.143.155"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656057/; classtype:trojan-activity;sid:84519157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-05-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656054/; classtype:trojan-activity;sid:84519154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656051/; classtype:trojan-activity;sid:84519151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"141.155.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656050/; classtype:trojan-activity;sid:84519150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"187.247.242.34"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656047/; classtype:trojan-activity;sid:84519147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656037/; classtype:trojan-activity;sid:84519137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"122.179.136.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656038/; classtype:trojan-activity;sid:84519138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656030/; classtype:trojan-activity;sid:84519130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656021/; classtype:trojan-activity;sid:84519121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"157.10.63.251"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656019/; classtype:trojan-activity;sid:84519119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"77.172.14.72"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656007/; classtype:trojan-activity;sid:84519107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655977/; classtype:trojan-activity;sid:84519077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-12-08/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655975/; classtype:trojan-activity;sid:84519075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"185.43.45.171"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655973/; classtype:trojan-activity;sid:84519073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"27.72.159.162"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655969/; classtype:trojan-activity;sid:84519069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"160.202.15.212"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655970/; classtype:trojan-activity;sid:84519070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"157.10.63.251"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655908/; classtype:trojan-activity;sid:84519008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655903/; classtype:trojan-activity;sid:84519003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"103.8.164.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655896/; classtype:trojan-activity;sid:84518996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-31/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655887/; classtype:trojan-activity;sid:84518987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-12-23/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655881/; classtype:trojan-activity;sid:84518981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-05-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655880/; classtype:trojan-activity;sid:84518980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"70.95.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655875/; classtype:trojan-activity;sid:84518975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-06-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655867/; classtype:trojan-activity;sid:84518967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"116.58.62.74"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655866/; classtype:trojan-activity;sid:84518966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655860/; classtype:trojan-activity;sid:84518960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"138.36.2.110"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655859/; classtype:trojan-activity;sid:84518959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655844/; classtype:trojan-activity;sid:84518944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-07-14/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655845/; classtype:trojan-activity;sid:84518945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655838/; classtype:trojan-activity;sid:84518938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"93.55.251.246"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655839/; classtype:trojan-activity;sid:84518939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"37.34.230.9"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655834/; classtype:trojan-activity;sid:84518934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655829/; classtype:trojan-activity;sid:84518929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"87.249.142.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655825/; classtype:trojan-activity;sid:84518925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-01-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655824/; classtype:trojan-activity;sid:84518924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655806/; classtype:trojan-activity;sid:84518906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-01-31/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655803/; classtype:trojan-activity;sid:84518903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655801/; classtype:trojan-activity;sid:84518901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2023-06-22/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655799/; classtype:trojan-activity;sid:84518899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-01-14/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655797/; classtype:trojan-activity;sid:84518897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"138.36.2.110"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655792/; classtype:trojan-activity;sid:84518892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655791/; classtype:trojan-activity;sid:84518891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-06-02/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655787/; classtype:trojan-activity;sid:84518887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655784/; classtype:trojan-activity;sid:84518884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655782/; classtype:trojan-activity;sid:84518882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"37.34.230.9"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655783/; classtype:trojan-activity;sid:84518883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655775/; classtype:trojan-activity;sid:84518875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"32.219.189.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655774/; classtype:trojan-activity;sid:84518874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655768/; classtype:trojan-activity;sid:84518868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655766/; classtype:trojan-activity;sid:84518866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655761/; classtype:trojan-activity;sid:84518861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"77.172.14.72"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655757/; classtype:trojan-activity;sid:84518857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-16/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655754/; classtype:trojan-activity;sid:84518854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"77.211.28.150"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655755/; classtype:trojan-activity;sid:84518855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655753/; classtype:trojan-activity;sid:84518853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"77.172.14.72"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655751/; classtype:trojan-activity;sid:84518851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"188.82.127.68"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655748/; classtype:trojan-activity;sid:84518848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-06-22/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655743/; classtype:trojan-activity;sid:84518843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"170.55.7.234"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655745/; classtype:trojan-activity;sid:84518845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-03-07/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655733/; classtype:trojan-activity;sid:84518833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"67.177.204.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655730/; classtype:trojan-activity;sid:84518830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"93.55.251.246"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655718/; classtype:trojan-activity;sid:84518818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655717/; classtype:trojan-activity;sid:84518817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"157.10.63.251"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655714/; classtype:trojan-activity;sid:84518814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"72.132.64.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655699/; classtype:trojan-activity;sid:84518799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"92.150.82.148"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655703/; classtype:trojan-activity;sid:84518803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"77.211.28.150"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655696/; classtype:trojan-activity;sid:84518796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"5.89.102.77"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655697/; classtype:trojan-activity;sid:84518797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"157.10.63.251"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655662/; classtype:trojan-activity;sid:84518762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"50.65.169.30"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655665/; classtype:trojan-activity;sid:84518765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"71.198.110.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655654/; classtype:trojan-activity;sid:84518754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"178.61.160.6"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655649/; classtype:trojan-activity;sid:84518749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-12-23/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655646/; classtype:trojan-activity;sid:84518746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"178.198.246.24"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655631/; classtype:trojan-activity;sid:84518731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"103.209.67.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655596/; classtype:trojan-activity;sid:84518696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"138.36.2.110"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655593/; classtype:trojan-activity;sid:84518693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"178.61.160.6"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655594/; classtype:trojan-activity;sid:84518694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"222.252.31.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655590/; classtype:trojan-activity;sid:84518690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-11-29/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655586/; classtype:trojan-activity;sid:84518686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-02-04/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655570/; classtype:trojan-activity;sid:84518670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"103.59.134.98"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655572/; classtype:trojan-activity;sid:84518672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"103.59.134.98"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655562/; classtype:trojan-activity;sid:84518662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"70.95.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655560/; classtype:trojan-activity;sid:84518660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-03-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655556/; classtype:trojan-activity;sid:84518656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"93.43.53.67"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655557/; classtype:trojan-activity;sid:84518657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"37.34.230.9"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655559/; classtype:trojan-activity;sid:84518659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"103.36.80.114"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655553/; classtype:trojan-activity;sid:84518653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"77.211.28.150"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655518/; classtype:trojan-activity;sid:84518618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-10-22/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655510/; classtype:trojan-activity;sid:84518610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"138.36.2.110"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655507/; classtype:trojan-activity;sid:84518607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-08-05/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655503/; classtype:trojan-activity;sid:84518603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"103.8.164.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655501/; classtype:trojan-activity;sid:84518601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655495/; classtype:trojan-activity;sid:84518595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655493/; classtype:trojan-activity;sid:84518593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-12-17/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655490/; classtype:trojan-activity;sid:84518590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"160.202.15.212"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655479/; classtype:trojan-activity;sid:84518579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655476/; classtype:trojan-activity;sid:84518576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"222.252.31.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655474/; classtype:trojan-activity;sid:84518574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-09-17/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655471/; classtype:trojan-activity;sid:84518571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"70.190.199.152"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655469/; classtype:trojan-activity;sid:84518569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"93.55.251.246"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655462/; classtype:trojan-activity;sid:84518562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"92.150.82.148"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655453/; classtype:trojan-activity;sid:84518553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"138.36.2.110"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655447/; classtype:trojan-activity;sid:84518547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"186.235.86.129"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655440/; classtype:trojan-activity;sid:84518540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-02-24/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655442/; classtype:trojan-activity;sid:84518542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655430/; classtype:trojan-activity;sid:84518530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"124.123.123.15"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655436/; classtype:trojan-activity;sid:84518536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-12/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655421/; classtype:trojan-activity;sid:84518521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"93.43.53.67"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655420/; classtype:trojan-activity;sid:84518520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-01-07/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655413/; classtype:trojan-activity;sid:84518513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655411/; classtype:trojan-activity;sid:84518511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"141.155.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655408/; classtype:trojan-activity;sid:84518508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"186.235.86.129"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655403/; classtype:trojan-activity;sid:84518503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"103.209.67.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655398/; classtype:trojan-activity;sid:84518498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655387/; classtype:trojan-activity;sid:84518487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"178.198.246.24"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655383/; classtype:trojan-activity;sid:84518483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"103.209.67.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655379/; classtype:trojan-activity;sid:84518479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655378/; classtype:trojan-activity;sid:84518478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655368/; classtype:trojan-activity;sid:84518468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"160.202.15.212"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655362/; classtype:trojan-activity;sid:84518462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655353/; classtype:trojan-activity;sid:84518453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-02-14/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655345/; classtype:trojan-activity;sid:84518445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"103.209.67.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655343/; classtype:trojan-activity;sid:84518443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"72.132.64.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655339/; classtype:trojan-activity;sid:84518439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"109.193.105.79"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655335/; classtype:trojan-activity;sid:84518435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-11-14/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655330/; classtype:trojan-activity;sid:84518430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655331/; classtype:trojan-activity;sid:84518431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"32.219.189.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655329/; classtype:trojan-activity;sid:84518429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"103.8.164.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655322/; classtype:trojan-activity;sid:84518422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"94.203.254.14"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655323/; classtype:trojan-activity;sid:84518423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655321/; classtype:trojan-activity;sid:84518421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"187.247.242.34"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655317/; classtype:trojan-activity;sid:84518417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"70.95.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655313/; classtype:trojan-activity;sid:84518413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-03-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655314/; classtype:trojan-activity;sid:84518414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-03-15/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655311/; classtype:trojan-activity;sid:84518411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"186.235.86.129"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655309/; classtype:trojan-activity;sid:84518409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"122.179.136.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655306/; classtype:trojan-activity;sid:84518406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655300/; classtype:trojan-activity;sid:84518400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"141.155.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655295/; classtype:trojan-activity;sid:84518395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-10-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655293/; classtype:trojan-activity;sid:84518393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655291/; classtype:trojan-activity;sid:84518391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655286/; classtype:trojan-activity;sid:84518386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"72.132.64.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655280/; classtype:trojan-activity;sid:84518380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"138.36.2.110"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655279/; classtype:trojan-activity;sid:84518379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-02-28/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655274/; classtype:trojan-activity;sid:84518374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"93.55.251.246"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655276/; classtype:trojan-activity;sid:84518376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"188.82.127.68"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655272/; classtype:trojan-activity;sid:84518372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"103.8.164.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655267/; classtype:trojan-activity;sid:84518367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655259/; classtype:trojan-activity;sid:84518359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655257/; classtype:trojan-activity;sid:84518357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"188.82.127.68"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655253/; classtype:trojan-activity;sid:84518353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655244/; classtype:trojan-activity;sid:84518344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/sp/info.zip"; depth:55; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655245/; classtype:trojan-activity;sid:84518345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"64.234.95.70"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655230/; classtype:trojan-activity;sid:84518330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655220/; classtype:trojan-activity;sid:84518320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655213/; classtype:trojan-activity;sid:84518313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"49.204.232.47"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655207/; classtype:trojan-activity;sid:84518307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"43.230.44.36"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655203/; classtype:trojan-activity;sid:84518303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"32.219.189.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655200/; classtype:trojan-activity;sid:84518300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"187.247.242.34"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655191/; classtype:trojan-activity;sid:84518291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/info.zip"; depth:76; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655187/; classtype:trojan-activity;sid:84518287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pb/normal/produ%c3%a7%c3%a3o/info.zip"; depth:81; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655179/; classtype:trojan-activity;sid:84518279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"43.230.44.36"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655169/; classtype:trojan-activity;sid:84518269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655170/; classtype:trojan-activity;sid:84518270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"185.8.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655163/; classtype:trojan-activity;sid:84518263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"124.123.123.15"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655160/; classtype:trojan-activity;sid:84518260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"111.235.143.155"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655143/; classtype:trojan-activity;sid:84518243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"222.252.31.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655126/; classtype:trojan-activity;sid:84518226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655115/; classtype:trojan-activity;sid:84518215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"93.43.53.67"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655109/; classtype:trojan-activity;sid:84518209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655099/; classtype:trojan-activity;sid:84518199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"88.28.218.163"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655094/; classtype:trojan-activity;sid:84518194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"109.193.105.79"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655090/; classtype:trojan-activity;sid:84518190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-03-07/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655088/; classtype:trojan-activity;sid:84518188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2025-01-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655085/; classtype:trojan-activity;sid:84518185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"37.34.230.9"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655084/; classtype:trojan-activity;sid:84518184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"124.123.123.15"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655081/; classtype:trojan-activity;sid:84518181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"122.165.240.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655077/; classtype:trojan-activity;sid:84518177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-01-14/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655079/; classtype:trojan-activity;sid:84518179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"71.198.110.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655072/; classtype:trojan-activity;sid:84518172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"49.205.173.192"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655070/; classtype:trojan-activity;sid:84518170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655065/; classtype:trojan-activity;sid:84518165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"109.193.105.79"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655064/; classtype:trojan-activity;sid:84518164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655061/; classtype:trojan-activity;sid:84518161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"122.165.240.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655057/; classtype:trojan-activity;sid:84518157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"186.235.86.129"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655054/; classtype:trojan-activity;sid:84518154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655052/; classtype:trojan-activity;sid:84518152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"111.235.143.155"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655046/; classtype:trojan-activity;sid:84518146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"132.247.103.239"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655037/; classtype:trojan-activity;sid:84518137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"93.43.53.67"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655038/; classtype:trojan-activity;sid:84518138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655034/; classtype:trojan-activity;sid:84518134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655025/; classtype:trojan-activity;sid:84518125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655021/; classtype:trojan-activity;sid:84518121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"27.72.159.162"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655016/; classtype:trojan-activity;sid:84518116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"109.193.105.79"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655008/; classtype:trojan-activity;sid:84518108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"103.8.164.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655005/; classtype:trojan-activity;sid:84518105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"49.204.232.47"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655004/; classtype:trojan-activity;sid:84518104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"93.55.251.246"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655001/; classtype:trojan-activity;sid:84518101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"188.82.127.68"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654999/; classtype:trojan-activity;sid:84518099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"122.165.240.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654994/; classtype:trojan-activity;sid:84518094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-01-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654992/; classtype:trojan-activity;sid:84518092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-03-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654985/; classtype:trojan-activity;sid:84518085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654981/; classtype:trojan-activity;sid:84518081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"87.249.142.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654972/; classtype:trojan-activity;sid:84518072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"141.155.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654967/; classtype:trojan-activity;sid:84518067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-10-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654966/; classtype:trojan-activity;sid:84518066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"103.36.80.114"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654962/; classtype:trojan-activity;sid:84518062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"109.193.105.79"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654953/; classtype:trojan-activity;sid:84518053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654942/; classtype:trojan-activity;sid:84518042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"67.177.204.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654936/; classtype:trojan-activity;sid:84518036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"68.148.10.182"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654935/; classtype:trojan-activity;sid:84518035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-10-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654927/; classtype:trojan-activity;sid:84518027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654921/; classtype:trojan-activity;sid:84518021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"70.95.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654917/; classtype:trojan-activity;sid:84518017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"71.198.110.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654904/; classtype:trojan-activity;sid:84518004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"160.202.15.212"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654898/; classtype:trojan-activity;sid:84517998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654894/; classtype:trojan-activity;sid:84517994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"178.198.246.24"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654892/; classtype:trojan-activity;sid:84517992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654882/; classtype:trojan-activity;sid:84517982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"141.155.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654874/; classtype:trojan-activity;sid:84517974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654859/; classtype:trojan-activity;sid:84517959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654860/; classtype:trojan-activity;sid:84517960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"27.72.159.162"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654857/; classtype:trojan-activity;sid:84517957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654853/; classtype:trojan-activity;sid:84517953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"103.36.80.114"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654850/; classtype:trojan-activity;sid:84517950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"132.247.103.239"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654829/; classtype:trojan-activity;sid:84517929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"156.200.99.139"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654826/; classtype:trojan-activity;sid:84517926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-02-04/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654814/; classtype:trojan-activity;sid:84517914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"5.89.102.77"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654811/; classtype:trojan-activity;sid:84517911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"72.132.64.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654806/; classtype:trojan-activity;sid:84517906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654804/; classtype:trojan-activity;sid:84517904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"64.234.95.70"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654803/; classtype:trojan-activity;sid:84517903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"103.209.67.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654799/; classtype:trojan-activity;sid:84517899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654796/; classtype:trojan-activity;sid:84517896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"32.219.189.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654793/; classtype:trojan-activity;sid:84517893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"94.203.254.14"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654788/; classtype:trojan-activity;sid:84517888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/ma/info.zip"; depth:55; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654781/; classtype:trojan-activity;sid:84517881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"170.55.7.234"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654769/; classtype:trojan-activity;sid:84517869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-06-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654762/; classtype:trojan-activity;sid:84517862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"132.247.103.239"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654747/; classtype:trojan-activity;sid:84517847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"43.230.44.36"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654746/; classtype:trojan-activity;sid:84517846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654735/; classtype:trojan-activity;sid:84517835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654732/; classtype:trojan-activity;sid:84517832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-09-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654726/; classtype:trojan-activity;sid:84517826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"178.198.246.24"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654721/; classtype:trojan-activity;sid:84517821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"37.34.230.9"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654719/; classtype:trojan-activity;sid:84517819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654714/; classtype:trojan-activity;sid:84517814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654694/; classtype:trojan-activity;sid:84517794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654695/; classtype:trojan-activity;sid:84517795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-03-07/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654690/; classtype:trojan-activity;sid:84517790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654687/; classtype:trojan-activity;sid:84517787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654682/; classtype:trojan-activity;sid:84517782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-08-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654677/; classtype:trojan-activity;sid:84517777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654678/; classtype:trojan-activity;sid:84517778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"222.252.31.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654673/; classtype:trojan-activity;sid:84517773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654674/; classtype:trojan-activity;sid:84517774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-10-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654672/; classtype:trojan-activity;sid:84517772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654668/; classtype:trojan-activity;sid:84517768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654665/; classtype:trojan-activity;sid:84517765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"27.72.159.162"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654661/; classtype:trojan-activity;sid:84517761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"122.165.240.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654659/; classtype:trojan-activity;sid:84517759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"71.198.110.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654657/; classtype:trojan-activity;sid:84517757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"93.43.53.67"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654655/; classtype:trojan-activity;sid:84517755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"43.230.44.36"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654654/; classtype:trojan-activity;sid:84517754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"70.190.199.152"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654651/; classtype:trojan-activity;sid:84517751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-11-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654643/; classtype:trojan-activity;sid:84517743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"49.205.173.192"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654641/; classtype:trojan-activity;sid:84517741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654634/; classtype:trojan-activity;sid:84517734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"124.123.123.15"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654625/; classtype:trojan-activity;sid:84517725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654622/; classtype:trojan-activity;sid:84517722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654610/; classtype:trojan-activity;sid:84517710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654608/; classtype:trojan-activity;sid:84517708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"50.65.169.30"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654600/; classtype:trojan-activity;sid:84517700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"72.132.64.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654589/; classtype:trojan-activity;sid:84517689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654585/; classtype:trojan-activity;sid:84517685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654575/; classtype:trojan-activity;sid:84517675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"122.165.240.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654555/; classtype:trojan-activity;sid:84517655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654546/; classtype:trojan-activity;sid:84517646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"50.65.169.30"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654541/; classtype:trojan-activity;sid:84517641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"122.179.136.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654542/; classtype:trojan-activity;sid:84517642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"72.132.64.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654533/; classtype:trojan-activity;sid:84517633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"109.193.105.79"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654531/; classtype:trojan-activity;sid:84517631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"77.211.28.150"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654527/; classtype:trojan-activity;sid:84517627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654526/; classtype:trojan-activity;sid:84517626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-11-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654522/; classtype:trojan-activity;sid:84517622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"222.252.31.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654513/; classtype:trojan-activity;sid:84517613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-15/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654514/; classtype:trojan-activity;sid:84517614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-07-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654509/; classtype:trojan-activity;sid:84517609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"103.36.80.114"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654508/; classtype:trojan-activity;sid:84517608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654507/; classtype:trojan-activity;sid:84517607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"93.43.53.67"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654504/; classtype:trojan-activity;sid:84517604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"77.172.14.72"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654499/; classtype:trojan-activity;sid:84517599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"49.204.232.47"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654501/; classtype:trojan-activity;sid:84517601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"103.59.134.98"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654498/; classtype:trojan-activity;sid:84517598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"157.10.63.251"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654495/; classtype:trojan-activity;sid:84517595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-30/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654491/; classtype:trojan-activity;sid:84517591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"116.58.62.74"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654484/; classtype:trojan-activity;sid:84517584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"141.155.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654477/; classtype:trojan-activity;sid:84517577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"160.202.15.212"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654451/; classtype:trojan-activity;sid:84517551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"122.165.240.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654447/; classtype:trojan-activity;sid:84517547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"187.247.242.34"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654445/; classtype:trojan-activity;sid:84517545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654428/; classtype:trojan-activity;sid:84517528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-08-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654414/; classtype:trojan-activity;sid:84517514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"186.235.86.129"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654392/; classtype:trojan-activity;sid:84517492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"103.209.67.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654390/; classtype:trojan-activity;sid:84517490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654391/; classtype:trojan-activity;sid:84517491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"5.89.102.77"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654385/; classtype:trojan-activity;sid:84517485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-06-05/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654372/; classtype:trojan-activity;sid:84517472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"49.204.232.47"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654342/; classtype:trojan-activity;sid:84517442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654336/; classtype:trojan-activity;sid:84517436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"50.65.169.30"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654337/; classtype:trojan-activity;sid:84517437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"222.252.31.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654334/; classtype:trojan-activity;sid:84517434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"188.82.127.68"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654333/; classtype:trojan-activity;sid:84517433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654331/; classtype:trojan-activity;sid:84517431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-09-08/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654328/; classtype:trojan-activity;sid:84517428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"103.59.134.98"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654326/; classtype:trojan-activity;sid:84517426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"64.234.95.70"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654321/; classtype:trojan-activity;sid:84517421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654320/; classtype:trojan-activity;sid:84517420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"111.235.143.155"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654312/; classtype:trojan-activity;sid:84517412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654308/; classtype:trojan-activity;sid:84517408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"187.247.242.34"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654303/; classtype:trojan-activity;sid:84517403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654299/; classtype:trojan-activity;sid:84517399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654292/; classtype:trojan-activity;sid:84517392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"103.59.134.98"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654288/; classtype:trojan-activity;sid:84517388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"49.204.232.47"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654289/; classtype:trojan-activity;sid:84517389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"67.177.204.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654285/; classtype:trojan-activity;sid:84517385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"116.58.62.74"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654284/; classtype:trojan-activity;sid:84517384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654283/; classtype:trojan-activity;sid:84517383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"27.72.159.162"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654276/; classtype:trojan-activity;sid:84517376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654270/; classtype:trojan-activity;sid:84517370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654268/; classtype:trojan-activity;sid:84517368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"43.230.44.36"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654258/; classtype:trojan-activity;sid:84517358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"178.198.246.24"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654253/; classtype:trojan-activity;sid:84517353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654247/; classtype:trojan-activity;sid:84517347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"70.95.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654243/; classtype:trojan-activity;sid:84517343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654239/; classtype:trojan-activity;sid:84517339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"107.128.101.219"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654234/; classtype:trojan-activity;sid:84517334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654233/; classtype:trojan-activity;sid:84517333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-03-22/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654227/; classtype:trojan-activity;sid:84517327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654209/; classtype:trojan-activity;sid:84517309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654205/; classtype:trojan-activity;sid:84517305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"103.8.164.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654203/; classtype:trojan-activity;sid:84517303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654204/; classtype:trojan-activity;sid:84517304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"116.58.62.74"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654202/; classtype:trojan-activity;sid:84517302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"5.89.102.77"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654197/; classtype:trojan-activity;sid:84517297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"122.179.136.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654195/; classtype:trojan-activity;sid:84517295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"178.198.246.24"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654192/; classtype:trojan-activity;sid:84517292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-10-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654187/; classtype:trojan-activity;sid:84517287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"111.235.143.155"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654173/; classtype:trojan-activity;sid:84517273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-06-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654163/; classtype:trojan-activity;sid:84517263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"37.34.230.9"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654161/; classtype:trojan-activity;sid:84517261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-09-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654160/; classtype:trojan-activity;sid:84517260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-12-10/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654135/; classtype:trojan-activity;sid:84517235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654125/; classtype:trojan-activity;sid:84517225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"122.179.136.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654122/; classtype:trojan-activity;sid:84517222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"49.204.232.47"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654123/; classtype:trojan-activity;sid:84517223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654119/; classtype:trojan-activity;sid:84517219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654117/; classtype:trojan-activity;sid:84517217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"132.247.103.239"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654113/; classtype:trojan-activity;sid:84517213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"49.205.173.192"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654108/; classtype:trojan-activity;sid:84517208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"27.72.159.162"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654098/; classtype:trojan-activity;sid:84517198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-01-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654092/; classtype:trojan-activity;sid:84517192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654088/; classtype:trojan-activity;sid:84517188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"122.165.240.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654078/; classtype:trojan-activity;sid:84517178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"49.205.173.192"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654077/; classtype:trojan-activity;sid:84517177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654076/; classtype:trojan-activity;sid:84517176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"70.190.199.152"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654074/; classtype:trojan-activity;sid:84517174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"77.211.28.150"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654072/; classtype:trojan-activity;sid:84517172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"50.65.169.30"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654065/; classtype:trojan-activity;sid:84517165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"124.123.123.15"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654044/; classtype:trojan-activity;sid:84517144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654034/; classtype:trojan-activity;sid:84517134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654033/; classtype:trojan-activity;sid:84517133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"70.95.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654032/; classtype:trojan-activity;sid:84517132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654025/; classtype:trojan-activity;sid:84517125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"94.203.254.14"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654024/; classtype:trojan-activity;sid:84517124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"49.205.173.192"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654019/; classtype:trojan-activity;sid:84517119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"170.55.7.234"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654018/; classtype:trojan-activity;sid:84517118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654017/; classtype:trojan-activity;sid:84517117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"103.36.80.114"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654009/; classtype:trojan-activity;sid:84517109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-08-17/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654005/; classtype:trojan-activity;sid:84517105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654003/; classtype:trojan-activity;sid:84517103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"5.89.102.77"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653997/; classtype:trojan-activity;sid:84517097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653992/; classtype:trojan-activity;sid:84517092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"67.177.204.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653985/; classtype:trojan-activity;sid:84517085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"70.190.199.152"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653977/; classtype:trojan-activity;sid:84517077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653972/; classtype:trojan-activity;sid:84517072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"124.123.123.15"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653964/; classtype:trojan-activity;sid:84517064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"186.235.86.129"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653960/; classtype:trojan-activity;sid:84517060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653947/; classtype:trojan-activity;sid:84517047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"156.200.99.139"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653941/; classtype:trojan-activity;sid:84517041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653943/; classtype:trojan-activity;sid:84517043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"170.55.7.234"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653939/; classtype:trojan-activity;sid:84517039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"116.58.62.74"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653930/; classtype:trojan-activity;sid:84517030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"49.205.173.192"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653917/; classtype:trojan-activity;sid:84517017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"64.234.95.70"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653918/; classtype:trojan-activity;sid:84517018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"178.61.160.6"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653916/; classtype:trojan-activity;sid:84517016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653914/; classtype:trojan-activity;sid:84517014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"160.202.15.212"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653912/; classtype:trojan-activity;sid:84517012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"93.55.251.246"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653910/; classtype:trojan-activity;sid:84517010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-04-01/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653907/; classtype:trojan-activity;sid:84517007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"94.203.254.14"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653900/; classtype:trojan-activity;sid:84517000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653892/; classtype:trojan-activity;sid:84516992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"116.58.62.74"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653888/; classtype:trojan-activity;sid:84516988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"32.219.189.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653885/; classtype:trojan-activity;sid:84516985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-04-19/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653882/; classtype:trojan-activity;sid:84516982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-31/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653875/; classtype:trojan-activity;sid:84516975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653874/; classtype:trojan-activity;sid:84516974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"178.198.246.24"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653871/; classtype:trojan-activity;sid:84516971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"94.203.254.14"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653867/; classtype:trojan-activity;sid:84516967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653864/; classtype:trojan-activity;sid:84516964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653861/; classtype:trojan-activity;sid:84516961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"77.172.14.72"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653858/; classtype:trojan-activity;sid:84516958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653856/; classtype:trojan-activity;sid:84516956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653852/; classtype:trojan-activity;sid:84516952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"132.247.103.239"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653848/; classtype:trojan-activity;sid:84516948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653849/; classtype:trojan-activity;sid:84516949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"32.219.189.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653840/; classtype:trojan-activity;sid:84516940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-01-10/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653839/; classtype:trojan-activity;sid:84516939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653836/; classtype:trojan-activity;sid:84516936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"5.89.102.77"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653828/; classtype:trojan-activity;sid:84516928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"43.230.44.36"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653827/; classtype:trojan-activity;sid:84516927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653826/; classtype:trojan-activity;sid:84516926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"70.190.199.152"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653824/; classtype:trojan-activity;sid:84516924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653823/; classtype:trojan-activity;sid:84516923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-04-29/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653819/; classtype:trojan-activity;sid:84516919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"170.55.7.234"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653813/; classtype:trojan-activity;sid:84516913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"156.200.99.139"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653806/; classtype:trojan-activity;sid:84516906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"156.200.99.139"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653799/; classtype:trojan-activity;sid:84516899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653792/; classtype:trojan-activity;sid:84516892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-04-01/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653790/; classtype:trojan-activity;sid:84516890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653785/; classtype:trojan-activity;sid:84516885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/df/conting%c3%aancia/produ%c3%a7%c3%a3o/info.zip"; depth:92; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653783/; classtype:trojan-activity;sid:84516883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653782/; classtype:trojan-activity;sid:84516882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"49.205.173.192"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653781/; classtype:trojan-activity;sid:84516881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"103.36.80.114"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653770/; classtype:trojan-activity;sid:84516870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653758/; classtype:trojan-activity;sid:84516858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"212.27.26.206"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653756/; classtype:trojan-activity;sid:84516856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653755/; classtype:trojan-activity;sid:84516855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653751/; classtype:trojan-activity;sid:84516851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"187.247.242.34"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653749/; classtype:trojan-activity;sid:84516849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"103.59.134.98"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653748/; classtype:trojan-activity;sid:84516848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"170.55.7.234"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653745/; classtype:trojan-activity;sid:84516845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"186.235.86.129"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653743/; classtype:trojan-activity;sid:84516843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/info.zip"; depth:59; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653741/; classtype:trojan-activity;sid:84516841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-06-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653737/; classtype:trojan-activity;sid:84516837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653734/; classtype:trojan-activity;sid:84516834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"178.61.160.6"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653732/; classtype:trojan-activity;sid:84516832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653730/; classtype:trojan-activity;sid:84516830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653728/; classtype:trojan-activity;sid:84516828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653722/; classtype:trojan-activity;sid:84516822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"32.219.189.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653717/; classtype:trojan-activity;sid:84516817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-11-30/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653707/; classtype:trojan-activity;sid:84516807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"168.121.168.84"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653705/; classtype:trojan-activity;sid:84516805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653702/; classtype:trojan-activity;sid:84516802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-03-01/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653696/; classtype:trojan-activity;sid:84516796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653695/; classtype:trojan-activity;sid:84516795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653693/; classtype:trojan-activity;sid:84516793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"71.198.110.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653690/; classtype:trojan-activity;sid:84516790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"111.235.143.155"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653691/; classtype:trojan-activity;sid:84516791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653685/; classtype:trojan-activity;sid:84516785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653683/; classtype:trojan-activity;sid:84516783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653681/; classtype:trojan-activity;sid:84516781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653675/; classtype:trojan-activity;sid:84516775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"43.230.44.36"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653672/; classtype:trojan-activity;sid:84516772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"67.177.204.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653669/; classtype:trojan-activity;sid:84516769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-03-17/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653665/; classtype:trojan-activity;sid:84516765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"70.190.199.152"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653666/; classtype:trojan-activity;sid:84516766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"188.82.127.68"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653662/; classtype:trojan-activity;sid:84516762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"178.61.160.6"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653661/; classtype:trojan-activity;sid:84516761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"122.179.136.112"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653655/; classtype:trojan-activity;sid:84516755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653649/; classtype:trojan-activity;sid:84516749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-04-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653650/; classtype:trojan-activity;sid:84516750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"71.198.110.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653647/; classtype:trojan-activity;sid:84516747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.scr"; depth:10; endswith; nocase; http.host; content:"49.204.232.47"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653640/; classtype:trojan-activity;sid:84516740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-10-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653636/; classtype:trojan-activity;sid:84516736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.scr"; depth:7; endswith; nocase; http.host; content:"64.234.95.70"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653634/; classtype:trojan-activity;sid:84516734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"93.55.251.246"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653632/; classtype:trojan-activity;sid:84516732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"188.82.127.68"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653627/; classtype:trojan-activity;sid:84516727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-07-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653619/; classtype:trojan-activity;sid:84516719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.lnk"; depth:10; endswith; nocase; http.host; content:"156.200.99.139"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653620/; classtype:trojan-activity;sid:84516720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"156.200.99.139"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653621/; classtype:trojan-activity;sid:84516721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/av.lnk"; depth:7; endswith; nocase; http.host; content:"94.203.254.14"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653611/; classtype:trojan-activity;sid:84516711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653606/; classtype:trojan-activity;sid:84516706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/video.lnk"; depth:10; endswith; nocase; http.host; content:"80.11.25.16"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653607/; classtype:trojan-activity;sid:84516707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653605/; classtype:trojan-activity;sid:84516705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653602/; classtype:trojan-activity;sid:84516702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653599/; classtype:trojan-activity;sid:84516699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653598/; classtype:trojan-activity;sid:84516698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-02-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653595/; classtype:trojan-activity;sid:84516695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-12-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653593/; classtype:trojan-activity;sid:84516693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-04-14/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653586/; classtype:trojan-activity;sid:84516686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653585/; classtype:trojan-activity;sid:84516685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653577/; classtype:trojan-activity;sid:84516677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-08-17/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653550/; classtype:trojan-activity;sid:84516650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653546/; classtype:trojan-activity;sid:84516646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653537/; classtype:trojan-activity;sid:84516637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-03-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653530/; classtype:trojan-activity;sid:84516630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653525/; classtype:trojan-activity;sid:84516625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653526/; classtype:trojan-activity;sid:84516626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-08-03/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653518/; classtype:trojan-activity;sid:84516618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-11/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653508/; classtype:trojan-activity;sid:84516608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653502/; classtype:trojan-activity;sid:84516602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-05/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653500/; classtype:trojan-activity;sid:84516600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653492/; classtype:trojan-activity;sid:84516592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-01-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653489/; classtype:trojan-activity;sid:84516589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653487/; classtype:trojan-activity;sid:84516587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653485/; classtype:trojan-activity;sid:84516585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-07-26/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653483/; classtype:trojan-activity;sid:84516583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653479/; classtype:trojan-activity;sid:84516579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653466/; classtype:trojan-activity;sid:84516566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-04-05/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653464/; classtype:trojan-activity;sid:84516564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pa/conting%c3%aancia/info.zip"; depth:73; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653440/; classtype:trojan-activity;sid:84516540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653427/; classtype:trojan-activity;sid:84516527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-05/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653408/; classtype:trojan-activity;sid:84516508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-05-04/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653405/; classtype:trojan-activity;sid:84516505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-09-17/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653384/; classtype:trojan-activity;sid:84516484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653380/; classtype:trojan-activity;sid:84516480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-07-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653374/; classtype:trojan-activity;sid:84516474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653370/; classtype:trojan-activity;sid:84516470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-07-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653366/; classtype:trojan-activity;sid:84516466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653363/; classtype:trojan-activity;sid:84516463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653347/; classtype:trojan-activity;sid:84516447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-12-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653343/; classtype:trojan-activity;sid:84516443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-08-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653333/; classtype:trojan-activity;sid:84516433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-12-19/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653310/; classtype:trojan-activity;sid:84516410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653311/; classtype:trojan-activity;sid:84516411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653303/; classtype:trojan-activity;sid:84516403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-10-10/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653304/; classtype:trojan-activity;sid:84516404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653297/; classtype:trojan-activity;sid:84516397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653293/; classtype:trojan-activity;sid:84516393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653290/; classtype:trojan-activity;sid:84516390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-07-06/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653289/; classtype:trojan-activity;sid:84516389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653288/; classtype:trojan-activity;sid:84516388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653281/; classtype:trojan-activity;sid:84516381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-09-03/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653279/; classtype:trojan-activity;sid:84516379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-31/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653278/; classtype:trojan-activity;sid:84516378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653264/; classtype:trojan-activity;sid:84516364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653248/; classtype:trojan-activity;sid:84516348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653250/; classtype:trojan-activity;sid:84516350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2023-11-23/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653244/; classtype:trojan-activity;sid:84516344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653243/; classtype:trojan-activity;sid:84516343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653238/; classtype:trojan-activity;sid:84516338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653234/; classtype:trojan-activity;sid:84516334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653208/; classtype:trojan-activity;sid:84516308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653205/; classtype:trojan-activity;sid:84516305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653204/; classtype:trojan-activity;sid:84516304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-04-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653179/; classtype:trojan-activity;sid:84516279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-11-23/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653176/; classtype:trojan-activity;sid:84516276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-04-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653177/; classtype:trojan-activity;sid:84516277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653173/; classtype:trojan-activity;sid:84516273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-11-30/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653169/; classtype:trojan-activity;sid:84516269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653171/; classtype:trojan-activity;sid:84516271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653172/; classtype:trojan-activity;sid:84516272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653166/; classtype:trojan-activity;sid:84516266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-01-10/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653159/; classtype:trojan-activity;sid:84516259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653160/; classtype:trojan-activity;sid:84516260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653161/; classtype:trojan-activity;sid:84516261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653156/; classtype:trojan-activity;sid:84516256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-10-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653155/; classtype:trojan-activity;sid:84516255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-01-19/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653151/; classtype:trojan-activity;sid:84516251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-16/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653149/; classtype:trojan-activity;sid:84516249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-10-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653148/; classtype:trojan-activity;sid:84516248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-09-10/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653143/; classtype:trojan-activity;sid:84516243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653140/; classtype:trojan-activity;sid:84516240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653137/; classtype:trojan-activity;sid:84516237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653136/; classtype:trojan-activity;sid:84516236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-01-14/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653121/; classtype:trojan-activity;sid:84516221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653114/; classtype:trojan-activity;sid:84516214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653111/; classtype:trojan-activity;sid:84516211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653107/; classtype:trojan-activity;sid:84516207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653104/; classtype:trojan-activity;sid:84516204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653097/; classtype:trojan-activity;sid:84516197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653094/; classtype:trojan-activity;sid:84516194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653079/; classtype:trojan-activity;sid:84516179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653073/; classtype:trojan-activity;sid:84516173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653066/; classtype:trojan-activity;sid:84516166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-10-04/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653056/; classtype:trojan-activity;sid:84516156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-02-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653054/; classtype:trojan-activity;sid:84516154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-11-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653051/; classtype:trojan-activity;sid:84516151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-11-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653047/; classtype:trojan-activity;sid:84516147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-05-07/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653049/; classtype:trojan-activity;sid:84516149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653044/; classtype:trojan-activity;sid:84516144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653041/; classtype:trojan-activity;sid:84516141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-11-12/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653042/; classtype:trojan-activity;sid:84516142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653038/; classtype:trojan-activity;sid:84516138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653025/; classtype:trojan-activity;sid:84516125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653021/; classtype:trojan-activity;sid:84516121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-02-08/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653011/; classtype:trojan-activity;sid:84516111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652998/; classtype:trojan-activity;sid:84516098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652994/; classtype:trojan-activity;sid:84516094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-09-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652988/; classtype:trojan-activity;sid:84516088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652989/; classtype:trojan-activity;sid:84516089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652985/; classtype:trojan-activity;sid:84516085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652980/; classtype:trojan-activity;sid:84516080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652976/; classtype:trojan-activity;sid:84516076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652977/; classtype:trojan-activity;sid:84516077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-01-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652970/; classtype:trojan-activity;sid:84516070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-10-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652967/; classtype:trojan-activity;sid:84516067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-03-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652962/; classtype:trojan-activity;sid:84516062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652960/; classtype:trojan-activity;sid:84516060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652954/; classtype:trojan-activity;sid:84516054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-10-26/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652953/; classtype:trojan-activity;sid:84516053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-09-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652940/; classtype:trojan-activity;sid:84516040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-31/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652935/; classtype:trojan-activity;sid:84516035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652932/; classtype:trojan-activity;sid:84516032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652933/; classtype:trojan-activity;sid:84516033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652926/; classtype:trojan-activity;sid:84516026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652923/; classtype:trojan-activity;sid:84516023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652921/; classtype:trojan-activity;sid:84516021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652919/; classtype:trojan-activity;sid:84516019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652920/; classtype:trojan-activity;sid:84516020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-03-01/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652907/; classtype:trojan-activity;sid:84516007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652895/; classtype:trojan-activity;sid:84515995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652869/; classtype:trojan-activity;sid:84515969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652865/; classtype:trojan-activity;sid:84515965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652846/; classtype:trojan-activity;sid:84515946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652851/; classtype:trojan-activity;sid:84515951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652837/; classtype:trojan-activity;sid:84515937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-05-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652820/; classtype:trojan-activity;sid:84515920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652821/; classtype:trojan-activity;sid:84515921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652803/; classtype:trojan-activity;sid:84515903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652788/; classtype:trojan-activity;sid:84515888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652789/; classtype:trojan-activity;sid:84515889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652777/; classtype:trojan-activity;sid:84515877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652776/; classtype:trojan-activity;sid:84515876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652772/; classtype:trojan-activity;sid:84515872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-06-25/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652742/; classtype:trojan-activity;sid:84515842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-01-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652725/; classtype:trojan-activity;sid:84515825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652723/; classtype:trojan-activity;sid:84515823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652718/; classtype:trojan-activity;sid:84515818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652719/; classtype:trojan-activity;sid:84515819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652720/; classtype:trojan-activity;sid:84515820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652721/; classtype:trojan-activity;sid:84515821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652716/; classtype:trojan-activity;sid:84515816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652717/; classtype:trojan-activity;sid:84515817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652705/; classtype:trojan-activity;sid:84515805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652707/; classtype:trojan-activity;sid:84515807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-09-09/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652702/; classtype:trojan-activity;sid:84515802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652696/; classtype:trojan-activity;sid:84515796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-11-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652688/; classtype:trojan-activity;sid:84515788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652692/; classtype:trojan-activity;sid:84515792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652675/; classtype:trojan-activity;sid:84515775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-08-04/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652645/; classtype:trojan-activity;sid:84515745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-05-13/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652637/; classtype:trojan-activity;sid:84515737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-03-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652640/; classtype:trojan-activity;sid:84515740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-11-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652636/; classtype:trojan-activity;sid:84515736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652629/; classtype:trojan-activity;sid:84515729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652618/; classtype:trojan-activity;sid:84515718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-04-01/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652604/; classtype:trojan-activity;sid:84515704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-01-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652593/; classtype:trojan-activity;sid:84515693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-01-30/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652591/; classtype:trojan-activity;sid:84515691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652578/; classtype:trojan-activity;sid:84515678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-05-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652573/; classtype:trojan-activity;sid:84515673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652564/; classtype:trojan-activity;sid:84515664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652527/; classtype:trojan-activity;sid:84515627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-11-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652485/; classtype:trojan-activity;sid:84515585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652483/; classtype:trojan-activity;sid:84515583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652484/; classtype:trojan-activity;sid:84515584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/es/conting%c3%aancia/info.zip"; depth:73; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652482/; classtype:trojan-activity;sid:84515582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pa/info.zip"; depth:55; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652481/; classtype:trojan-activity;sid:84515581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652480/; classtype:trojan-activity;sid:84515580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652478/; classtype:trojan-activity;sid:84515578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-02-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652476/; classtype:trojan-activity;sid:84515576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-07-05/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652474/; classtype:trojan-activity;sid:84515574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-09-10/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652475/; classtype:trojan-activity;sid:84515575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-06-23/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652473/; classtype:trojan-activity;sid:84515573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-09-26/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652472/; classtype:trojan-activity;sid:84515572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652471/; classtype:trojan-activity;sid:84515571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652470/; classtype:trojan-activity;sid:84515570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-05-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652467/; classtype:trojan-activity;sid:84515567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-05-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652468/; classtype:trojan-activity;sid:84515568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652469/; classtype:trojan-activity;sid:84515569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-04-03/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652465/; classtype:trojan-activity;sid:84515565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652463/; classtype:trojan-activity;sid:84515563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652462/; classtype:trojan-activity;sid:84515562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652461/; classtype:trojan-activity;sid:84515561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-12-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652460/; classtype:trojan-activity;sid:84515560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-04-23/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652458/; classtype:trojan-activity;sid:84515558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652459/; classtype:trojan-activity;sid:84515559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652457/; classtype:trojan-activity;sid:84515557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652455/; classtype:trojan-activity;sid:84515555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-03-30/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652454/; classtype:trojan-activity;sid:84515554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-12-11/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652453/; classtype:trojan-activity;sid:84515553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-01-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652451/; classtype:trojan-activity;sid:84515551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652452/; classtype:trojan-activity;sid:84515552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652446/; classtype:trojan-activity;sid:84515546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652447/; classtype:trojan-activity;sid:84515547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652448/; classtype:trojan-activity;sid:84515548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-07-08/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652442/; classtype:trojan-activity;sid:84515542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652441/; classtype:trojan-activity;sid:84515541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-01-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652439/; classtype:trojan-activity;sid:84515539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652437/; classtype:trojan-activity;sid:84515537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652438/; classtype:trojan-activity;sid:84515538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652436/; classtype:trojan-activity;sid:84515536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652435/; classtype:trojan-activity;sid:84515535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-09-14/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652434/; classtype:trojan-activity;sid:84515534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652433/; classtype:trojan-activity;sid:84515533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-05-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652432/; classtype:trojan-activity;sid:84515532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652431/; classtype:trojan-activity;sid:84515531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652430/; classtype:trojan-activity;sid:84515530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652429/; classtype:trojan-activity;sid:84515529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652427/; classtype:trojan-activity;sid:84515527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-10-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652428/; classtype:trojan-activity;sid:84515528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-02-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652425/; classtype:trojan-activity;sid:84515525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652424/; classtype:trojan-activity;sid:84515524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652423/; classtype:trojan-activity;sid:84515523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-04-26/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652421/; classtype:trojan-activity;sid:84515521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pe/normal/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652419/; classtype:trojan-activity;sid:84515519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-03-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652420/; classtype:trojan-activity;sid:84515520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652417/; classtype:trojan-activity;sid:84515517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652418/; classtype:trojan-activity;sid:84515518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652415/; classtype:trojan-activity;sid:84515515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-12-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652416/; classtype:trojan-activity;sid:84515516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652413/; classtype:trojan-activity;sid:84515513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652412/; classtype:trojan-activity;sid:84515512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/df/normal/produ%c3%a7%c3%a3o/info.zip"; depth:81; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652411/; classtype:trojan-activity;sid:84515511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-03-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652407/; classtype:trojan-activity;sid:84515507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652402/; classtype:trojan-activity;sid:84515502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652399/; classtype:trojan-activity;sid:84515499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652400/; classtype:trojan-activity;sid:84515500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-03-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652397/; classtype:trojan-activity;sid:84515497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652398/; classtype:trojan-activity;sid:84515498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652395/; classtype:trojan-activity;sid:84515495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-07-29/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652396/; classtype:trojan-activity;sid:84515496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-01-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652391/; classtype:trojan-activity;sid:84515491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/ma/conting%c3%aancia/info.zip"; depth:73; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652392/; classtype:trojan-activity;sid:84515492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652390/; classtype:trojan-activity;sid:84515490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652389/; classtype:trojan-activity;sid:84515489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652386/; classtype:trojan-activity;sid:84515486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-11-08/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652384/; classtype:trojan-activity;sid:84515484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-08-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652383/; classtype:trojan-activity;sid:84515483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-09-29/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652380/; classtype:trojan-activity;sid:84515480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652381/; classtype:trojan-activity;sid:84515481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652382/; classtype:trojan-activity;sid:84515482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652377/; classtype:trojan-activity;sid:84515477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652378/; classtype:trojan-activity;sid:84515478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652376/; classtype:trojan-activity;sid:84515476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652375/; classtype:trojan-activity;sid:84515475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652373/; classtype:trojan-activity;sid:84515473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652371/; classtype:trojan-activity;sid:84515471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652370/; classtype:trojan-activity;sid:84515470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-01-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652368/; classtype:trojan-activity;sid:84515468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652369/; classtype:trojan-activity;sid:84515469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652366/; classtype:trojan-activity;sid:84515466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-11/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652365/; classtype:trojan-activity;sid:84515465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-12-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652363/; classtype:trojan-activity;sid:84515463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652364/; classtype:trojan-activity;sid:84515464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-10-13/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652360/; classtype:trojan-activity;sid:84515460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652359/; classtype:trojan-activity;sid:84515459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-09-09/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652358/; classtype:trojan-activity;sid:84515458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-10-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652357/; classtype:trojan-activity;sid:84515457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652356/; classtype:trojan-activity;sid:84515456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652353/; classtype:trojan-activity;sid:84515453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652354/; classtype:trojan-activity;sid:84515454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652349/; classtype:trojan-activity;sid:84515449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/info.zip"; depth:76; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652351/; classtype:trojan-activity;sid:84515451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652352/; classtype:trojan-activity;sid:84515452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652348/; classtype:trojan-activity;sid:84515448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652346/; classtype:trojan-activity;sid:84515446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-10-19/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652342/; classtype:trojan-activity;sid:84515442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652343/; classtype:trojan-activity;sid:84515443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652344/; classtype:trojan-activity;sid:84515444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652345/; classtype:trojan-activity;sid:84515445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652340/; classtype:trojan-activity;sid:84515440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652336/; classtype:trojan-activity;sid:84515436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652337/; classtype:trojan-activity;sid:84515437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652338/; classtype:trojan-activity;sid:84515438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652339/; classtype:trojan-activity;sid:84515439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652335/; classtype:trojan-activity;sid:84515435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-04-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652333/; classtype:trojan-activity;sid:84515433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-12-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652331/; classtype:trojan-activity;sid:84515431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652326/; classtype:trojan-activity;sid:84515426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-01-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652327/; classtype:trojan-activity;sid:84515427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652328/; classtype:trojan-activity;sid:84515428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652329/; classtype:trojan-activity;sid:84515429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-11-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652330/; classtype:trojan-activity;sid:84515430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652325/; classtype:trojan-activity;sid:84515425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-09-30/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652324/; classtype:trojan-activity;sid:84515424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652323/; classtype:trojan-activity;sid:84515423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652322/; classtype:trojan-activity;sid:84515422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652320/; classtype:trojan-activity;sid:84515420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-12-09/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652318/; classtype:trojan-activity;sid:84515418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652319/; classtype:trojan-activity;sid:84515419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652317/; classtype:trojan-activity;sid:84515417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-04-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652316/; classtype:trojan-activity;sid:84515416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-31/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652314/; classtype:trojan-activity;sid:84515414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pa/conting%c3%aancia/produ%c3%a7%c3%a3o/info.zip"; depth:92; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652312/; classtype:trojan-activity;sid:84515412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-06-04/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652313/; classtype:trojan-activity;sid:84515413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652309/; classtype:trojan-activity;sid:84515409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652307/; classtype:trojan-activity;sid:84515407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652305/; classtype:trojan-activity;sid:84515405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652306/; classtype:trojan-activity;sid:84515406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-10-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652304/; classtype:trojan-activity;sid:84515404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652303/; classtype:trojan-activity;sid:84515403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652300/; classtype:trojan-activity;sid:84515400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652302/; classtype:trojan-activity;sid:84515402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652298/; classtype:trojan-activity;sid:84515398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-04-19/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652296/; classtype:trojan-activity;sid:84515396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652294/; classtype:trojan-activity;sid:84515394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652295/; classtype:trojan-activity;sid:84515395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652293/; classtype:trojan-activity;sid:84515393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-01-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652292/; classtype:trojan-activity;sid:84515392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-08-25/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652291/; classtype:trojan-activity;sid:84515391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-04-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652290/; classtype:trojan-activity;sid:84515390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-11-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652289/; classtype:trojan-activity;sid:84515389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-25/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652288/; classtype:trojan-activity;sid:84515388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pe/normal/produ%c3%a7%c3%a3o/info.zip"; depth:81; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652287/; classtype:trojan-activity;sid:84515387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652286/; classtype:trojan-activity;sid:84515386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-11-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652284/; classtype:trojan-activity;sid:84515384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652282/; classtype:trojan-activity;sid:84515382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-12-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652280/; classtype:trojan-activity;sid:84515380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652281/; classtype:trojan-activity;sid:84515381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-01-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652279/; classtype:trojan-activity;sid:84515379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652278/; classtype:trojan-activity;sid:84515378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-31/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652276/; classtype:trojan-activity;sid:84515376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652273/; classtype:trojan-activity;sid:84515373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-08-18/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652274/; classtype:trojan-activity;sid:84515374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652272)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-11-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652272/; classtype:trojan-activity;sid:84515372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652270/; classtype:trojan-activity;sid:84515370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-01-29/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652269/; classtype:trojan-activity;sid:84515369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652268/; classtype:trojan-activity;sid:84515368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-10-27/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652265/; classtype:trojan-activity;sid:84515365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-16/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652264/; classtype:trojan-activity;sid:84515364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652263/; classtype:trojan-activity;sid:84515363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652262/; classtype:trojan-activity;sid:84515362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652261/; classtype:trojan-activity;sid:84515361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-01-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652259/; classtype:trojan-activity;sid:84515359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652260/; classtype:trojan-activity;sid:84515360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652257/; classtype:trojan-activity;sid:84515357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-03-29/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652256/; classtype:trojan-activity;sid:84515356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652255/; classtype:trojan-activity;sid:84515355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-11-25/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652250/; classtype:trojan-activity;sid:84515350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652247/; classtype:trojan-activity;sid:84515347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652249/; classtype:trojan-activity;sid:84515349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-12-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652246/; classtype:trojan-activity;sid:84515346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652245/; classtype:trojan-activity;sid:84515345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-09-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652244/; classtype:trojan-activity;sid:84515344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-09-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652243/; classtype:trojan-activity;sid:84515343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652241/; classtype:trojan-activity;sid:84515341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652242/; classtype:trojan-activity;sid:84515342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-08-10/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652239/; classtype:trojan-activity;sid:84515339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652240/; classtype:trojan-activity;sid:84515340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652238/; classtype:trojan-activity;sid:84515338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652237/; classtype:trojan-activity;sid:84515337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-07-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652236/; classtype:trojan-activity;sid:84515336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652235/; classtype:trojan-activity;sid:84515335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-03-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652234/; classtype:trojan-activity;sid:84515334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-08-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652232/; classtype:trojan-activity;sid:84515332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652233/; classtype:trojan-activity;sid:84515333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652230/; classtype:trojan-activity;sid:84515330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-01-27/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652231/; classtype:trojan-activity;sid:84515331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-02-12/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652229/; classtype:trojan-activity;sid:84515329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-06-25/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652225/; classtype:trojan-activity;sid:84515325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652223/; classtype:trojan-activity;sid:84515323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652221/; classtype:trojan-activity;sid:84515321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652222/; classtype:trojan-activity;sid:84515322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652219/; classtype:trojan-activity;sid:84515319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652218/; classtype:trojan-activity;sid:84515318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652217/; classtype:trojan-activity;sid:84515317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652216/; classtype:trojan-activity;sid:84515316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652214/; classtype:trojan-activity;sid:84515314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-02-01/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652215/; classtype:trojan-activity;sid:84515315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652213/; classtype:trojan-activity;sid:84515313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652211/; classtype:trojan-activity;sid:84515311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-02-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652209/; classtype:trojan-activity;sid:84515309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652208/; classtype:trojan-activity;sid:84515308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-03-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652206/; classtype:trojan-activity;sid:84515306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652207/; classtype:trojan-activity;sid:84515307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652205/; classtype:trojan-activity;sid:84515305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652204/; classtype:trojan-activity;sid:84515304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652203/; classtype:trojan-activity;sid:84515303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652201/; classtype:trojan-activity;sid:84515301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652200/; classtype:trojan-activity;sid:84515300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-06/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652196/; classtype:trojan-activity;sid:84515296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652193/; classtype:trojan-activity;sid:84515293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-08-08/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652194/; classtype:trojan-activity;sid:84515294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652192/; classtype:trojan-activity;sid:84515292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pe/conting%c3%aancia/info.zip"; depth:73; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652186/; classtype:trojan-activity;sid:84515286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652188/; classtype:trojan-activity;sid:84515288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652189/; classtype:trojan-activity;sid:84515289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-08-28/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652190/; classtype:trojan-activity;sid:84515290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652191/; classtype:trojan-activity;sid:84515291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652185/; classtype:trojan-activity;sid:84515285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652184/; classtype:trojan-activity;sid:84515284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652183/; classtype:trojan-activity;sid:84515283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652181/; classtype:trojan-activity;sid:84515281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652180/; classtype:trojan-activity;sid:84515280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-04-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652179/; classtype:trojan-activity;sid:84515279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652176/; classtype:trojan-activity;sid:84515276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652177/; classtype:trojan-activity;sid:84515277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-11-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652178/; classtype:trojan-activity;sid:84515278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652175/; classtype:trojan-activity;sid:84515275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-04/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652174/; classtype:trojan-activity;sid:84515274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652173/; classtype:trojan-activity;sid:84515273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652171/; classtype:trojan-activity;sid:84515271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652169/; classtype:trojan-activity;sid:84515269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652170/; classtype:trojan-activity;sid:84515270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652167/; classtype:trojan-activity;sid:84515267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652166/; classtype:trojan-activity;sid:84515266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652165/; classtype:trojan-activity;sid:84515265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652164/; classtype:trojan-activity;sid:84515264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652163/; classtype:trojan-activity;sid:84515263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-24/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652162/; classtype:trojan-activity;sid:84515262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652161/; classtype:trojan-activity;sid:84515261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652160/; classtype:trojan-activity;sid:84515260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652157/; classtype:trojan-activity;sid:84515257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652158/; classtype:trojan-activity;sid:84515258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652159/; classtype:trojan-activity;sid:84515259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652156/; classtype:trojan-activity;sid:84515256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652154/; classtype:trojan-activity;sid:84515254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-08-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652152/; classtype:trojan-activity;sid:84515252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652153/; classtype:trojan-activity;sid:84515253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652151/; classtype:trojan-activity;sid:84515251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-06-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652150/; classtype:trojan-activity;sid:84515250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-08-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652147/; classtype:trojan-activity;sid:84515247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652148/; classtype:trojan-activity;sid:84515248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652149/; classtype:trojan-activity;sid:84515249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652145/; classtype:trojan-activity;sid:84515245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652146/; classtype:trojan-activity;sid:84515246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652141/; classtype:trojan-activity;sid:84515241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-10-14/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652143/; classtype:trojan-activity;sid:84515243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652140/; classtype:trojan-activity;sid:84515240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652136/; classtype:trojan-activity;sid:84515236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652137/; classtype:trojan-activity;sid:84515237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652135/; classtype:trojan-activity;sid:84515235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652132/; classtype:trojan-activity;sid:84515232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652133/; classtype:trojan-activity;sid:84515233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652134/; classtype:trojan-activity;sid:84515234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652128/; classtype:trojan-activity;sid:84515228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652129/; classtype:trojan-activity;sid:84515229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-04-19/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652130/; classtype:trojan-activity;sid:84515230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652131/; classtype:trojan-activity;sid:84515231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652126/; classtype:trojan-activity;sid:84515226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652124/; classtype:trojan-activity;sid:84515224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-03-24/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652121/; classtype:trojan-activity;sid:84515221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652120/; classtype:trojan-activity;sid:84515220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652119/; classtype:trojan-activity;sid:84515219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652112/; classtype:trojan-activity;sid:84515212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652113/; classtype:trojan-activity;sid:84515213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652114/; classtype:trojan-activity;sid:84515214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652115/; classtype:trojan-activity;sid:84515215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652116/; classtype:trojan-activity;sid:84515216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652118/; classtype:trojan-activity;sid:84515218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652108/; classtype:trojan-activity;sid:84515208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-09/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652109/; classtype:trojan-activity;sid:84515209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-11-30/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652110/; classtype:trojan-activity;sid:84515210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652111/; classtype:trojan-activity;sid:84515211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652107/; classtype:trojan-activity;sid:84515207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652105/; classtype:trojan-activity;sid:84515205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652106/; classtype:trojan-activity;sid:84515206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652102/; classtype:trojan-activity;sid:84515202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-04-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652103/; classtype:trojan-activity;sid:84515203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652104/; classtype:trojan-activity;sid:84515204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-12-19/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652101/; classtype:trojan-activity;sid:84515201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-10-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652099/; classtype:trojan-activity;sid:84515199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652100/; classtype:trojan-activity;sid:84515200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652098/; classtype:trojan-activity;sid:84515198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652097/; classtype:trojan-activity;sid:84515197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-05-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652095/; classtype:trojan-activity;sid:84515195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-04-24/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652094/; classtype:trojan-activity;sid:84515194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-03-13/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652091/; classtype:trojan-activity;sid:84515191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-08-05/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652090/; classtype:trojan-activity;sid:84515190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-05-24/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652086/; classtype:trojan-activity;sid:84515186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-12-27/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652088/; classtype:trojan-activity;sid:84515188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-02-04/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652089/; classtype:trojan-activity;sid:84515189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652081/; classtype:trojan-activity;sid:84515181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-08-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652082/; classtype:trojan-activity;sid:84515182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-06-07/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652083/; classtype:trojan-activity;sid:84515183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652078/; classtype:trojan-activity;sid:84515178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-04-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652075/; classtype:trojan-activity;sid:84515175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652076/; classtype:trojan-activity;sid:84515176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652077/; classtype:trojan-activity;sid:84515177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652070/; classtype:trojan-activity;sid:84515170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652071/; classtype:trojan-activity;sid:84515171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-11-23/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652067/; classtype:trojan-activity;sid:84515167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652068/; classtype:trojan-activity;sid:84515168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652060/; classtype:trojan-activity;sid:84515160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-10-24/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652061/; classtype:trojan-activity;sid:84515161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-27/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652063/; classtype:trojan-activity;sid:84515163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652064/; classtype:trojan-activity;sid:84515164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-11-09/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652065/; classtype:trojan-activity;sid:84515165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652066/; classtype:trojan-activity;sid:84515166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-04-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652057/; classtype:trojan-activity;sid:84515157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-03-29/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652053/; classtype:trojan-activity;sid:84515153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652054/; classtype:trojan-activity;sid:84515154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-08-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652048/; classtype:trojan-activity;sid:84515148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652049/; classtype:trojan-activity;sid:84515149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652050/; classtype:trojan-activity;sid:84515150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652051/; classtype:trojan-activity;sid:84515151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652052/; classtype:trojan-activity;sid:84515152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-02-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652045/; classtype:trojan-activity;sid:84515145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-06-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652046/; classtype:trojan-activity;sid:84515146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652042/; classtype:trojan-activity;sid:84515142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652043/; classtype:trojan-activity;sid:84515143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-03-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652041/; classtype:trojan-activity;sid:84515141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652039/; classtype:trojan-activity;sid:84515139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-07-30/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652040/; classtype:trojan-activity;sid:84515140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652036/; classtype:trojan-activity;sid:84515136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-05-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652037/; classtype:trojan-activity;sid:84515137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-01-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652038/; classtype:trojan-activity;sid:84515138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652025/; classtype:trojan-activity;sid:84515125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/info.zip"; depth:76; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652026/; classtype:trojan-activity;sid:84515126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652027/; classtype:trojan-activity;sid:84515127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652028/; classtype:trojan-activity;sid:84515128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652029/; classtype:trojan-activity;sid:84515129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652030/; classtype:trojan-activity;sid:84515130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652031)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652031/; classtype:trojan-activity;sid:84515131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-07-06/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652024/; classtype:trojan-activity;sid:84515124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652023/; classtype:trojan-activity;sid:84515123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652022/; classtype:trojan-activity;sid:84515122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652021/; classtype:trojan-activity;sid:84515121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-09-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652014/; classtype:trojan-activity;sid:84515114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652015/; classtype:trojan-activity;sid:84515115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652017/; classtype:trojan-activity;sid:84515117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652019/; classtype:trojan-activity;sid:84515119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652020/; classtype:trojan-activity;sid:84515120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-18/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652012/; classtype:trojan-activity;sid:84515112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652013/; classtype:trojan-activity;sid:84515113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652007/; classtype:trojan-activity;sid:84515107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652008/; classtype:trojan-activity;sid:84515108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-04-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652010/; classtype:trojan-activity;sid:84515110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-07-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652011/; classtype:trojan-activity;sid:84515111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-03-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652006/; classtype:trojan-activity;sid:84515106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652003/; classtype:trojan-activity;sid:84515103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652002/; classtype:trojan-activity;sid:84515102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3652000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-04-11/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3652000/; classtype:trojan-activity;sid:84515100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651998/; classtype:trojan-activity;sid:84515098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651993/; classtype:trojan-activity;sid:84515093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/info.zip"; depth:76; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651996/; classtype:trojan-activity;sid:84515096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-07-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651997/; classtype:trojan-activity;sid:84515097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651991/; classtype:trojan-activity;sid:84515091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651992/; classtype:trojan-activity;sid:84515092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651989/; classtype:trojan-activity;sid:84515089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651990/; classtype:trojan-activity;sid:84515090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-09-09/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651987/; classtype:trojan-activity;sid:84515087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651988/; classtype:trojan-activity;sid:84515088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-02-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651981/; classtype:trojan-activity;sid:84515081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-09-02/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651982/; classtype:trojan-activity;sid:84515082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-07-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651983/; classtype:trojan-activity;sid:84515083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-03-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651985/; classtype:trojan-activity;sid:84515085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-08-17/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651986/; classtype:trojan-activity;sid:84515086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651978/; classtype:trojan-activity;sid:84515078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-12-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651980/; classtype:trojan-activity;sid:84515080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-03-07/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651969/; classtype:trojan-activity;sid:84515069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-07-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651971/; classtype:trojan-activity;sid:84515071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-02-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651972/; classtype:trojan-activity;sid:84515072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-31/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651973/; classtype:trojan-activity;sid:84515073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651974/; classtype:trojan-activity;sid:84515074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651975/; classtype:trojan-activity;sid:84515075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651976/; classtype:trojan-activity;sid:84515076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-03-03/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651977/; classtype:trojan-activity;sid:84515077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651967/; classtype:trojan-activity;sid:84515067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-09-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651968/; classtype:trojan-activity;sid:84515068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651965/; classtype:trojan-activity;sid:84515065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-02-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651966/; classtype:trojan-activity;sid:84515066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-10-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651963/; classtype:trojan-activity;sid:84515063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-09-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651964/; classtype:trojan-activity;sid:84515064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651959/; classtype:trojan-activity;sid:84515059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651960/; classtype:trojan-activity;sid:84515060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651961/; classtype:trojan-activity;sid:84515061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651962/; classtype:trojan-activity;sid:84515062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-04-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651958/; classtype:trojan-activity;sid:84515058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-09-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651956/; classtype:trojan-activity;sid:84515056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651957/; classtype:trojan-activity;sid:84515057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651955/; classtype:trojan-activity;sid:84515055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651954/; classtype:trojan-activity;sid:84515054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651952/; classtype:trojan-activity;sid:84515052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651953/; classtype:trojan-activity;sid:84515053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651951/; classtype:trojan-activity;sid:84515051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-05-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651949/; classtype:trojan-activity;sid:84515049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651950/; classtype:trojan-activity;sid:84515050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pa/normal/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651944/; classtype:trojan-activity;sid:84515044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651945/; classtype:trojan-activity;sid:84515045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/1/9929/11032020101348/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651946/; classtype:trojan-activity;sid:84515046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-09-27/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651947/; classtype:trojan-activity;sid:84515047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651943/; classtype:trojan-activity;sid:84515043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-12-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651942/; classtype:trojan-activity;sid:84515042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651937/; classtype:trojan-activity;sid:84515037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651938/; classtype:trojan-activity;sid:84515038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651941/; classtype:trojan-activity;sid:84515041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651933/; classtype:trojan-activity;sid:84515033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-10-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651934/; classtype:trojan-activity;sid:84515034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651935/; classtype:trojan-activity;sid:84515035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651931/; classtype:trojan-activity;sid:84515031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-10-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651932/; classtype:trojan-activity;sid:84515032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pe/conting%c3%aancia/produ%c3%a7%c3%a3o/info.zip"; depth:92; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651930/; classtype:trojan-activity;sid:84515030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651928/; classtype:trojan-activity;sid:84515028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pb/info.zip"; depth:55; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651929/; classtype:trojan-activity;sid:84515029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-03-18/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651926/; classtype:trojan-activity;sid:84515026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651927/; classtype:trojan-activity;sid:84515027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651921/; classtype:trojan-activity;sid:84515021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-07-29/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651923/; classtype:trojan-activity;sid:84515023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651924/; classtype:trojan-activity;sid:84515024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651925/; classtype:trojan-activity;sid:84515025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-03-26/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651915/; classtype:trojan-activity;sid:84515015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-05-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651916/; classtype:trojan-activity;sid:84515016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651917/; classtype:trojan-activity;sid:84515017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651913/; classtype:trojan-activity;sid:84515013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-12-02/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651909/; classtype:trojan-activity;sid:84515009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651912/; classtype:trojan-activity;sid:84515012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651905/; classtype:trojan-activity;sid:84515005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651906/; classtype:trojan-activity;sid:84515006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651907/; classtype:trojan-activity;sid:84515007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651901/; classtype:trojan-activity;sid:84515001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-11-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651902/; classtype:trojan-activity;sid:84515002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651903/; classtype:trojan-activity;sid:84515003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651899/; classtype:trojan-activity;sid:84514999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651900/; classtype:trojan-activity;sid:84515000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-09-08/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651896/; classtype:trojan-activity;sid:84514996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651897/; classtype:trojan-activity;sid:84514997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651898/; classtype:trojan-activity;sid:84514998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651894/; classtype:trojan-activity;sid:84514994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651895/; classtype:trojan-activity;sid:84514995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160618/td00000000000000159843/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651892/; classtype:trojan-activity;sid:84514992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651893/; classtype:trojan-activity;sid:84514993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651890/; classtype:trojan-activity;sid:84514990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651891/; classtype:trojan-activity;sid:84514991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651887/; classtype:trojan-activity;sid:84514987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/ma/normal/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651888/; classtype:trojan-activity;sid:84514988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651889/; classtype:trojan-activity;sid:84514989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651883/; classtype:trojan-activity;sid:84514983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651884/; classtype:trojan-activity;sid:84514984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-07-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651885/; classtype:trojan-activity;sid:84514985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651881/; classtype:trojan-activity;sid:84514981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651882/; classtype:trojan-activity;sid:84514982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651877/; classtype:trojan-activity;sid:84514977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-02-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651878/; classtype:trojan-activity;sid:84514978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-11-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651879/; classtype:trojan-activity;sid:84514979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651874/; classtype:trojan-activity;sid:84514974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-10-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651875/; classtype:trojan-activity;sid:84514975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651876/; classtype:trojan-activity;sid:84514976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-12-10/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651867/; classtype:trojan-activity;sid:84514967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651868/; classtype:trojan-activity;sid:84514968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651869/; classtype:trojan-activity;sid:84514969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-04-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651870/; classtype:trojan-activity;sid:84514970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651872/; classtype:trojan-activity;sid:84514972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651873/; classtype:trojan-activity;sid:84514973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-12-27/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651866/; classtype:trojan-activity;sid:84514966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651865/; classtype:trojan-activity;sid:84514965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651861/; classtype:trojan-activity;sid:84514961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651862/; classtype:trojan-activity;sid:84514962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651863/; classtype:trojan-activity;sid:84514963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651864/; classtype:trojan-activity;sid:84514964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651859/; classtype:trojan-activity;sid:84514959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651860/; classtype:trojan-activity;sid:84514960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651857/; classtype:trojan-activity;sid:84514957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651855/; classtype:trojan-activity;sid:84514955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-22/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651854/; classtype:trojan-activity;sid:84514954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651852/; classtype:trojan-activity;sid:84514952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651853/; classtype:trojan-activity;sid:84514953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651849/; classtype:trojan-activity;sid:84514949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651850/; classtype:trojan-activity;sid:84514950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-08-31/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651848/; classtype:trojan-activity;sid:84514948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651847/; classtype:trojan-activity;sid:84514947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651845/; classtype:trojan-activity;sid:84514945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pb/conting%c3%aancia/produ%c3%a7%c3%a3o/info.zip"; depth:92; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651844/; classtype:trojan-activity;sid:84514944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651843/; classtype:trojan-activity;sid:84514943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651836/; classtype:trojan-activity;sid:84514936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651837/; classtype:trojan-activity;sid:84514937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-03/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651838/; classtype:trojan-activity;sid:84514938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651839/; classtype:trojan-activity;sid:84514939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651840/; classtype:trojan-activity;sid:84514940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651842/; classtype:trojan-activity;sid:84514942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-11-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651834/; classtype:trojan-activity;sid:84514934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-04-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651835/; classtype:trojan-activity;sid:84514935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651832/; classtype:trojan-activity;sid:84514932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651833/; classtype:trojan-activity;sid:84514933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-07-01/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651829/; classtype:trojan-activity;sid:84514929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651830/; classtype:trojan-activity;sid:84514930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651822/; classtype:trojan-activity;sid:84514922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651823/; classtype:trojan-activity;sid:84514923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651824/; classtype:trojan-activity;sid:84514924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-03-11/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651825/; classtype:trojan-activity;sid:84514925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651826/; classtype:trojan-activity;sid:84514926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-05-27/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651820/; classtype:trojan-activity;sid:84514920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/es/normal/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651821/; classtype:trojan-activity;sid:84514921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651819/; classtype:trojan-activity;sid:84514919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651813/; classtype:trojan-activity;sid:84514913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651814/; classtype:trojan-activity;sid:84514914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-01-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651815/; classtype:trojan-activity;sid:84514915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651816/; classtype:trojan-activity;sid:84514916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651818/; classtype:trojan-activity;sid:84514918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-10-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651812/; classtype:trojan-activity;sid:84514912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-04-29/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651808/; classtype:trojan-activity;sid:84514908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-06-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651802/; classtype:trojan-activity;sid:84514902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-06-18/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651803/; classtype:trojan-activity;sid:84514903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-03/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651805/; classtype:trojan-activity;sid:84514905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651801/; classtype:trojan-activity;sid:84514901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-01-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651798/; classtype:trojan-activity;sid:84514898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-02-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651797/; classtype:trojan-activity;sid:84514897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-01-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651790/; classtype:trojan-activity;sid:84514890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168897/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651789/; classtype:trojan-activity;sid:84514889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/sp/conting%c3%aancia/info.zip"; depth:73; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651787/; classtype:trojan-activity;sid:84514887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-05-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651782/; classtype:trojan-activity;sid:84514882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651783/; classtype:trojan-activity;sid:84514883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651785/; classtype:trojan-activity;sid:84514885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651786/; classtype:trojan-activity;sid:84514886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pa/normal/produ%c3%a7%c3%a3o/info.zip"; depth:81; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651777/; classtype:trojan-activity;sid:84514877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-16/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651778/; classtype:trojan-activity;sid:84514878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651780/; classtype:trojan-activity;sid:84514880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651781/; classtype:trojan-activity;sid:84514881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651774/; classtype:trojan-activity;sid:84514874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-11-22/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651775/; classtype:trojan-activity;sid:84514875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651770/; classtype:trojan-activity;sid:84514870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651772/; classtype:trojan-activity;sid:84514872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651773/; classtype:trojan-activity;sid:84514873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-01-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651769/; classtype:trojan-activity;sid:84514869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651766/; classtype:trojan-activity;sid:84514866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651767/; classtype:trojan-activity;sid:84514867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-03-15/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651763/; classtype:trojan-activity;sid:84514863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-11-27/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651764/; classtype:trojan-activity;sid:84514864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651765/; classtype:trojan-activity;sid:84514865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651760/; classtype:trojan-activity;sid:84514860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-04-01/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651761/; classtype:trojan-activity;sid:84514861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651762/; classtype:trojan-activity;sid:84514862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-10-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651755/; classtype:trojan-activity;sid:84514855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-06/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651756/; classtype:trojan-activity;sid:84514856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/sp/normal/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651758/; classtype:trojan-activity;sid:84514858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651759/; classtype:trojan-activity;sid:84514859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-09-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651753/; classtype:trojan-activity;sid:84514853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-09-15/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651754/; classtype:trojan-activity;sid:84514854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651751/; classtype:trojan-activity;sid:84514851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651752/; classtype:trojan-activity;sid:84514852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/info.zip"; depth:59; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651750/; classtype:trojan-activity;sid:84514850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651741/; classtype:trojan-activity;sid:84514841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651742/; classtype:trojan-activity;sid:84514842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651745/; classtype:trojan-activity;sid:84514845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651747/; classtype:trojan-activity;sid:84514847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pa/conting%c3%aancia/homologa%c3%a7%c3%a3o/info.zip"; depth:95; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651748/; classtype:trojan-activity;sid:84514848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651740/; classtype:trojan-activity;sid:84514840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651734/; classtype:trojan-activity;sid:84514834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-08-28/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651736/; classtype:trojan-activity;sid:84514836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651737/; classtype:trojan-activity;sid:84514837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/info.zip"; depth:76; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651738/; classtype:trojan-activity;sid:84514838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651739/; classtype:trojan-activity;sid:84514839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-08-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651730/; classtype:trojan-activity;sid:84514830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651731/; classtype:trojan-activity;sid:84514831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-11-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651732/; classtype:trojan-activity;sid:84514832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651728/; classtype:trojan-activity;sid:84514828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-12-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651726/; classtype:trojan-activity;sid:84514826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-01-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651727/; classtype:trojan-activity;sid:84514827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-12-23/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651725/; classtype:trojan-activity;sid:84514825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651720/; classtype:trojan-activity;sid:84514820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-08-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651721/; classtype:trojan-activity;sid:84514821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651722/; classtype:trojan-activity;sid:84514822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-04-27/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651723/; classtype:trojan-activity;sid:84514823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651724/; classtype:trojan-activity;sid:84514824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651717/; classtype:trojan-activity;sid:84514817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-01-08/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651718/; classtype:trojan-activity;sid:84514818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pb/normal/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651716/; classtype:trojan-activity;sid:84514816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651715/; classtype:trojan-activity;sid:84514815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-04-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651713/; classtype:trojan-activity;sid:84514813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-11-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651714/; classtype:trojan-activity;sid:84514814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-18/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651710/; classtype:trojan-activity;sid:84514810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651711/; classtype:trojan-activity;sid:84514811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-20/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651709/; classtype:trojan-activity;sid:84514809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651707/; classtype:trojan-activity;sid:84514807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651708/; classtype:trojan-activity;sid:84514808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651705/; classtype:trojan-activity;sid:84514805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-06-27/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651699/; classtype:trojan-activity;sid:84514799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-12-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651700/; classtype:trojan-activity;sid:84514800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-04-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651701/; classtype:trojan-activity;sid:84514801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pb/conting%c3%aancia/info.zip"; depth:73; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651702/; classtype:trojan-activity;sid:84514802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651703/; classtype:trojan-activity;sid:84514803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-07/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651695/; classtype:trojan-activity;sid:84514795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-22/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651696/; classtype:trojan-activity;sid:84514796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-05-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651697/; classtype:trojan-activity;sid:84514797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-15/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651693/; classtype:trojan-activity;sid:84514793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651694/; classtype:trojan-activity;sid:84514794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651691/; classtype:trojan-activity;sid:84514791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651692/; classtype:trojan-activity;sid:84514792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-01-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651686/; classtype:trojan-activity;sid:84514786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651687/; classtype:trojan-activity;sid:84514787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651688/; classtype:trojan-activity;sid:84514788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651690/; classtype:trojan-activity;sid:84514790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-07-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651685/; classtype:trojan-activity;sid:84514785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-07-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651682/; classtype:trojan-activity;sid:84514782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-04-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651683/; classtype:trojan-activity;sid:84514783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651681/; classtype:trojan-activity;sid:84514781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-02-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651680/; classtype:trojan-activity;sid:84514780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-03-14/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651678/; classtype:trojan-activity;sid:84514778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-04-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651675/; classtype:trojan-activity;sid:84514775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651677/; classtype:trojan-activity;sid:84514777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-03-22/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651668/; classtype:trojan-activity;sid:84514768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/df/conting%c3%aancia/info.zip"; depth:73; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651669/; classtype:trojan-activity;sid:84514769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-02-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651670/; classtype:trojan-activity;sid:84514770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651671/; classtype:trojan-activity;sid:84514771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-12-04/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651667/; classtype:trojan-activity;sid:84514767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/info.zip"; depth:59; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651664/; classtype:trojan-activity;sid:84514764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-11-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651665/; classtype:trojan-activity;sid:84514765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651655/; classtype:trojan-activity;sid:84514755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-02-23/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651656/; classtype:trojan-activity;sid:84514756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651657/; classtype:trojan-activity;sid:84514757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-12/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651658/; classtype:trojan-activity;sid:84514758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651659/; classtype:trojan-activity;sid:84514759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651661/; classtype:trojan-activity;sid:84514761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-06-24/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651651/; classtype:trojan-activity;sid:84514751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-09/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651652/; classtype:trojan-activity;sid:84514752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651653/; classtype:trojan-activity;sid:84514753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651654/; classtype:trojan-activity;sid:84514754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651645/; classtype:trojan-activity;sid:84514745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-11/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651646/; classtype:trojan-activity;sid:84514746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-09-29/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651647/; classtype:trojan-activity;sid:84514747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651648/; classtype:trojan-activity;sid:84514748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651649/; classtype:trojan-activity;sid:84514749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-29/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651640/; classtype:trojan-activity;sid:84514740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-02/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651641/; classtype:trojan-activity;sid:84514741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651642/; classtype:trojan-activity;sid:84514742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651643/; classtype:trojan-activity;sid:84514743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-05-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651644/; classtype:trojan-activity;sid:84514744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-09-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651632/; classtype:trojan-activity;sid:84514732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-07-16/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651633/; classtype:trojan-activity;sid:84514733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651634/; classtype:trojan-activity;sid:84514734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-01-19/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651635/; classtype:trojan-activity;sid:84514735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-05-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651636/; classtype:trojan-activity;sid:84514736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/info.zip"; depth:59; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651637/; classtype:trojan-activity;sid:84514737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651638/; classtype:trojan-activity;sid:84514738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-06-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651630/; classtype:trojan-activity;sid:84514730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-02-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651631/; classtype:trojan-activity;sid:84514731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-09-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651628/; classtype:trojan-activity;sid:84514728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-04-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651622/; classtype:trojan-activity;sid:84514722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-07-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651623/; classtype:trojan-activity;sid:84514723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-03-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651624/; classtype:trojan-activity;sid:84514724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-04-05/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651625/; classtype:trojan-activity;sid:84514725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-14/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651627/; classtype:trojan-activity;sid:84514727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651620/; classtype:trojan-activity;sid:84514720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-21/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651621/; classtype:trojan-activity;sid:84514721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651619/; classtype:trojan-activity;sid:84514719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651617/; classtype:trojan-activity;sid:84514717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-17/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651616/; classtype:trojan-activity;sid:84514716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-05-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651615/; classtype:trojan-activity;sid:84514715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651614/; classtype:trojan-activity;sid:84514714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-03-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651613/; classtype:trojan-activity;sid:84514713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-08-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651608/; classtype:trojan-activity;sid:84514708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651605/; classtype:trojan-activity;sid:84514705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651603/; classtype:trojan-activity;sid:84514703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-08-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651604/; classtype:trojan-activity;sid:84514704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-03-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651598/; classtype:trojan-activity;sid:84514698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-05-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651599/; classtype:trojan-activity;sid:84514699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651600/; classtype:trojan-activity;sid:84514700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-11-09/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651601/; classtype:trojan-activity;sid:84514701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-11-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651591/; classtype:trojan-activity;sid:84514691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-01-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651592/; classtype:trojan-activity;sid:84514692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-07-07/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651593/; classtype:trojan-activity;sid:84514693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-10-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651594/; classtype:trojan-activity;sid:84514694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-13/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651595/; classtype:trojan-activity;sid:84514695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-02-04/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651597/; classtype:trojan-activity;sid:84514697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-08-06/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651588/; classtype:trojan-activity;sid:84514688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/ma/conting%c3%aancia/produ%c3%a7%c3%a3o/info.zip"; depth:92; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651589/; classtype:trojan-activity;sid:84514689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-23/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651590/; classtype:trojan-activity;sid:84514690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-03-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651583/; classtype:trojan-activity;sid:84514683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-08-25/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651584/; classtype:trojan-activity;sid:84514684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-01-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651582/; classtype:trojan-activity;sid:84514682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-04-26/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651580/; classtype:trojan-activity;sid:84514680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-09/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651581/; classtype:trojan-activity;sid:84514681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-04-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651579/; classtype:trojan-activity;sid:84514679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-12/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651577/; classtype:trojan-activity;sid:84514677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651578/; classtype:trojan-activity;sid:84514678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-05/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651574/; classtype:trojan-activity;sid:84514674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-10/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651575/; classtype:trojan-activity;sid:84514675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-04-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651576/; classtype:trojan-activity;sid:84514676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651570/; classtype:trojan-activity;sid:84514670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-03-06/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651571/; classtype:trojan-activity;sid:84514671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-08-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651567/; classtype:trojan-activity;sid:84514667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-04-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651568/; classtype:trojan-activity;sid:84514668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-05-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651565/; classtype:trojan-activity;sid:84514665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-05-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651566/; classtype:trojan-activity;sid:84514666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651564/; classtype:trojan-activity;sid:84514664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-05-30/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651562/; classtype:trojan-activity;sid:84514662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651563/; classtype:trojan-activity;sid:84514663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-05-01/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651560/; classtype:trojan-activity;sid:84514660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651561/; classtype:trojan-activity;sid:84514661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-10-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651558/; classtype:trojan-activity;sid:84514658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-02-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651559/; classtype:trojan-activity;sid:84514659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-15/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651553/; classtype:trojan-activity;sid:84514653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651554/; classtype:trojan-activity;sid:84514654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651555/; classtype:trojan-activity;sid:84514655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651557/; classtype:trojan-activity;sid:84514657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-02-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651548/; classtype:trojan-activity;sid:84514648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-04/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651549/; classtype:trojan-activity;sid:84514649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170596/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651550/; classtype:trojan-activity;sid:84514650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-07-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651551/; classtype:trojan-activity;sid:84514651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-03-27/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651552/; classtype:trojan-activity;sid:84514652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-07-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651545/; classtype:trojan-activity;sid:84514645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-04-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651546/; classtype:trojan-activity;sid:84514646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000162/consulta%20geral/2025-04-24/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651539/; classtype:trojan-activity;sid:84514639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-25/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651542/; classtype:trojan-activity;sid:84514642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-01-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651544/; classtype:trojan-activity;sid:84514644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000405/consulta%20geral/2025-02-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651532/; classtype:trojan-activity;sid:84514632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-16/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651533/; classtype:trojan-activity;sid:84514633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651534/; classtype:trojan-activity;sid:84514634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-07-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651535/; classtype:trojan-activity;sid:84514635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000324/consulta%20geral/2025-02-08/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651536/; classtype:trojan-activity;sid:84514636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-05/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651530/; classtype:trojan-activity;sid:84514630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651531/; classtype:trojan-activity;sid:84514631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-06-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651529/; classtype:trojan-activity;sid:84514629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000596/consulta%20geral/2025-04-18/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651527/; classtype:trojan-activity;sid:84514627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/02589791000677/consulta%20geral/2025-02-28/info.zip"; depth:87; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651526/; classtype:trojan-activity;sid:84514626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-02-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651525/; classtype:trojan-activity;sid:84514625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/pe/info.zip"; depth:55; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651524/; classtype:trojan-activity;sid:84514624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-01-26/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651521/; classtype:trojan-activity;sid:84514621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-11-04/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651522/; classtype:trojan-activity;sid:84514622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651523/; classtype:trojan-activity;sid:84514623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-05-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651520/; classtype:trojan-activity;sid:84514620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-01-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651516/; classtype:trojan-activity;sid:84514616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-06-01/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651517/; classtype:trojan-activity;sid:84514617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2025-04-09/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651518/; classtype:trojan-activity;sid:84514618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-04-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651515/; classtype:trojan-activity;sid:84514615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-08-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651512/; classtype:trojan-activity;sid:84514612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2023-11-27/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651513/; classtype:trojan-activity;sid:84514613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-02-22/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651514/; classtype:trojan-activity;sid:84514614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-09-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651511/; classtype:trojan-activity;sid:84514611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2020-09-15/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651509/; classtype:trojan-activity;sid:84514609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-01-15/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651510/; classtype:trojan-activity;sid:84514610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-01-03/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651506/; classtype:trojan-activity;sid:84514606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-08-26/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651508/; classtype:trojan-activity;sid:84514608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-05-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651504/; classtype:trojan-activity;sid:84514604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2022-03-14/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651505/; classtype:trojan-activity;sid:84514605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-12-16/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651502/; classtype:trojan-activity;sid:84514602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-05-06/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651503/; classtype:trojan-activity;sid:84514603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"107.128.101.219"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651494/; classtype:trojan-activity;sid:84514594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"67.177.204.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651481/; classtype:trojan-activity;sid:84514581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"132.247.103.239"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651477/; classtype:trojan-activity;sid:84514577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"77.172.14.72"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651476/; classtype:trojan-activity;sid:84514576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/info.zip"; depth:18; endswith; nocase; http.host; content:"47.104.31.7"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651304/; classtype:trojan-activity;sid:84514404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"103.59.134.98"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651202/; classtype:trojan-activity;sid:84514302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000566431/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651195/; classtype:trojan-activity;sid:84514295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000225745/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651183/; classtype:trojan-activity;sid:84514283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000585574/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651168/; classtype:trojan-activity;sid:84514268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000567168/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651169/; classtype:trojan-activity;sid:84514269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171472/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651167/; classtype:trojan-activity;sid:84514267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170010/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651165/; classtype:trojan-activity;sid:84514265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-04-11/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651164/; classtype:trojan-activity;sid:84514264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651160/; classtype:trojan-activity;sid:84514260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651154/; classtype:trojan-activity;sid:84514254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165772/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651151/; classtype:trojan-activity;sid:84514251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-05-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651149/; classtype:trojan-activity;sid:84514249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170922/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651139/; classtype:trojan-activity;sid:84514239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000603094/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651135/; classtype:trojan-activity;sid:84514235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171064/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651136/; classtype:trojan-activity;sid:84514236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651127/; classtype:trojan-activity;sid:84514227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000603095/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651125/; classtype:trojan-activity;sid:84514225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-04-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651122/; classtype:trojan-activity;sid:84514222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-07-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651118/; classtype:trojan-activity;sid:84514218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171016/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651095/; classtype:trojan-activity;sid:84514195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-03-17/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651094/; classtype:trojan-activity;sid:84514194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000253230/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651090/; classtype:trojan-activity;sid:84514190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651086/; classtype:trojan-activity;sid:84514186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171252/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651088/; classtype:trojan-activity;sid:84514188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"132.247.103.239"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651084/; classtype:trojan-activity;sid:84514184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000189793/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651078/; classtype:trojan-activity;sid:84514178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-04-30/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651077/; classtype:trojan-activity;sid:84514177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"103.36.80.114"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651075/; classtype:trojan-activity;sid:84514175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604320/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651071/; classtype:trojan-activity;sid:84514171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000758/2024-05-31/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651061/; classtype:trojan-activity;sid:84514161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651056/; classtype:trojan-activity;sid:84514156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-01-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651044/; classtype:trojan-activity;sid:84514144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651040/; classtype:trojan-activity;sid:84514140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000232289/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651041/; classtype:trojan-activity;sid:84514141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000306/2021-01-13/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651037/; classtype:trojan-activity;sid:84514137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-12-01/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651033/; classtype:trojan-activity;sid:84514133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-11-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651022/; classtype:trojan-activity;sid:84514122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/mdf-e/info.zip"; depth:22; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651020/; classtype:trojan-activity;sid:84514120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000186186/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651016/; classtype:trojan-activity;sid:84514116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164262/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651012/; classtype:trojan-activity;sid:84514112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169167/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651015/; classtype:trojan-activity;sid:84514115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000683762/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651011/; classtype:trojan-activity;sid:84514111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-06-04/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651008/; classtype:trojan-activity;sid:84514108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168339/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651006/; classtype:trojan-activity;sid:84514106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168881/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650998/; classtype:trojan-activity;sid:84514098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000602407/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650995/; classtype:trojan-activity;sid:84514095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000626337/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650993/; classtype:trojan-activity;sid:84514093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-12-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650991/; classtype:trojan-activity;sid:84514091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000565438/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650986/; classtype:trojan-activity;sid:84514086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650977/; classtype:trojan-activity;sid:84514077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-12-27/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650976/; classtype:trojan-activity;sid:84514076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aspnet_client/info.zip"; depth:23; endswith; nocase; http.host; content:"96.11.145.107"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650970/; classtype:trojan-activity;sid:84514070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-09-11/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650969/; classtype:trojan-activity;sid:84514069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000619269/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650968/; classtype:trojan-activity;sid:84514068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169465/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650963/; classtype:trojan-activity;sid:84514063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-01-23/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650961/; classtype:trojan-activity;sid:84514061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160983/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650959/; classtype:trojan-activity;sid:84514059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000179610/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650958/; classtype:trojan-activity;sid:84514058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165004/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650955/; classtype:trojan-activity;sid:84514055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000600294/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650943/; classtype:trojan-activity;sid:84514043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000589083/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650940/; classtype:trojan-activity;sid:84514040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169469/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650939/; classtype:trojan-activity;sid:84514039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167445/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650934/; classtype:trojan-activity;sid:84514034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000608221/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650928/; classtype:trojan-activity;sid:84514028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168559/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650924/; classtype:trojan-activity;sid:84514024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000767154/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650915/; classtype:trojan-activity;sid:84514015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169966/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650912/; classtype:trojan-activity;sid:84514012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/info.zip"; depth:28; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650913/; classtype:trojan-activity;sid:84514013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000625892/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650902/; classtype:trojan-activity;sid:84514002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/app_error/info.zip"; depth:26; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650900/; classtype:trojan-activity;sid:84514000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160599/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650887/; classtype:trojan-activity;sid:84513987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166747/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650884/; classtype:trojan-activity;sid:84513984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171986/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650886/; classtype:trojan-activity;sid:84513986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000555504/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650880/; classtype:trojan-activity;sid:84513980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000765366/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650881/; classtype:trojan-activity;sid:84513981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604319/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650870/; classtype:trojan-activity;sid:84513970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171330/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650868/; classtype:trojan-activity;sid:84513968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650867/; classtype:trojan-activity;sid:84513967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650865/; classtype:trojan-activity;sid:84513965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650859/; classtype:trojan-activity;sid:84513959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000621738/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650856/; classtype:trojan-activity;sid:84513956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165010/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650855/; classtype:trojan-activity;sid:84513955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650854/; classtype:trojan-activity;sid:84513954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"94.203.254.14"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650851/; classtype:trojan-activity;sid:84513951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168303/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650850/; classtype:trojan-activity;sid:84513950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"68.148.10.182"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650846/; classtype:trojan-activity;sid:84513946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-09-13/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650840/; classtype:trojan-activity;sid:84513940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-03-24/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650836/; classtype:trojan-activity;sid:84513936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-06-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650833/; classtype:trojan-activity;sid:84513933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2021-04-01/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650828/; classtype:trojan-activity;sid:84513928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000391039/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650820/; classtype:trojan-activity;sid:84513920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000574637/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650818/; classtype:trojan-activity;sid:84513918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"64.234.95.70"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650810/; classtype:trojan-activity;sid:84513910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/df/normal/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650806/; classtype:trojan-activity;sid:84513906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000601712/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650791/; classtype:trojan-activity;sid:84513891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-06-25/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650781/; classtype:trojan-activity;sid:84513881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164804/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650779/; classtype:trojan-activity;sid:84513879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000591478/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650770/; classtype:trojan-activity;sid:84513870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165246/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650768/; classtype:trojan-activity;sid:84513868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000631756/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650748/; classtype:trojan-activity;sid:84513848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-04-15/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650746/; classtype:trojan-activity;sid:84513846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167557/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650744/; classtype:trojan-activity;sid:84513844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-10-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650742/; classtype:trojan-activity;sid:84513842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000232287/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650735/; classtype:trojan-activity;sid:84513835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000607873/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650729/; classtype:trojan-activity;sid:84513829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166887/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650726/; classtype:trojan-activity;sid:84513826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000162883/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650720/; classtype:trojan-activity;sid:84513820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000680913/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650719/; classtype:trojan-activity;sid:84513819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000625326/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650718/; classtype:trojan-activity;sid:84513818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167443/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650712/; classtype:trojan-activity;sid:84513812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"67.177.204.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650711/; classtype:trojan-activity;sid:84513811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-03-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650708/; classtype:trojan-activity;sid:84513808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650704/; classtype:trojan-activity;sid:84513804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000566429/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650703/; classtype:trojan-activity;sid:84513803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-01-14/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650701/; classtype:trojan-activity;sid:84513801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"77.211.28.150"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650698/; classtype:trojan-activity;sid:84513798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166105/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650693/; classtype:trojan-activity;sid:84513793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171466/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650690/; classtype:trojan-activity;sid:84513790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164836/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650689/; classtype:trojan-activity;sid:84513789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000758/2021-10-24/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650686/; classtype:trojan-activity;sid:84513786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165072/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650683/; classtype:trojan-activity;sid:84513783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-27/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650681/; classtype:trojan-activity;sid:84513781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000457040/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650678/; classtype:trojan-activity;sid:84513778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"103.8.164.18"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650679/; classtype:trojan-activity;sid:84513779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000218874/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650676/; classtype:trojan-activity;sid:84513776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171556/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650667/; classtype:trojan-activity;sid:84513767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000224647/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650664/; classtype:trojan-activity;sid:84513764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165656/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650665/; classtype:trojan-activity;sid:84513765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000603149/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650655/; classtype:trojan-activity;sid:84513755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650650/; classtype:trojan-activity;sid:84513750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-12-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650652/; classtype:trojan-activity;sid:84513752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171224/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650649/; classtype:trojan-activity;sid:84513749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000187451/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650640/; classtype:trojan-activity;sid:84513740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170836/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650638/; classtype:trojan-activity;sid:84513738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650635/; classtype:trojan-activity;sid:84513735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-06-04/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650633/; classtype:trojan-activity;sid:84513733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-05-04/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650631/; classtype:trojan-activity;sid:84513731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171296/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650622/; classtype:trojan-activity;sid:84513722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"88.28.218.163"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650616/; classtype:trojan-activity;sid:84513716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/info.zip"; depth:65; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650611/; classtype:trojan-activity;sid:84513711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604318/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650609/; classtype:trojan-activity;sid:84513709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-05-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650603/; classtype:trojan-activity;sid:84513703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-06/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650602/; classtype:trojan-activity;sid:84513702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000677/2024-06-19/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650600/; classtype:trojan-activity;sid:84513700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-06-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650598/; classtype:trojan-activity;sid:84513698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-10-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650596/; classtype:trojan-activity;sid:84513696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000426238/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650595/; classtype:trojan-activity;sid:84513695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-01-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650594/; classtype:trojan-activity;sid:84513694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-01-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650591/; classtype:trojan-activity;sid:84513691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"156.200.99.139"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650588/; classtype:trojan-activity;sid:84513688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172470/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650585/; classtype:trojan-activity;sid:84513685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168287/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650586/; classtype:trojan-activity;sid:84513686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000585436/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650575/; classtype:trojan-activity;sid:84513675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171288/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650573/; classtype:trojan-activity;sid:84513673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"14.224.205.246"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650570/; classtype:trojan-activity;sid:84513670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000176793/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650568/; classtype:trojan-activity;sid:84513668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000213545/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650569/; classtype:trojan-activity;sid:84513669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167279/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650565/; classtype:trojan-activity;sid:84513665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167437/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650561/; classtype:trojan-activity;sid:84513661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000606633/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650554/; classtype:trojan-activity;sid:84513654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167071/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650551/; classtype:trojan-activity;sid:84513651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-06-03/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650550/; classtype:trojan-activity;sid:84513650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172576/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650549/; classtype:trojan-activity;sid:84513649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/info.zip"; depth:32; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650541/; classtype:trojan-activity;sid:84513641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000306/2024-10-23/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650535/; classtype:trojan-activity;sid:84513635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650536/; classtype:trojan-activity;sid:84513636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171304/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650529/; classtype:trojan-activity;sid:84513629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-08-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650528/; classtype:trojan-activity;sid:84513628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-10-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650522/; classtype:trojan-activity;sid:84513622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-11-04/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650520/; classtype:trojan-activity;sid:84513620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-09-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650519/; classtype:trojan-activity;sid:84513619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-04-30/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650517/; classtype:trojan-activity;sid:84513617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000306/2020-11-19/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650513/; classtype:trojan-activity;sid:84513613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166971/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650512/; classtype:trojan-activity;sid:84513612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164808/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650508/; classtype:trojan-activity;sid:84513608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170482/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650504/; classtype:trojan-activity;sid:84513604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165644/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650506/; classtype:trojan-activity;sid:84513606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000264706/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650493/; classtype:trojan-activity;sid:84513593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000562134/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650494/; classtype:trojan-activity;sid:84513594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-12/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650495/; classtype:trojan-activity;sid:84513595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000680914/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650498/; classtype:trojan-activity;sid:84513598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169171/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650499/; classtype:trojan-activity;sid:84513599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"72.132.64.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650492/; classtype:trojan-activity;sid:84513592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/2023-11-28/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650491/; classtype:trojan-activity;sid:84513591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165020/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650482/; classtype:trojan-activity;sid:84513582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-11-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650483/; classtype:trojan-activity;sid:84513583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171284/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650480/; classtype:trojan-activity;sid:84513580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604651/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650472/; classtype:trojan-activity;sid:84513572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650467/; classtype:trojan-activity;sid:84513567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166079/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650465/; classtype:trojan-activity;sid:84513565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650466/; classtype:trojan-activity;sid:84513566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650461/; classtype:trojan-activity;sid:84513561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000601171/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650457/; classtype:trojan-activity;sid:84513557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-07-14/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650453/; classtype:trojan-activity;sid:84513553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000677/2024-01-02/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650454/; classtype:trojan-activity;sid:84513554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-10-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650452/; classtype:trojan-activity;sid:84513552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000159804/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650450/; classtype:trojan-activity;sid:84513550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000566428/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650443/; classtype:trojan-activity;sid:84513543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168305/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650441/; classtype:trojan-activity;sid:84513541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"185.8.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650442/; classtype:trojan-activity;sid:84513542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170516/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650439/; classtype:trojan-activity;sid:84513539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000163666/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650431/; classtype:trojan-activity;sid:84513531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000601753/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650430/; classtype:trojan-activity;sid:84513530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000629919/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650423/; classtype:trojan-activity;sid:84513523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000263120/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650422/; classtype:trojan-activity;sid:84513522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650419/; classtype:trojan-activity;sid:84513519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000237372/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650412/; classtype:trojan-activity;sid:84513512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"50.65.169.30"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650413/; classtype:trojan-activity;sid:84513513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-10-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650397/; classtype:trojan-activity;sid:84513497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000555505/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650390/; classtype:trojan-activity;sid:84513490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650388)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-05-19/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650388/; classtype:trojan-activity;sid:84513488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169865/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650386/; classtype:trojan-activity;sid:84513486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-06-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650385/; classtype:trojan-activity;sid:84513485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172466/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650383/; classtype:trojan-activity;sid:84513483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171312/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650381/; classtype:trojan-activity;sid:84513481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-15/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650375/; classtype:trojan-activity;sid:84513475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169769/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650374/; classtype:trojan-activity;sid:84513474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000573133/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650364/; classtype:trojan-activity;sid:84513464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000606636/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650366/; classtype:trojan-activity;sid:84513466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-01-30/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650370/; classtype:trojan-activity;sid:84513470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000546234/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650371/; classtype:trojan-activity;sid:84513471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"37.34.230.9"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650373/; classtype:trojan-activity;sid:84513473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000586306/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650362/; classtype:trojan-activity;sid:84513462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-31/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650363/; classtype:trojan-activity;sid:84513463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170378/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650358/; classtype:trojan-activity;sid:84513458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2025-01-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650356/; classtype:trojan-activity;sid:84513456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"71.198.110.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650351/; classtype:trojan-activity;sid:84513451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160995/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650348/; classtype:trojan-activity;sid:84513448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-11-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650347/; classtype:trojan-activity;sid:84513447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"93.43.53.67"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650343/; classtype:trojan-activity;sid:84513443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168278/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650337/; classtype:trojan-activity;sid:84513437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170774/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650338/; classtype:trojan-activity;sid:84513438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000633210/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650340/; classtype:trojan-activity;sid:84513440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000224648/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650331/; classtype:trojan-activity;sid:84513431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165504/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650332/; classtype:trojan-activity;sid:84513432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-01-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650326/; classtype:trojan-activity;sid:84513426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-09-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650327/; classtype:trojan-activity;sid:84513427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"138.36.2.110"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650319/; classtype:trojan-activity;sid:84513419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"5.89.102.77"; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650307/; classtype:trojan-activity;sid:84513407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"109.193.105.79"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650299/; classtype:trojan-activity;sid:84513399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166309/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650300/; classtype:trojan-activity;sid:84513400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650282/; classtype:trojan-activity;sid:84513382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-08-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650280/; classtype:trojan-activity;sid:84513380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650281/; classtype:trojan-activity;sid:84513381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650276)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000553612/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650276/; classtype:trojan-activity;sid:84513376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169947/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650270/; classtype:trojan-activity;sid:84513370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165200/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650271/; classtype:trojan-activity;sid:84513371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/mdf-e/01/consulta%20n%c3%a3o%20encerrado/info.zip"; depth:57; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650269/; classtype:trojan-activity;sid:84513369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"107.128.101.219"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650263/; classtype:trojan-activity;sid:84513363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-10-17/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650266/; classtype:trojan-activity;sid:84513366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/eventos/2021-02-16/info.zip"; depth:58; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650259/; classtype:trojan-activity;sid:84513359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168295/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650258/; classtype:trojan-activity;sid:84513358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000585560/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650253/; classtype:trojan-activity;sid:84513353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/2023-11-29/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650251/; classtype:trojan-activity;sid:84513351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604650/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650244/; classtype:trojan-activity;sid:84513344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604662/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650243/; classtype:trojan-activity;sid:84513343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-08-17/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650233/; classtype:trojan-activity;sid:84513333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-07-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650230/; classtype:trojan-activity;sid:84513330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168293/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650222/; classtype:trojan-activity;sid:84513322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2023-08-08/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650218/; classtype:trojan-activity;sid:84513318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000162637/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650215/; classtype:trojan-activity;sid:84513315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000600441/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650214/; classtype:trojan-activity;sid:84513314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000584368/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650213/; classtype:trojan-activity;sid:84513313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165935/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650201/; classtype:trojan-activity;sid:84513301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-11-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650196/; classtype:trojan-activity;sid:84513296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"103.209.67.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650193/; classtype:trojan-activity;sid:84513293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000179593/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650191/; classtype:trojan-activity;sid:84513291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-12-27/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650181/; classtype:trojan-activity;sid:84513281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000306/2024-06-03/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650178/; classtype:trojan-activity;sid:84513278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2023-11-09/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650176/; classtype:trojan-activity;sid:84513276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000222522/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650170/; classtype:trojan-activity;sid:84513270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650167/; classtype:trojan-activity;sid:84513267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166869/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650162/; classtype:trojan-activity;sid:84513262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000566150/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650160/; classtype:trojan-activity;sid:84513260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000546495/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650161/; classtype:trojan-activity;sid:84513261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-05-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650158/; classtype:trojan-activity;sid:84513258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-11-09/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650156/; classtype:trojan-activity;sid:84513256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164138/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650146/; classtype:trojan-activity;sid:84513246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/2023-12-22/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650138/; classtype:trojan-activity;sid:84513238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-01-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650139/; classtype:trojan-activity;sid:84513239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-09-03/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650136/; classtype:trojan-activity;sid:84513236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170520/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650130/; classtype:trojan-activity;sid:84513230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-10-19/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650129/; classtype:trojan-activity;sid:84513229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171256/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650127/; classtype:trojan-activity;sid:84513227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172428/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650123/; classtype:trojan-activity;sid:84513223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650124/; classtype:trojan-activity;sid:84513224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-01-09/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650126/; classtype:trojan-activity;sid:84513226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000553463/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650122/; classtype:trojan-activity;sid:84513222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000677/2023-11-14/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650117/; classtype:trojan-activity;sid:84513217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165900/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650118/; classtype:trojan-activity;sid:84513218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000566395/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650112/; classtype:trojan-activity;sid:84513212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171314/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650107/; classtype:trojan-activity;sid:84513207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000567163/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650104/; classtype:trojan-activity;sid:84513204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650101/; classtype:trojan-activity;sid:84513201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171298/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650093/; classtype:trojan-activity;sid:84513193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168275/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650092/; classtype:trojan-activity;sid:84513192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/2023-11-24/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650082/; classtype:trojan-activity;sid:84513182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166259/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650079/; classtype:trojan-activity;sid:84513179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165824/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650078/; classtype:trojan-activity;sid:84513178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/info.zip"; depth:16; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650071/; classtype:trojan-activity;sid:84513171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000600293/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650067/; classtype:trojan-activity;sid:84513167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-11-23/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650068/; classtype:trojan-activity;sid:84513168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000567166/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650058/; classtype:trojan-activity;sid:84513158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"70.95.233.160"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650061/; classtype:trojan-activity;sid:84513161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-08-25/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650056/; classtype:trojan-activity;sid:84513156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000567145/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650051/; classtype:trojan-activity;sid:84513151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-05-04/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650047/; classtype:trojan-activity;sid:84513147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-03-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650048/; classtype:trojan-activity;sid:84513148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"111.235.143.155"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650044/; classtype:trojan-activity;sid:84513144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167243/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650036/; classtype:trojan-activity;sid:84513136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169473/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650028/; classtype:trojan-activity;sid:84513128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171454/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650026/; classtype:trojan-activity;sid:84513126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170532/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650023/; classtype:trojan-activity;sid:84513123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-16/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650019/; classtype:trojan-activity;sid:84513119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000543689/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650004/; classtype:trojan-activity;sid:84513104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000633209/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650001/; classtype:trojan-activity;sid:84513101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-04-05/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649997/; classtype:trojan-activity;sid:84513097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000546233/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649996/; classtype:trojan-activity;sid:84513096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000173466/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649995/; classtype:trojan-activity;sid:84513095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000585575/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649992/; classtype:trojan-activity;sid:84513092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-10-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649985/; classtype:trojan-activity;sid:84513085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171194/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649986/; classtype:trojan-activity;sid:84513086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172163/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649987/; classtype:trojan-activity;sid:84513087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-08-05/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649988/; classtype:trojan-activity;sid:84513088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"160.202.15.212"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649984/; classtype:trojan-activity;sid:84513084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000586961/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649980/; classtype:trojan-activity;sid:84513080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000609592/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649981/; classtype:trojan-activity;sid:84513081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"27.72.159.162"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649975/; classtype:trojan-activity;sid:84513075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-09-30/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649970/; classtype:trojan-activity;sid:84513070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"107.128.101.219"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649968/; classtype:trojan-activity;sid:84513068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649963/; classtype:trojan-activity;sid:84513063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-02-09/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649961/; classtype:trojan-activity;sid:84513061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172788/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649959/; classtype:trojan-activity;sid:84513059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000237371/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649956/; classtype:trojan-activity;sid:84513056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000552709/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649952/; classtype:trojan-activity;sid:84513052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168509/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649944/; classtype:trojan-activity;sid:84513044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000683761/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649943/; classtype:trojan-activity;sid:84513043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000567164/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649932/; classtype:trojan-activity;sid:84513032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171888/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649930/; classtype:trojan-activity;sid:84513030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165116/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649931/; classtype:trojan-activity;sid:84513031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-07-16/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649929/; classtype:trojan-activity;sid:84513029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000208170/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649923/; classtype:trojan-activity;sid:84513023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000264645/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649919/; classtype:trojan-activity;sid:84513019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-11-09/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649916/; classtype:trojan-activity;sid:84513016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2022-08-19/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649914/; classtype:trojan-activity;sid:84513014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-12-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649913/; classtype:trojan-activity;sid:84513013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171458/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649910/; classtype:trojan-activity;sid:84513010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-11-28/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649908/; classtype:trojan-activity;sid:84513008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-10-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649904/; classtype:trojan-activity;sid:84513004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000617432/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649900/; classtype:trojan-activity;sid:84513000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-08-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649897/; classtype:trojan-activity;sid:84512997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2023-06-22/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649898/; classtype:trojan-activity;sid:84512998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-04-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649899/; classtype:trojan-activity;sid:84512999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000624762/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649896/; classtype:trojan-activity;sid:84512996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000265247/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649895/; classtype:trojan-activity;sid:84512995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165014/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649888/; classtype:trojan-activity;sid:84512988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165090/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649885/; classtype:trojan-activity;sid:84512985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168749/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649886/; classtype:trojan-activity;sid:84512986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172574/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649884/; classtype:trojan-activity;sid:84512984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167339/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649881/; classtype:trojan-activity;sid:84512981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000212326/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649878/; classtype:trojan-activity;sid:84512978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000603747/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649874/; classtype:trojan-activity;sid:84512974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000746890/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649870/; classtype:trojan-activity;sid:84512970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160628/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649867/; classtype:trojan-activity;sid:84512967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171452/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649868/; classtype:trojan-activity;sid:84512968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-06-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649869/; classtype:trojan-activity;sid:84512969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164253/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649864/; classtype:trojan-activity;sid:84512964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000426237/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649863/; classtype:trojan-activity;sid:84512963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-08-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649858/; classtype:trojan-activity;sid:84512958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2023-07-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649849/; classtype:trojan-activity;sid:84512949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-04-02/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649848/; classtype:trojan-activity;sid:84512948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-03-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649840/; classtype:trojan-activity;sid:84512940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170894/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649839/; classtype:trojan-activity;sid:84512939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"70.190.199.152"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649837/; classtype:trojan-activity;sid:84512937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171742/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649833/; classtype:trojan-activity;sid:84512933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171248/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649821/; classtype:trojan-activity;sid:84512921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-02-04/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649812/; classtype:trojan-activity;sid:84512912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-07-08/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649811/; classtype:trojan-activity;sid:84512911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-03-17/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649806/; classtype:trojan-activity;sid:84512906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000465109/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649801/; classtype:trojan-activity;sid:84512901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-02-04/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649793/; classtype:trojan-activity;sid:84512893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172568/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649790/; classtype:trojan-activity;sid:84512890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2021-07-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649788/; classtype:trojan-activity;sid:84512888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000226537/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649783/; classtype:trojan-activity;sid:84512883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000306/2022-02-16/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649780/; classtype:trojan-activity;sid:84512880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166135/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649771/; classtype:trojan-activity;sid:84512871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-06-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649768/; classtype:trojan-activity;sid:84512868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000583935/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649762/; classtype:trojan-activity;sid:84512862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171246/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649761/; classtype:trojan-activity;sid:84512861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165999/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649751/; classtype:trojan-activity;sid:84512851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649745/; classtype:trojan-activity;sid:84512845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/2024-07-06/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649738/; classtype:trojan-activity;sid:84512838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000557542/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649730/; classtype:trojan-activity;sid:84512830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167115/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649731/; classtype:trojan-activity;sid:84512831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"178.61.160.6"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649707/; classtype:trojan-activity;sid:84512807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168301/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649699/; classtype:trojan-activity;sid:84512799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171474/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649701/; classtype:trojan-activity;sid:84512801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167423/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649692/; classtype:trojan-activity;sid:84512792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-05-04/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649687/; classtype:trojan-activity;sid:84512787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"87.249.142.126"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649685/; classtype:trojan-activity;sid:84512785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"222.252.31.94"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649682/; classtype:trojan-activity;sid:84512782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171702/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649681/; classtype:trojan-activity;sid:84512781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171468/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649677/; classtype:trojan-activity;sid:84512777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"96.11.145.107"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649676/; classtype:trojan-activity;sid:84512776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000230418/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649673/; classtype:trojan-activity;sid:84512773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166739/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649674/; classtype:trojan-activity;sid:84512774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-11-21/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649672/; classtype:trojan-activity;sid:84512772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000552326/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649669/; classtype:trojan-activity;sid:84512769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-04-29/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649656/; classtype:trojan-activity;sid:84512756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169927/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649655/; classtype:trojan-activity;sid:84512755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-09-10/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649654/; classtype:trojan-activity;sid:84512754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000543908/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649647/; classtype:trojan-activity;sid:84512747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-10-19/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649641/; classtype:trojan-activity;sid:84512741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172094/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649643/; classtype:trojan-activity;sid:84512743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000542543/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649644/; classtype:trojan-activity;sid:84512744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000162506/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649635/; classtype:trojan-activity;sid:84512735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171302/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649622/; classtype:trojan-activity;sid:84512722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166801/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649626/; classtype:trojan-activity;sid:84512726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-02-11/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649616/; classtype:trojan-activity;sid:84512716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160981/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649613/; classtype:trojan-activity;sid:84512713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000551812/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649607/; classtype:trojan-activity;sid:84512707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649601/; classtype:trojan-activity;sid:84512701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-12-08/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649602/; classtype:trojan-activity;sid:84512702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2023-03-10/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649590/; classtype:trojan-activity;sid:84512690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-12-14/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649592/; classtype:trojan-activity;sid:84512692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168299/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649576/; classtype:trojan-activity;sid:84512676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167451/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649577/; classtype:trojan-activity;sid:84512677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160619/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649573/; classtype:trojan-activity;sid:84512673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171294/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649574/; classtype:trojan-activity;sid:84512674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171316/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649572/; classtype:trojan-activity;sid:84512672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2020-08-27/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649570/; classtype:trojan-activity;sid:84512670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000223168/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649567/; classtype:trojan-activity;sid:84512667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168281/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649556/; classtype:trojan-activity;sid:84512656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171358/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649549/; classtype:trojan-activity;sid:84512649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167601/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649551/; classtype:trojan-activity;sid:84512651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000758/2024-06-06/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649552/; classtype:trojan-activity;sid:84512652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aspnet_client/system_web/info.zip"; depth:34; endswith; nocase; http.host; content:"96.11.145.107"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649546/; classtype:trojan-activity;sid:84512646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166323/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649533/; classtype:trojan-activity;sid:84512633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649532)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000732234/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649532/; classtype:trojan-activity;sid:84512632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000223167/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649528/; classtype:trojan-activity;sid:84512628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000584370/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649521/; classtype:trojan-activity;sid:84512621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000583934/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649517/; classtype:trojan-activity;sid:84512617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165844/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649514/; classtype:trojan-activity;sid:84512614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165184/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649503/; classtype:trojan-activity;sid:84512603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649501/; classtype:trojan-activity;sid:84512601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/df/info.zip"; depth:55; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649498/; classtype:trojan-activity;sid:84512598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649493/; classtype:trojan-activity;sid:84512593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168365/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649492/; classtype:trojan-activity;sid:84512592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-03-26/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649489/; classtype:trojan-activity;sid:84512589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-12-11/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649490/; classtype:trojan-activity;sid:84512590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-07-29/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649485/; classtype:trojan-activity;sid:84512585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000209999/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649483/; classtype:trojan-activity;sid:84512583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-09/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649481/; classtype:trojan-activity;sid:84512581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-03-26/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649471/; classtype:trojan-activity;sid:84512571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164122/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649468/; classtype:trojan-activity;sid:84512568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000567165/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649459/; classtype:trojan-activity;sid:84512559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171854/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649455/; classtype:trojan-activity;sid:84512555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-05-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649449/; classtype:trojan-activity;sid:84512549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-06-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649446/; classtype:trojan-activity;sid:84512546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604321/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649440/; classtype:trojan-activity;sid:84512540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-09/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649436/; classtype:trojan-activity;sid:84512536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160615/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649424/; classtype:trojan-activity;sid:84512524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171250/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649418/; classtype:trojan-activity;sid:84512518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-03-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649417/; classtype:trojan-activity;sid:84512517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165250/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649416/; classtype:trojan-activity;sid:84512516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-01-10/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649415/; classtype:trojan-activity;sid:84512515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171286/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649414/; classtype:trojan-activity;sid:84512514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-18/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649410/; classtype:trojan-activity;sid:84512510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171402/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649406/; classtype:trojan-activity;sid:84512506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000758/2021-05-08/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649397/; classtype:trojan-activity;sid:84512497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-08-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649395/; classtype:trojan-activity;sid:84512495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171478/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649392/; classtype:trojan-activity;sid:84512492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168553/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649389/; classtype:trojan-activity;sid:84512489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-08-22/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649391/; classtype:trojan-activity;sid:84512491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171462/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649387/; classtype:trojan-activity;sid:84512487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/2023-12-12/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649385/; classtype:trojan-activity;sid:84512485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/1/info.zip"; depth:23; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649382/; classtype:trojan-activity;sid:84512482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000606635/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649379/; classtype:trojan-activity;sid:84512479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000238203/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649377/; classtype:trojan-activity;sid:84512477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2019-12-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649375/; classtype:trojan-activity;sid:84512475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171242/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649372/; classtype:trojan-activity;sid:84512472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/info.zip"; depth:21; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649370/; classtype:trojan-activity;sid:84512470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171464/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649365/; classtype:trojan-activity;sid:84512465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-07-30/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649366/; classtype:trojan-activity;sid:84512466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171332/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649360/; classtype:trojan-activity;sid:84512460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166237/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649357/; classtype:trojan-activity;sid:84512457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165850/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649354/; classtype:trojan-activity;sid:84512454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000213544/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649353/; classtype:trojan-activity;sid:84512453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000265246/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649346/; classtype:trojan-activity;sid:84512446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blog/info.zip"; depth:14; endswith; nocase; http.host; content:"96.11.145.107"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649341/; classtype:trojan-activity;sid:84512441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-06-13/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649338/; classtype:trojan-activity;sid:84512438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-08-11/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649337/; classtype:trojan-activity;sid:84512437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000587212/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649335/; classtype:trojan-activity;sid:84512435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649332)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172165/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649332/; classtype:trojan-activity;sid:84512432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-09-09/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649333/; classtype:trojan-activity;sid:84512433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165794/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649329/; classtype:trojan-activity;sid:84512429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000173022/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649326/; classtype:trojan-activity;sid:84512426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/ct-e/distribui%c3%a7%c3%a3o/info.zip"; depth:44; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649321/; classtype:trojan-activity;sid:84512421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000677/2023-11-20/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649323/; classtype:trojan-activity;sid:84512423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000566420/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649310/; classtype:trojan-activity;sid:84512410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000567141/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649309/; classtype:trojan-activity;sid:84512409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000215215/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649306/; classtype:trojan-activity;sid:84512406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000562903/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649303/; classtype:trojan-activity;sid:84512403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-12-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649300/; classtype:trojan-activity;sid:84512400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000567162/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649295/; classtype:trojan-activity;sid:84512395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168063/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649278/; classtype:trojan-activity;sid:84512378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649265/; classtype:trojan-activity;sid:84512365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-04-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649263/; classtype:trojan-activity;sid:84512363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-05-13/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649262/; classtype:trojan-activity;sid:84512362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000558592/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649250/; classtype:trojan-activity;sid:84512350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2024-06-06/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649252/; classtype:trojan-activity;sid:84512352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-05-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649243/; classtype:trojan-activity;sid:84512343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-06-24/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649240/; classtype:trojan-activity;sid:84512340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649241/; classtype:trojan-activity;sid:84512341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-01-27/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649237/; classtype:trojan-activity;sid:84512337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-15/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649224/; classtype:trojan-activity;sid:84512324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-05-19/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649206/; classtype:trojan-activity;sid:84512306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-06/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649197/; classtype:trojan-activity;sid:84512297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000600544/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649193/; classtype:trojan-activity;sid:84512293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-08-05/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649188/; classtype:trojan-activity;sid:84512288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165480/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649189/; classtype:trojan-activity;sid:84512289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000564863/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649180/; classtype:trojan-activity;sid:84512280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-01-19/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649183/; classtype:trojan-activity;sid:84512283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-01-10/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649177/; classtype:trojan-activity;sid:84512277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000162652/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649173/; classtype:trojan-activity;sid:84512273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166657/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649158/; classtype:trojan-activity;sid:84512258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-05-04/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649155/; classtype:trojan-activity;sid:84512255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000625429/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649149/; classtype:trojan-activity;sid:84512249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000600309/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649145/; classtype:trojan-activity;sid:84512245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000556239/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649143/; classtype:trojan-activity;sid:84512243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000765367/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649144/; classtype:trojan-activity;sid:84512244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000625325/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649142/; classtype:trojan-activity;sid:84512242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000306/2021-11-14/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649137/; classtype:trojan-activity;sid:84512237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649134/; classtype:trojan-activity;sid:84512234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/1/9929/info.zip"; depth:28; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649135/; classtype:trojan-activity;sid:84512235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171244/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649130/; classtype:trojan-activity;sid:84512230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/info.zip"; depth:52; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649128/; classtype:trojan-activity;sid:84512228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-02-11/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649125/; classtype:trojan-activity;sid:84512225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-20/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649123/; classtype:trojan-activity;sid:84512223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168297/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649124/; classtype:trojan-activity;sid:84512224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-07-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649120/; classtype:trojan-activity;sid:84512220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168387/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649118/; classtype:trojan-activity;sid:84512218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000606634/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649119/; classtype:trojan-activity;sid:84512219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000551813/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649110/; classtype:trojan-activity;sid:84512210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2019-03-13/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649111/; classtype:trojan-activity;sid:84512211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164394/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649112/; classtype:trojan-activity;sid:84512212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166665/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649107/; classtype:trojan-activity;sid:84512207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000224583/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649108/; classtype:trojan-activity;sid:84512208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170506/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649099/; classtype:trojan-activity;sid:84512199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-07-01/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649092/; classtype:trojan-activity;sid:84512192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/2022-03-09/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649089/; classtype:trojan-activity;sid:84512189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000591279/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649084/; classtype:trojan-activity;sid:84512184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165248/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649080/; classtype:trojan-activity;sid:84512180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000225746/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649078/; classtype:trojan-activity;sid:84512178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-10-09/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649068/; classtype:trojan-activity;sid:84512168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166183/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649061/; classtype:trojan-activity;sid:84512161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-05-07/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649062/; classtype:trojan-activity;sid:84512162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000616852/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649055/; classtype:trojan-activity;sid:84512155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-07-05/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649056/; classtype:trojan-activity;sid:84512156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-01-27/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649050/; classtype:trojan-activity;sid:84512150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-07-18/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649043/; classtype:trojan-activity;sid:84512143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000170776/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649033/; classtype:trojan-activity;sid:84512133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160612/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649034/; classtype:trojan-activity;sid:84512134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000306/2020-12-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649035/; classtype:trojan-activity;sid:84512135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/info.zip"; depth:80; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649037/; classtype:trojan-activity;sid:84512137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171306/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649027/; classtype:trojan-activity;sid:84512127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160718/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649028/; classtype:trojan-activity;sid:84512128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604673/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649029/; classtype:trojan-activity;sid:84512129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-06-02/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649030/; classtype:trojan-activity;sid:84512130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649018/; classtype:trojan-activity;sid:84512118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-04-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649020/; classtype:trojan-activity;sid:84512120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164236/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649021/; classtype:trojan-activity;sid:84512121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171640/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649012/; classtype:trojan-activity;sid:84512112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000586305/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649003/; classtype:trojan-activity;sid:84512103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/18296147000306/2024-08-07/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648998/; classtype:trojan-activity;sid:84512098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166851/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648995/; classtype:trojan-activity;sid:84512095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791001053/info.zip"; depth:80; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648997/; classtype:trojan-activity;sid:84512097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000553613/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648988/; classtype:trojan-activity;sid:84512088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-04-05/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648986/; classtype:trojan-activity;sid:84512086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-05-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648978/; classtype:trojan-activity;sid:84512078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172670/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648972/; classtype:trojan-activity;sid:84512072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000164510/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648973/; classtype:trojan-activity;sid:84512073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-09-16/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648964/; classtype:trojan-activity;sid:84512064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167219/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648966/; classtype:trojan-activity;sid:84512066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-05-02/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648960/; classtype:trojan-activity;sid:84512060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171308/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648957/; classtype:trojan-activity;sid:84512057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000556238/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648956/; classtype:trojan-activity;sid:84512056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171858/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648954/; classtype:trojan-activity;sid:84512054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-04-29/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648955/; classtype:trojan-activity;sid:84512055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/02589791000910/2023-12-21/info.zip"; depth:91; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648953/; classtype:trojan-activity;sid:84512053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160742/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648952/; classtype:trojan-activity;sid:84512052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-11-11/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648949/; classtype:trojan-activity;sid:84512049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2022-09-09/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648938/; classtype:trojan-activity;sid:84512038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648939/; classtype:trojan-activity;sid:84512039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000629918/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648941/; classtype:trojan-activity;sid:84512041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta%20nsu%20faltante/18296147000306/info.zip"; depth:80; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648942/; classtype:trojan-activity;sid:84512042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/disponibilidade%20de%20servi%c3%a7o/es/info.zip"; depth:55; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648943/; classtype:trojan-activity;sid:84512043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000566149/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648936/; classtype:trojan-activity;sid:84512036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168121/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648933/; classtype:trojan-activity;sid:84512033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165244/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648926/; classtype:trojan-activity;sid:84512026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-06-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648930/; classtype:trojan-activity;sid:84512030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-03-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648931/; classtype:trojan-activity;sid:84512031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000226538/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648921/; classtype:trojan-activity;sid:84512021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-04-16/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648917/; classtype:trojan-activity;sid:84512017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000201084/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648912/; classtype:trojan-activity;sid:84512012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-09-27/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648904/; classtype:trojan-activity;sid:84512004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168527/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648900/; classtype:trojan-activity;sid:84512000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2024-06-07/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648893/; classtype:trojan-activity;sid:84511993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167509/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648891/; classtype:trojan-activity;sid:84511991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171476/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648889/; classtype:trojan-activity;sid:84511989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168551/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648884/; classtype:trojan-activity;sid:84511984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165820/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648885/; classtype:trojan-activity;sid:84511985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000603104/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648886/; classtype:trojan-activity;sid:84511986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-09-21/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648887/; classtype:trojan-activity;sid:84511987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166085/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648872/; classtype:trojan-activity;sid:84511972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171292/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648877/; classtype:trojan-activity;sid:84511977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-12-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648871/; classtype:trojan-activity;sid:84511971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165486/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648868/; classtype:trojan-activity;sid:84511968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-05/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648862/; classtype:trojan-activity;sid:84511962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000169013/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648858/; classtype:trojan-activity;sid:84511958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160982/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648854/; classtype:trojan-activity;sid:84511954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000618093/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648852/; classtype:trojan-activity;sid:84511952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000165826/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648849/; classtype:trojan-activity;sid:84511949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-02-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648835/; classtype:trojan-activity;sid:84511935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000591547/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648832/; classtype:trojan-activity;sid:84511932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000595438/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648828/; classtype:trojan-activity;sid:84511928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000621599/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648824/; classtype:trojan-activity;sid:84511924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171450/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648825/; classtype:trojan-activity;sid:84511925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166307/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648819/; classtype:trojan-activity;sid:84511919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-09-11/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648820/; classtype:trojan-activity;sid:84511920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171228/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648811/; classtype:trojan-activity;sid:84511911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171470/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648805/; classtype:trojan-activity;sid:84511905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172170/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648802/; classtype:trojan-activity;sid:84511902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000595439/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648798/; classtype:trojan-activity;sid:84511898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-03-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648794/; classtype:trojan-activity;sid:84511894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/info.zip"; depth:21; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648791/; classtype:trojan-activity;sid:84511891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000625549/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648788/; classtype:trojan-activity;sid:84511888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2020-01-03/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648785/; classtype:trojan-activity;sid:84511885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168291/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648781/; classtype:trojan-activity;sid:84511881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171318/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648771/; classtype:trojan-activity;sid:84511871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/recep%c3%a7%c3%a3o/2019-05-08/info.zip"; depth:49; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648759/; classtype:trojan-activity;sid:84511859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000602408/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648758/; classtype:trojan-activity;sid:84511858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-12-09/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648754/; classtype:trojan-activity;sid:84511854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000553198/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648755/; classtype:trojan-activity;sid:84511855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172872/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648750/; classtype:trojan-activity;sid:84511850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160984/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648746/; classtype:trojan-activity;sid:84511846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2019-12-19/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648740/; classtype:trojan-activity;sid:84511840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-05-22/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648736/; classtype:trojan-activity;sid:84511836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160478/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648737/; classtype:trojan-activity;sid:84511837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000166243/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648725/; classtype:trojan-activity;sid:84511825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000585561/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648722/; classtype:trojan-activity;sid:84511822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-06-04/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648712/; classtype:trojan-activity;sid:84511812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2023-08-23/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648709/; classtype:trojan-activity;sid:84511809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172746/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648710/; classtype:trojan-activity;sid:84511810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-11-12/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648707/; classtype:trojan-activity;sid:84511807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-05-09/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648706/; classtype:trojan-activity;sid:84511806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171310/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648700/; classtype:trojan-activity;sid:84511800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-08-08/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648702/; classtype:trojan-activity;sid:84511802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172292/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648698/; classtype:trojan-activity;sid:84511798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-06-08/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648696/; classtype:trojan-activity;sid:84511796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000542542/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648693/; classtype:trojan-activity;sid:84511793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000160618/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648692/; classtype:trojan-activity;sid:84511792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-06-16/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648691/; classtype:trojan-activity;sid:84511791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-11-16/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648688/; classtype:trojan-activity;sid:84511788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000624761/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648689/; classtype:trojan-activity;sid:84511789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2025-01-06/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648690/; classtype:trojan-activity;sid:84511790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168329/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648686/; classtype:trojan-activity;sid:84511786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000167041/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648682/; classtype:trojan-activity;sid:84511782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-11-30/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648684/; classtype:trojan-activity;sid:84511784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-02-23/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648677/; classtype:trojan-activity;sid:84511777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000624984/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648670/; classtype:trojan-activity;sid:84511770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000566430/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648672/; classtype:trojan-activity;sid:84511772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604501/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648669/; classtype:trojan-activity;sid:84511769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171438/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648655/; classtype:trojan-activity;sid:84511755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000230417/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648657/; classtype:trojan-activity;sid:84511757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648652/; classtype:trojan-activity;sid:84511752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2021-11-12/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648643/; classtype:trojan-activity;sid:84511743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000604491/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648637/; classtype:trojan-activity;sid:84511737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2022-12-27/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648634/; classtype:trojan-activity;sid:84511734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-07-06/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648627/; classtype:trojan-activity;sid:84511727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000585614/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648630/; classtype:trojan-activity;sid:84511730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-01-08/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648631/; classtype:trojan-activity;sid:84511731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-30/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648632/; classtype:trojan-activity;sid:84511732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/mdf-e/01/info.zip"; depth:25; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648623/; classtype:trojan-activity;sid:84511723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/carta%20de%20corre%c3%a7%c3%a3o/2024-03-20/info.zip"; depth:62; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648625/; classtype:trojan-activity;sid:84511725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2021-06-30/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648604/; classtype:trojan-activity;sid:84511704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-05-10/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648606/; classtype:trojan-activity;sid:84511706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2019-03-26/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648600/; classtype:trojan-activity;sid:84511700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2020-03-02/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648596/; classtype:trojan-activity;sid:84511696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000168289/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648592/; classtype:trojan-activity;sid:84511692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/consulta/2021-06-22/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648589/; classtype:trojan-activity;sid:84511689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171240/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648590/; classtype:trojan-activity;sid:84511690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/inutiliza%c3%a7%c3%a3o/2020-02-12/info.zip"; depth:53; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648583/; classtype:trojan-activity;sid:84511683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000600290/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648568/; classtype:trojan-activity;sid:84511668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000172690/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648571/; classtype:trojan-activity;sid:84511671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/01/cancelamento/2022-08-24/info.zip"; depth:43; endswith; nocase; http.host; content:"177.70.102.232"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648563/; classtype:trojan-activity;sid:84511663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000624763/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648558/; classtype:trojan-activity;sid:84511658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/manifesta%c3%a7%c3%a3o/consulta/02589791000758/2019-08-24/info.zip"; depth:74; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648561/; classtype:trojan-activity;sid:84511661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/td00000000000000171726/info.zip"; depth:39; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648562/; classtype:trojan-activity;sid:84511662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/my%20pictures/info.zip"; depth:142; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648527/; classtype:trojan-activity;sid:84511627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/my%20received%20files/vinod982038189896/info.zip"; depth:168; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648357/; classtype:trojan-activity;sid:84511457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/desktop/transchart/unused%20desktop%20shortcuts/info.zip"; depth:161; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648354/; classtype:trojan-activity;sid:84511454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/downloads/info.zip"; depth:138; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648213/; classtype:trojan-activity;sid:84511313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3648112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/my%20received%20files/vinod982038189896/history/info.zip"; depth:176; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3648112/; classtype:trojan-activity;sid:84511212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/symantec/info.zip"; depth:137; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647944/; classtype:trojan-activity;sid:84511044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/raj%20sir/info.zip"; depth:138; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647826/; classtype:trojan-activity;sid:84510926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/desktop/transchart/info.zip"; depth:132; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647813/; classtype:trojan-activity;sid:84510913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/desktop/transchart/sail%20performa%20jan11/info.zip"; depth:156; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647655/; classtype:trojan-activity;sid:84510755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/fresh%20circulation%20list/info.zip"; depth:94; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647641/; classtype:trojan-activity;sid:84510741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/sail%20empanelment/info.zip"; depth:86; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647583/; classtype:trojan-activity;sid:84510683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.220.234.5"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647513/; classtype:trojan-activity;sid:84510613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/recipes/staging/a-89fb7017-7780-4b72-950d-c2db1146a34a.exe"; depth:59; endswith; nocase; http.host; content:"best10cdn.blob.core.windows.net"; depth:31; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647457/; classtype:trojan-activity;sid:84510557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3646414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/storage/v1/object/public/nano/image.jpg|3f|12711343"; depth:52; endswith; nocase; http.host; content:"ybgctdtbzvgpdxjivafy.supabase.co"; depth:32; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3646414/; classtype:trojan-activity;sid:84509514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3646403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/storage/v1/object/public/hold/image.jpg|3f|12711343h"; depth:53; endswith; nocase; http.host; content:"ihmmkvkaiwnilneauhfn.supabase.co"; depth:32; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3646403/; classtype:trojan-activity;sid:84509503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3646408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/jqqvlru0vaih3z.exe"; depth:25; endswith; nocase; http.host; content:"toolshare.com.tr"; depth:16; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3646408/; classtype:trojan-activity;sid:84509508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"www.intelligradeeducation.vicentecisnerospub.com"; depth:48; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645950/; classtype:trojan-activity;sid:84509050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/my%20pictures/neha%20imagecopy/info.zip"; depth:159; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645889/; classtype:trojan-activity;sid:84508989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"66.185.26.66"; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645874/; classtype:trojan-activity;sid:84508974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/wallpaper/info.zip"; depth:138; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645854/; classtype:trojan-activity;sid:84508954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/my%20music/info.zip"; depth:139; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645847/; classtype:trojan-activity;sid:84508947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/my%20scans/info.zip"; depth:139; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645832/; classtype:trojan-activity;sid:84508932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/my%20received%20files/info.zip"; depth:150; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645827/; classtype:trojan-activity;sid:84508927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/desktop/various%20files/info.zip"; depth:137; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645760/; classtype:trojan-activity;sid:84508860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/charter%20party/info.zip"; depth:144; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645751/; classtype:trojan-activity;sid:84508851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/desktop/bhushan/info.zip"; depth:129; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645677/; classtype:trojan-activity;sid:84508777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/microsoft/windows/powershell/info.zip"; depth:38; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645600/; classtype:trojan-activity;sid:84508700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/info.zip"; depth:113; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645569/; classtype:trojan-activity;sid:84508669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/deepak/info.zip"; depth:49; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645513/; classtype:trojan-activity;sid:84508613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/charter%20parties/aqaba%20jan%202014/info.zip"; depth:79; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645345/; classtype:trojan-activity;sid:84508445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/desktop/tai%20ping%20shan-phaethon-cp/info.zip"; depth:105; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645322/; classtype:trojan-activity;sid:84508422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/desktop/info.zip"; depth:75; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645247/; classtype:trojan-activity;sid:84508347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/cp%20transchart/info.zip"; depth:121; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645234/; classtype:trojan-activity;sid:84508334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/my%20documents/info.zip"; depth:128; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645139/; classtype:trojan-activity;sid:84508239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/backgrounds/aquavita/info.zip"; depth:63; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645130/; classtype:trojan-activity;sid:84508230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/akij%20glory%20cp/info.zip"; depth:60; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644884/; classtype:trojan-activity;sid:84507984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/10-6-13/desktop/info.zip"; depth:121; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644784/; classtype:trojan-activity;sid:84507884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/adnatco%20sulphur%20coa/info.zip"; depth:66; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644779/; classtype:trojan-activity;sid:84507879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/backgrounds/info.zip"; depth:54; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644564/; classtype:trojan-activity;sid:84507664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/reliance%20and%20airtel%20%20bills/info.zip"; depth:102; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644422/; classtype:trojan-activity;sid:84507522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/info.zip"; depth:105; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644339/; classtype:trojan-activity;sid:84507439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/info.zip"; depth:77; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644286/; classtype:trojan-activity;sid:84507386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/info.zip"; depth:49; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644169/; classtype:trojan-activity;sid:84507269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/rcf/info.zip"; depth:71; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644134/; classtype:trojan-activity;sid:84507234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/rinl%20empanelment/info.zip"; depth:86; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644127/; classtype:trojan-activity;sid:84507227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/crown%20voyager%20norvic/info.zip"; depth:67; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644040/; classtype:trojan-activity;sid:84507140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3644002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/umesh/info.zip"; depth:73; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3644002/; classtype:trojan-activity;sid:84507102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/backgrounds/precious%20charm/info.zip"; depth:71; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643969/; classtype:trojan-activity;sid:84507069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/charter%20parties/tai%20ping%20shan-phaethon-cp/info.zip"; depth:90; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643934/; classtype:trojan-activity;sid:84507034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/charter%20parties/info.zip"; depth:60; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643868/; classtype:trojan-activity;sid:84506968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/work/desktop/info.zip"; depth:80; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643843/; classtype:trojan-activity;sid:84506943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/deepak/daily%20report/info.zip"; depth:64; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643828/; classtype:trojan-activity;sid:84506928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/charter%20parties/d.maritime/info.zip"; depth:71; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643820/; classtype:trojan-activity;sid:84506920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/backgrounds/asan%20mm/info.zip"; depth:64; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643786/; classtype:trojan-activity;sid:84506886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/short%20terms%20for%20govt%20chrtrs/info.zip"; depth:103; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643658/; classtype:trojan-activity;sid:84506758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/desktop/aryacorp/info.zip"; depth:84; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643417/; classtype:trojan-activity;sid:84506517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/circulation%20list/info.zip"; depth:61; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643392/; classtype:trojan-activity;sid:84506492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/work/info.zip"; depth:72; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643163/; classtype:trojan-activity;sid:84506263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/10.6.2013/jain%20sir%20data%20desktop/for%20xp%20sp2/info.zip"; depth:120; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643147/; classtype:trojan-activity;sid:84506247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/info.zip"; depth:67; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643118/; classtype:trojan-activity;sid:84506218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3643033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/charter%20parties/china%20shipping/info.zip"; depth:77; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3643033/; classtype:trojan-activity;sid:84506133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/anshul/anshul%20archieve/new%20folder/info.zip"; depth:80; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642924/; classtype:trojan-activity;sid:84506024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/app/05-jun-2013/info.zip"; depth:41; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642847/; classtype:trojan-activity;sid:84505947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/big/microsoft.sql.server.2012.enterprise.edition.with.service.pack.1-kopie/info.zip"; depth:84; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642788/; classtype:trojan-activity;sid:84505888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inicis_dll/key/info.zip"; depth:24; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642779/; classtype:trojan-activity;sid:84505879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/incis/info.zip"; depth:15; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642775/; classtype:trojan-activity;sid:84505875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/incis/key/inipaytest/info.zip"; depth:30; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642717/; classtype:trojan-activity;sid:84505817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/info.zip"; depth:42; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642711/; classtype:trojan-activity;sid:84505811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slnammicafe/info.zip"; depth:21; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642700/; classtype:trojan-activity;sid:84505800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/microsoft/windows/info.zip"; depth:27; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642692/; classtype:trojan-activity;sid:84505792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/incis/key/info.zip"; depth:19; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642677/; classtype:trojan-activity;sid:84505777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inicis_dll/log/info.zip"; depth:24; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642643/; classtype:trojan-activity;sid:84505743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slnammicafe/ammicafefile/info.zip"; depth:34; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642634/; classtype:trojan-activity;sid:84505734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/microsoft/info.zip"; depth:19; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642602/; classtype:trojan-activity;sid:84505702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slnammicafe/ammicafefile/ammicafesetup/info.zip"; depth:48; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642522/; classtype:trojan-activity;sid:84505622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642518/; classtype:trojan-activity;sid:84505618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slnammicafe2/info.zip"; depth:22; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642484/; classtype:trojan-activity;sid:84505584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/2018%20fixture%20-cp%20status/info.zip"; depth:55; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642455/; classtype:trojan-activity;sid:84505555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"121.184.128.134"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642438/; classtype:trojan-activity;sid:84505538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02/info.zip"; depth:12; endswith; nocase; http.host; content:"121.184.128.134"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642422/; classtype:trojan-activity;sid:84505522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slnammicafe2/ammicafe2file/info.zip"; depth:36; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642417/; classtype:trojan-activity;sid:84505517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slnammicafe2/ammicafe2file/ammicafe2setup/info.zip"; depth:51; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642406/; classtype:trojan-activity;sid:84505506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/big/html/info.zip"; depth:18; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642382/; classtype:trojan-activity;sid:84505482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/big/sql%20server%202014/info.zip"; depth:33; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642346/; classtype:trojan-activity;sid:84505446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/info.zip"; depth:16; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642349/; classtype:trojan-activity;sid:84505449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/01/info.zip"; depth:12; endswith; nocase; http.host; content:"121.184.128.134"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642324/; classtype:trojan-activity;sid:84505424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/info.zip"; depth:25; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642297/; classtype:trojan-activity;sid:84505397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inicis_dll/key/inipaytest/info.zip"; depth:35; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642294/; classtype:trojan-activity;sid:84505394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/aryacorp%20delhi/bhushan/info.zip"; depth:50; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642274/; classtype:trojan-activity;sid:84505374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/info.zip"; depth:17; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642250/; classtype:trojan-activity;sid:84505350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inicis_dll/info.zip"; depth:20; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642245/; classtype:trojan-activity;sid:84505345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/big/info.zip"; depth:13; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642246/; classtype:trojan-activity;sid:84505346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/uploads/app/info.zip"; depth:29; endswith; nocase; http.host; content:"103.20.213.34"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642229/; classtype:trojan-activity;sid:84505329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inicis_dll/key/jungminsof/info.zip"; depth:35; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642226/; classtype:trojan-activity;sid:84505326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3639311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=15_5vja6ls72gnqbjqkrme1i7bmit0fe4"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3639311/; classtype:trojan-activity;sid:84502411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637224)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haozip.100021.exe"; depth:18; endswith; nocase; http.host; content:"download.haozip.com"; depth:19; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637224/; classtype:trojan-activity;sid:84500324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/bot.jpg"; depth:15; endswith; nocase; http.host; content:"atasapka.com.tr"; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637210/; classtype:trojan-activity;sid:84500310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/23082024105108/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637189/; classtype:trojan-activity;sid:84500289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/26072024113244/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637188/; classtype:trojan-activity;sid:84500288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/19092024115007/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637186/; classtype:trojan-activity;sid:84500286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/24072024081607/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637187/; classtype:trojan-activity;sid:84500287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/12062024095414/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637185/; classtype:trojan-activity;sid:84500285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/27082024072850/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637184/; classtype:trojan-activity;sid:84500284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/12082024064105/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637183/; classtype:trojan-activity;sid:84500283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/16082024070308/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637182/; classtype:trojan-activity;sid:84500282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/13092024072525/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637181/; classtype:trojan-activity;sid:84500281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/23072024115252/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637180/; classtype:trojan-activity;sid:84500280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/21072024112418/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637179/; classtype:trojan-activity;sid:84500279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/16082024104510/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637178/; classtype:trojan-activity;sid:84500278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/22082024110540/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637177/; classtype:trojan-activity;sid:84500277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/04092024104005/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637176/; classtype:trojan-activity;sid:84500276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8343/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637175/; classtype:trojan-activity;sid:84500275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/15082024173844/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637174/; classtype:trojan-activity;sid:84500274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/26072024180426/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637173/; classtype:trojan-activity;sid:84500273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/03072024101008/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637172/; classtype:trojan-activity;sid:84500272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/13082024112350/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637171/; classtype:trojan-activity;sid:84500271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/26072024074431/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637170/; classtype:trojan-activity;sid:84500270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/01092024171022/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637168/; classtype:trojan-activity;sid:84500268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/11072024080039/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637169/; classtype:trojan-activity;sid:84500269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/12092024113946/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637167/; classtype:trojan-activity;sid:84500267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/08092024115637/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637166/; classtype:trojan-activity;sid:84500266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/15092024104931/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637165/; classtype:trojan-activity;sid:84500265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/12072024075828/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637164/; classtype:trojan-activity;sid:84500264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/11092024115504/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637163/; classtype:trojan-activity;sid:84500263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/21082024115532/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637160/; classtype:trojan-activity;sid:84500260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/05072024114132/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637161/; classtype:trojan-activity;sid:84500261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8465/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637162/; classtype:trojan-activity;sid:84500262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/25062024073012/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637159/; classtype:trojan-activity;sid:84500259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/29072024110431/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637158/; classtype:trojan-activity;sid:84500258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/30072024091401/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637157/; classtype:trojan-activity;sid:84500257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/15072024124718/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637153/; classtype:trojan-activity;sid:84500253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/09082024185433/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637154/; classtype:trojan-activity;sid:84500254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/09072024110245/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637155/; classtype:trojan-activity;sid:84500255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/09092024072321/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637149/; classtype:trojan-activity;sid:84500249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07082024180909/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637150/; classtype:trojan-activity;sid:84500250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/24092024073908/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637151/; classtype:trojan-activity;sid:84500251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/19062024071831/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637147/; classtype:trojan-activity;sid:84500247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/21092024114951/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637148/; classtype:trojan-activity;sid:84500248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/30062024113348/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637145/; classtype:trojan-activity;sid:84500245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/04092024113047/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637146/; classtype:trojan-activity;sid:84500246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/04092024120154/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637144/; classtype:trojan-activity;sid:84500244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/01082024110241/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637143/; classtype:trojan-activity;sid:84500243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/14072024110540/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637141/; classtype:trojan-activity;sid:84500241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11082024185045/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637142/; classtype:trojan-activity;sid:84500242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/19062024103023/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637138/; classtype:trojan-activity;sid:84500238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/06092024072348/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637139/; classtype:trojan-activity;sid:84500239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/29072024070625/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637140/; classtype:trojan-activity;sid:84500240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/18072024112759/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637137/; classtype:trojan-activity;sid:84500237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/11072024155154/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637136/; classtype:trojan-activity;sid:84500236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/18082024113426/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637135/; classtype:trojan-activity;sid:84500235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07092024113602/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637133/; classtype:trojan-activity;sid:84500233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/28082024163408/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637134/; classtype:trojan-activity;sid:84500234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/10082024110351/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637130/; classtype:trojan-activity;sid:84500230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/12092024181446/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637131/; classtype:trojan-activity;sid:84500231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/26082024115142/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637129/; classtype:trojan-activity;sid:84500229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/09092024091444/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637128/; classtype:trojan-activity;sid:84500228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/23082024071038/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637127/; classtype:trojan-activity;sid:84500227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/17062024181518/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637122/; classtype:trojan-activity;sid:84500222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/05082024120940/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637123/; classtype:trojan-activity;sid:84500223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/24072024112235/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637124/; classtype:trojan-activity;sid:84500224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/17092024073614/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637125/; classtype:trojan-activity;sid:84500225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/09082024122457/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637120/; classtype:trojan-activity;sid:84500220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/09092024112532/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637117/; classtype:trojan-activity;sid:84500217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/24062024072602/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637118/; classtype:trojan-activity;sid:84500218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/12092024070406/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637119/; classtype:trojan-activity;sid:84500219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/24072024143513/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637115/; classtype:trojan-activity;sid:84500215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/21082024081755/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637116/; classtype:trojan-activity;sid:84500216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/13082024120234/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637114/; classtype:trojan-activity;sid:84500214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/19072024123916/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637113/; classtype:trojan-activity;sid:84500213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/29082024122318/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637110/; classtype:trojan-activity;sid:84500210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/15072024080426/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637111/; classtype:trojan-activity;sid:84500211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/22092024115602/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637112/; classtype:trojan-activity;sid:84500212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/05082024125302/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637109/; classtype:trojan-activity;sid:84500209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/16072024114842/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637107/; classtype:trojan-activity;sid:84500207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/16092024115114/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637108/; classtype:trojan-activity;sid:84500208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/31072024070936/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637105/; classtype:trojan-activity;sid:84500205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/17092024104334/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637106/; classtype:trojan-activity;sid:84500206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/01082024072447/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637104/; classtype:trojan-activity;sid:84500204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/05082024065930/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637103/; classtype:trojan-activity;sid:84500203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/01082024133101/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637101/; classtype:trojan-activity;sid:84500201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/02082024083649/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637099/; classtype:trojan-activity;sid:84500199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/29072024182036/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637100/; classtype:trojan-activity;sid:84500200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/19072024071620/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637098/; classtype:trojan-activity;sid:84500198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8029/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637096/; classtype:trojan-activity;sid:84500196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/25092024150814/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637097/; classtype:trojan-activity;sid:84500197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/03072024102505/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637092/; classtype:trojan-activity;sid:84500192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/03092024131015/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637093/; classtype:trojan-activity;sid:84500193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/15072024084956/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637094/; classtype:trojan-activity;sid:84500194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/25062024105808/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637090/; classtype:trojan-activity;sid:84500190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/04092024072725/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637091/; classtype:trojan-activity;sid:84500191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/20062024112748/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637089/; classtype:trojan-activity;sid:84500189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/17072024103622/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637087/; classtype:trojan-activity;sid:84500187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/16082024121016/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637088/; classtype:trojan-activity;sid:84500188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/24092024103551/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637085/; classtype:trojan-activity;sid:84500185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/15072024080017/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637086/; classtype:trojan-activity;sid:84500186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024081535/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637082/; classtype:trojan-activity;sid:84500182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/26072024111342/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637083/; classtype:trojan-activity;sid:84500183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11062024125904/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637084/; classtype:trojan-activity;sid:84500184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/tek/info.zip"; depth:20; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637081/; classtype:trojan-activity;sid:84500181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/11092024075310/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637080/; classtype:trojan-activity;sid:84500180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/24072024121144/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637076/; classtype:trojan-activity;sid:84500176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/badmail/info.zip"; depth:24; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637077/; classtype:trojan-activity;sid:84500177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/06082024080109/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637078/; classtype:trojan-activity;sid:84500178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/12072024072413/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637079/; classtype:trojan-activity;sid:84500179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/08082024071151/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637073/; classtype:trojan-activity;sid:84500173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/03092024073559/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637074/; classtype:trojan-activity;sid:84500174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8336/18072024083258/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637070/; classtype:trojan-activity;sid:84500170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/01092024084736/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637069/; classtype:trojan-activity;sid:84500169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/08082024072046/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637067/; classtype:trojan-activity;sid:84500167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/08072024110224/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637068/; classtype:trojan-activity;sid:84500168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/02092024075924/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637065/; classtype:trojan-activity;sid:84500165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/30082024115734/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637064/; classtype:trojan-activity;sid:84500164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/23072024075958/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637062/; classtype:trojan-activity;sid:84500162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/27082024173545/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637063/; classtype:trojan-activity;sid:84500163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/06092024074954/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637060/; classtype:trojan-activity;sid:84500160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/24082024112958/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637056/; classtype:trojan-activity;sid:84500156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/04092024180827/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637057/; classtype:trojan-activity;sid:84500157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/05092024073851/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637058/; classtype:trojan-activity;sid:84500158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/05092024175914/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637055/; classtype:trojan-activity;sid:84500155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07082024181015/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637054/; classtype:trojan-activity;sid:84500154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/09082024151247/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637053/; classtype:trojan-activity;sid:84500153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/05072024135901/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637052/; classtype:trojan-activity;sid:84500152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/04072024073930/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637050/; classtype:trojan-activity;sid:84500150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/27072024111013/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637051/; classtype:trojan-activity;sid:84500151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/28092024110908/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637047/; classtype:trojan-activity;sid:84500147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/17062024124213/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637048/; classtype:trojan-activity;sid:84500148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/21062024074659/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637049/; classtype:trojan-activity;sid:84500149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/06082024071203/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637046/; classtype:trojan-activity;sid:84500146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11092024163133/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637044/; classtype:trojan-activity;sid:84500144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/25092024084516/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637045/; classtype:trojan-activity;sid:84500145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/01082024134811/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637042/; classtype:trojan-activity;sid:84500142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8336/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637037/; classtype:trojan-activity;sid:84500137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/26062024074615/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637038/; classtype:trojan-activity;sid:84500138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/20072024103050/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637039/; classtype:trojan-activity;sid:84500139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/02072024072748/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637040/; classtype:trojan-activity;sid:84500140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/17092024073317/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637041/; classtype:trojan-activity;sid:84500141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/25072024124018/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637036/; classtype:trojan-activity;sid:84500136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/27092024120719/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637034/; classtype:trojan-activity;sid:84500134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/29062024115106/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637032/; classtype:trojan-activity;sid:84500132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/02092024121943/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637030/; classtype:trojan-activity;sid:84500130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/06092024173040/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637029/; classtype:trojan-activity;sid:84500129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/17072024080628/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637026/; classtype:trojan-activity;sid:84500126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/13082024144908/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637027/; classtype:trojan-activity;sid:84500127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/14092024112531/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637028/; classtype:trojan-activity;sid:84500128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/29082024110733/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637025/; classtype:trojan-activity;sid:84500125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/11092024161738/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637024/; classtype:trojan-activity;sid:84500124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/25062024074726/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637021/; classtype:trojan-activity;sid:84500121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/02102024124124/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637022/; classtype:trojan-activity;sid:84500122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/01082024124212/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637023/; classtype:trojan-activity;sid:84500123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/29072024170139/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637020/; classtype:trojan-activity;sid:84500120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/13092024090633/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637015/; classtype:trojan-activity;sid:84500115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/12082024111719/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637017/; classtype:trojan-activity;sid:84500117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/13062024073315/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637019/; classtype:trojan-activity;sid:84500119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/26092024073319/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637011/; classtype:trojan-activity;sid:84500111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/03072024075801/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637012/; classtype:trojan-activity;sid:84500112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/13092024065731/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637013/; classtype:trojan-activity;sid:84500113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/02092024155414/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637014/; classtype:trojan-activity;sid:84500114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/29062024131718/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637007/; classtype:trojan-activity;sid:84500107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024163711/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637008/; classtype:trojan-activity;sid:84500108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/27062024115812/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637009/; classtype:trojan-activity;sid:84500109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07072024113310/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637010/; classtype:trojan-activity;sid:84500110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/26082024175225/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637005/; classtype:trojan-activity;sid:84500105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/06092024112226/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637002/; classtype:trojan-activity;sid:84500102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/1/8325/14062024181140/info.zip"; depth:43; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637003/; classtype:trojan-activity;sid:84500103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/15092024163914/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637004/; classtype:trojan-activity;sid:84500104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/12082024111034/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636999/; classtype:trojan-activity;sid:84500099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/19062024111300/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637000/; classtype:trojan-activity;sid:84500100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/02092024070516/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637001/; classtype:trojan-activity;sid:84500101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/15062024120757/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636997/; classtype:trojan-activity;sid:84500097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/07082024074934/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636996/; classtype:trojan-activity;sid:84500096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/drop/info.zip"; depth:21; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636993/; classtype:trojan-activity;sid:84500093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11092024172104/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636994/; classtype:trojan-activity;sid:84500094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/23072024072015/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636995/; classtype:trojan-activity;sid:84500095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/18082024174028/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636992/; classtype:trojan-activity;sid:84500092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/10072024072615/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636991/; classtype:trojan-activity;sid:84500091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/03102024140347/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636990/; classtype:trojan-activity;sid:84500090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/29072024094428/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636987/; classtype:trojan-activity;sid:84500087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/08082024114220/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636988/; classtype:trojan-activity;sid:84500088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/19072024081323/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636986/; classtype:trojan-activity;sid:84500086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/08082024072411/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636985/; classtype:trojan-activity;sid:84500085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/11092024072722/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636982/; classtype:trojan-activity;sid:84500082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/17062024075813/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636978/; classtype:trojan-activity;sid:84500078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/26072024071101/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636979/; classtype:trojan-activity;sid:84500079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/18092024104929/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636980/; classtype:trojan-activity;sid:84500080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8051/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636975/; classtype:trojan-activity;sid:84500075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/25072024144032/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636976/; classtype:trojan-activity;sid:84500076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/26082024121258/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636977/; classtype:trojan-activity;sid:84500077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/27082024111920/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636967/; classtype:trojan-activity;sid:84500067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/25072024121015/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636968/; classtype:trojan-activity;sid:84500068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/21082024175843/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636969/; classtype:trojan-activity;sid:84500069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/18062024121810/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636970/; classtype:trojan-activity;sid:84500070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/12072024130606/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636971/; classtype:trojan-activity;sid:84500071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/16062024115815/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636972/; classtype:trojan-activity;sid:84500072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/13092024164829/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636973/; classtype:trojan-activity;sid:84500073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/02092024071944/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636965/; classtype:trojan-activity;sid:84500065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/01092024103900/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636966/; classtype:trojan-activity;sid:84500066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/23072024130857/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636964/; classtype:trojan-activity;sid:84500064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/06092024071949/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636963/; classtype:trojan-activity;sid:84500063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/17062024111134/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636957/; classtype:trojan-activity;sid:84500057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/12082024174415/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636958/; classtype:trojan-activity;sid:84500058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/02082024073257/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636959/; classtype:trojan-activity;sid:84500059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/03092024120537/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636960/; classtype:trojan-activity;sid:84500060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/01072024102122/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636961/; classtype:trojan-activity;sid:84500061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/27072024112004/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636962/; classtype:trojan-activity;sid:84500062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/09072024071533/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636956/; classtype:trojan-activity;sid:84500056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/22082024070804/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636955/; classtype:trojan-activity;sid:84500055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/21082024115442/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636954/; classtype:trojan-activity;sid:84500054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/1/8325/info.zip"; depth:28; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636953/; classtype:trojan-activity;sid:84500053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/17072024080732/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636948/; classtype:trojan-activity;sid:84500048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/19082024080051/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636949/; classtype:trojan-activity;sid:84500049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/28082024111159/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636950/; classtype:trojan-activity;sid:84500050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/28072024115238/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636951/; classtype:trojan-activity;sid:84500051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/07082024070516/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636947/; classtype:trojan-activity;sid:84500047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07092024175546/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636946/; classtype:trojan-activity;sid:84500046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/25072024103203/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636945/; classtype:trojan-activity;sid:84500045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/31082024165207/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636942/; classtype:trojan-activity;sid:84500042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/11062024093514/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636943/; classtype:trojan-activity;sid:84500043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/06092024114755/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636944/; classtype:trojan-activity;sid:84500044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/27092024123259/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636940/; classtype:trojan-activity;sid:84500040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/23092024073238/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636941/; classtype:trojan-activity;sid:84500041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/13072024115545/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636937/; classtype:trojan-activity;sid:84500037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/29072024104316/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636936/; classtype:trojan-activity;sid:84500036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/13072024115848/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636935/; classtype:trojan-activity;sid:84500035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/24072024071414/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636934/; classtype:trojan-activity;sid:84500034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/16092024105926/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636933/; classtype:trojan-activity;sid:84500033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/28082024174605/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636932/; classtype:trojan-activity;sid:84500032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/08082024174233/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636931/; classtype:trojan-activity;sid:84500031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/23072024081312/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636927/; classtype:trojan-activity;sid:84500027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/02102024072353/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636928/; classtype:trojan-activity;sid:84500028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/08092024174750/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636929/; classtype:trojan-activity;sid:84500029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8325/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636930/; classtype:trojan-activity;sid:84500030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8336/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636925/; classtype:trojan-activity;sid:84500025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/19062024070824/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636926/; classtype:trojan-activity;sid:84500026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/22082024121329/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636920/; classtype:trojan-activity;sid:84500020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/26062024155216/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636921/; classtype:trojan-activity;sid:84500021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/24092024120511/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636922/; classtype:trojan-activity;sid:84500022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/16062024180613/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636923/; classtype:trojan-activity;sid:84500023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07072024165922/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636919/; classtype:trojan-activity;sid:84500019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/13092024114239/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636918/; classtype:trojan-activity;sid:84500018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/20082024112036/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636917/; classtype:trojan-activity;sid:84500017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8318/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636916/; classtype:trojan-activity;sid:84500016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/31082024110606/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636913/; classtype:trojan-activity;sid:84500013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11062024112609/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636914/; classtype:trojan-activity;sid:84500014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/02072024115435/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636910/; classtype:trojan-activity;sid:84500010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07092024122439/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636909/; classtype:trojan-activity;sid:84500009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/14062024123830/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636906/; classtype:trojan-activity;sid:84500006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/17062024180043/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636908/; classtype:trojan-activity;sid:84500008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/28072024115112/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636905/; classtype:trojan-activity;sid:84500005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024090731/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636904/; classtype:trojan-activity;sid:84500004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/23092024113222/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636902/; classtype:trojan-activity;sid:84500002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/03072024113724/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636900/; classtype:trojan-activity;sid:84500000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/11092024134516/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636899/; classtype:trojan-activity;sid:84499999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8334/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636897/; classtype:trojan-activity;sid:84499997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/08082024114317/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636894/; classtype:trojan-activity;sid:84499994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/18072024151745/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636895/; classtype:trojan-activity;sid:84499995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/19072024124237/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636893/; classtype:trojan-activity;sid:84499993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/29082024170717/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636892/; classtype:trojan-activity;sid:84499992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/08072024075903/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636883/; classtype:trojan-activity;sid:84499983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8325/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636884/; classtype:trojan-activity;sid:84499984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/15062024114520/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636885/; classtype:trojan-activity;sid:84499985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/13092024153227/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636886/; classtype:trojan-activity;sid:84499986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/14082024075957/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636887/; classtype:trojan-activity;sid:84499987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/26082024070716/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636888/; classtype:trojan-activity;sid:84499988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/21062024072959/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636890/; classtype:trojan-activity;sid:84499990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/1/8325/13062024155232/info.zip"; depth:43; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636882/; classtype:trojan-activity;sid:84499982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/23082024111126/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636881/; classtype:trojan-activity;sid:84499981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/04072024125301/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636880/; classtype:trojan-activity;sid:84499980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11082024113244/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636876/; classtype:trojan-activity;sid:84499976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/04092024091820/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636877/; classtype:trojan-activity;sid:84499977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07102024125032/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636878/; classtype:trojan-activity;sid:84499978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/30072024114118/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636872/; classtype:trojan-activity;sid:84499972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/05082024083850/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636873/; classtype:trojan-activity;sid:84499973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/17062024072104/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636874/; classtype:trojan-activity;sid:84499974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/22072024125710/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636875/; classtype:trojan-activity;sid:84499975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/03072024103601/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636871/; classtype:trojan-activity;sid:84499971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/12082024120632/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636869/; classtype:trojan-activity;sid:84499969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636863/; classtype:trojan-activity;sid:84499963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/11072024071932/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636864/; classtype:trojan-activity;sid:84499964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/11072024143228/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636865/; classtype:trojan-activity;sid:84499965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/27092024124432/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636866/; classtype:trojan-activity;sid:84499966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/23082024175244/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636867/; classtype:trojan-activity;sid:84499967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/13062024070655/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636868/; classtype:trojan-activity;sid:84499968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/14062024072833/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636862/; classtype:trojan-activity;sid:84499962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/25092024120601/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636859/; classtype:trojan-activity;sid:84499959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/08092024115123/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636860/; classtype:trojan-activity;sid:84499960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/05072024071033/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636855/; classtype:trojan-activity;sid:84499955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/04102024094250/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636856/; classtype:trojan-activity;sid:84499956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/01082024101244/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636857/; classtype:trojan-activity;sid:84499957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/03072024091538/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636850/; classtype:trojan-activity;sid:84499950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/05082024114357/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636851/; classtype:trojan-activity;sid:84499951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/10092024070313/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636852/; classtype:trojan-activity;sid:84499952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/23092024123854/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636853/; classtype:trojan-activity;sid:84499953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/22082024112941/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636854/; classtype:trojan-activity;sid:84499954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/08072024113918/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636849/; classtype:trojan-activity;sid:84499949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8326/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636847/; classtype:trojan-activity;sid:84499947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11072024110808/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636843/; classtype:trojan-activity;sid:84499943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/06072024112721/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636845/; classtype:trojan-activity;sid:84499945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8326/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636846/; classtype:trojan-activity;sid:84499946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/15072024151521/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636839/; classtype:trojan-activity;sid:84499939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/16072024120102/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636840/; classtype:trojan-activity;sid:84499940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636842)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07102024115226/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636842/; classtype:trojan-activity;sid:84499942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/08072024070547/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636836/; classtype:trojan-activity;sid:84499936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/26092024103307/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636837/; classtype:trojan-activity;sid:84499937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/22072024134639/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636835/; classtype:trojan-activity;sid:84499935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/29072024120914/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636833/; classtype:trojan-activity;sid:84499933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11092024104834/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636834/; classtype:trojan-activity;sid:84499934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/01072024095738/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636826/; classtype:trojan-activity;sid:84499926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/10072024073020/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636827/; classtype:trojan-activity;sid:84499927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/13082024065051/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636828/; classtype:trojan-activity;sid:84499928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/23092024074730/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636829/; classtype:trojan-activity;sid:84499929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/05092024071139/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636830/; classtype:trojan-activity;sid:84499930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/05072024143423/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636831/; classtype:trojan-activity;sid:84499931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/01072024073548/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636832/; classtype:trojan-activity;sid:84499932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/16092024075132/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636825/; classtype:trojan-activity;sid:84499925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/28062024112249/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636824/; classtype:trojan-activity;sid:84499924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/18072024080738/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636823/; classtype:trojan-activity;sid:84499923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/06102024112545/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636816/; classtype:trojan-activity;sid:84499916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/17062024181057/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636817/; classtype:trojan-activity;sid:84499917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/02072024073145/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636818/; classtype:trojan-activity;sid:84499918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/21062024070935/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636819/; classtype:trojan-activity;sid:84499919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/06082024120113/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636820/; classtype:trojan-activity;sid:84499920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/27062024081736/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636821/; classtype:trojan-activity;sid:84499921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/29082024071803/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636822/; classtype:trojan-activity;sid:84499922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/24062024113513/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636815/; classtype:trojan-activity;sid:84499915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/25072024071606/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636814/; classtype:trojan-activity;sid:84499914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/12062024085922/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636812/; classtype:trojan-activity;sid:84499912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/03092024152101/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636813/; classtype:trojan-activity;sid:84499913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/08072024113231/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636811/; classtype:trojan-activity;sid:84499911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/22072024130114/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636806/; classtype:trojan-activity;sid:84499906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/16072024114959/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636807/; classtype:trojan-activity;sid:84499907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/20082024121600/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636809/; classtype:trojan-activity;sid:84499909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/26092024115544/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636810/; classtype:trojan-activity;sid:84499910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/28082024070417/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636803/; classtype:trojan-activity;sid:84499903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/26072024143113/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636804/; classtype:trojan-activity;sid:84499904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/13092024071052/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636800/; classtype:trojan-activity;sid:84499900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/10062024180136/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636801/; classtype:trojan-activity;sid:84499901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/23082024175356/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636802/; classtype:trojan-activity;sid:84499902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/27082024070328/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636799/; classtype:trojan-activity;sid:84499899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8050/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636798/; classtype:trojan-activity;sid:84499898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/18062024071837/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636795/; classtype:trojan-activity;sid:84499895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/18072024120409/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636796/; classtype:trojan-activity;sid:84499896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/30082024111343/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636797/; classtype:trojan-activity;sid:84499897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/21082024112544/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636794/; classtype:trojan-activity;sid:84499894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/19072024111357/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636791/; classtype:trojan-activity;sid:84499891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/11062024175200/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636784/; classtype:trojan-activity;sid:84499884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/30072024115935/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636785/; classtype:trojan-activity;sid:84499885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/02092024114819/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636786/; classtype:trojan-activity;sid:84499886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/30072024070959/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636788/; classtype:trojan-activity;sid:84499888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/05092024120909/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636789/; classtype:trojan-activity;sid:84499889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/05072024112530/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636790/; classtype:trojan-activity;sid:84499890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/09082024115132/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636783/; classtype:trojan-activity;sid:84499883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/10092024114316/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636782/; classtype:trojan-activity;sid:84499882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/15082024113136/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636781/; classtype:trojan-activity;sid:84499881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/04072024170824/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636779/; classtype:trojan-activity;sid:84499879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/23072024135746/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636780/; classtype:trojan-activity;sid:84499880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07102024115515/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636777/; classtype:trojan-activity;sid:84499877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/12072024115926/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636778/; classtype:trojan-activity;sid:84499878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/05082024082013/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636775/; classtype:trojan-activity;sid:84499875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/10072024110114/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636776/; classtype:trojan-activity;sid:84499876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/17072024071919/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636773/; classtype:trojan-activity;sid:84499873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/19082024070444/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636771/; classtype:trojan-activity;sid:84499871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/20082024104419/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636772/; classtype:trojan-activity;sid:84499872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/06082024070754/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636770/; classtype:trojan-activity;sid:84499870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/12092024074514/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636769/; classtype:trojan-activity;sid:84499869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/23072024073428/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636768/; classtype:trojan-activity;sid:84499868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/16082024110029/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636767/; classtype:trojan-activity;sid:84499867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/30072024075615/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636766/; classtype:trojan-activity;sid:84499866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/24082024173603/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636764/; classtype:trojan-activity;sid:84499864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/27092024072930/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636763/; classtype:trojan-activity;sid:84499863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/14092024070825/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636761/; classtype:trojan-activity;sid:84499861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/10082024105405/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636762/; classtype:trojan-activity;sid:84499862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/31072024120304/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636760/; classtype:trojan-activity;sid:84499860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/16082024171045/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636759/; classtype:trojan-activity;sid:84499859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/19062024083204/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636757/; classtype:trojan-activity;sid:84499857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/17062024175202/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636758/; classtype:trojan-activity;sid:84499858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/6011/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636756/; classtype:trojan-activity;sid:84499856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/09082024071028/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636754/; classtype:trojan-activity;sid:84499854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/bkp/info.zip"; depth:20; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636753/; classtype:trojan-activity;sid:84499853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/11062024074638/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636752/; classtype:trojan-activity;sid:84499852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8318/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636751/; classtype:trojan-activity;sid:84499851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024071328/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636750/; classtype:trojan-activity;sid:84499850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/17082024111540/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636749/; classtype:trojan-activity;sid:84499849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/25072024111710/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636748/; classtype:trojan-activity;sid:84499848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11062024125639/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636746/; classtype:trojan-activity;sid:84499846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/26062024072316/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636745/; classtype:trojan-activity;sid:84499845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/18072024152842/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636744/; classtype:trojan-activity;sid:84499844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/03092024065611/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636743/; classtype:trojan-activity;sid:84499843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/20082024074454/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636742/; classtype:trojan-activity;sid:84499842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/14062024182506/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636741/; classtype:trojan-activity;sid:84499841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/28062024162227/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636740/; classtype:trojan-activity;sid:84499840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/25082024112344/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636739/; classtype:trojan-activity;sid:84499839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/05102024112225/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636736/; classtype:trojan-activity;sid:84499836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/22072024112228/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636737/; classtype:trojan-activity;sid:84499837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/13092024123948/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636735/; classtype:trojan-activity;sid:84499835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636733/; classtype:trojan-activity;sid:84499833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/21082024065715/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636734/; classtype:trojan-activity;sid:84499834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024163507/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636728/; classtype:trojan-activity;sid:84499828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/05092024111850/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636729/; classtype:trojan-activity;sid:84499829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/24072024112124/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636730/; classtype:trojan-activity;sid:84499830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/pickup/info.zip"; depth:23; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636731/; classtype:trojan-activity;sid:84499831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/09072024072801/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636732/; classtype:trojan-activity;sid:84499832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/30082024070843/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636727/; classtype:trojan-activity;sid:84499827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/15072024111306/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636723/; classtype:trojan-activity;sid:84499823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/24072024072622/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636724/; classtype:trojan-activity;sid:84499824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/23082024120742/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636726/; classtype:trojan-activity;sid:84499826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/15072024121001/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636721/; classtype:trojan-activity;sid:84499821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/14092024162753/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636722/; classtype:trojan-activity;sid:84499822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/26072024130538/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636719/; classtype:trojan-activity;sid:84499819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/01102024075913/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636720/; classtype:trojan-activity;sid:84499820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/31072024110649/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636717/; classtype:trojan-activity;sid:84499817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/24092024074236/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636718/; classtype:trojan-activity;sid:84499818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/26092024073810/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636715/; classtype:trojan-activity;sid:84499815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/19062024073721/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636716/; classtype:trojan-activity;sid:84499816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/03102024114713/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636714/; classtype:trojan-activity;sid:84499814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/27062024134606/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636708/; classtype:trojan-activity;sid:84499808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/25092024074358/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636709/; classtype:trojan-activity;sid:84499809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636710/; classtype:trojan-activity;sid:84499810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/12092024065636/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636711/; classtype:trojan-activity;sid:84499811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/07082024113359/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636712/; classtype:trojan-activity;sid:84499812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/14082024102908/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636713/; classtype:trojan-activity;sid:84499813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/27062024074304/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636705/; classtype:trojan-activity;sid:84499805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/20092024114457/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636706/; classtype:trojan-activity;sid:84499806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/idi/info.zip"; depth:20; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636707/; classtype:trojan-activity;sid:84499807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/05072024105131/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636703/; classtype:trojan-activity;sid:84499803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/11062024123414/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636704/; classtype:trojan-activity;sid:84499804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/12062024122748/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636698/; classtype:trojan-activity;sid:84499798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636699/; classtype:trojan-activity;sid:84499799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/22082024180206/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636693/; classtype:trojan-activity;sid:84499793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/20082024172514/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636694/; classtype:trojan-activity;sid:84499794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/20082024070343/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636695/; classtype:trojan-activity;sid:84499795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/27092024125844/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636696/; classtype:trojan-activity;sid:84499796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/01082024070127/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636697/; classtype:trojan-activity;sid:84499797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/30092024073115/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636685/; classtype:trojan-activity;sid:84499785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/04102024114428/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636686/; classtype:trojan-activity;sid:84499786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/17072024162506/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636687/; classtype:trojan-activity;sid:84499787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/17072024112121/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636688/; classtype:trojan-activity;sid:84499788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/13062024123930/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636689/; classtype:trojan-activity;sid:84499789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/20082024114833/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636690/; classtype:trojan-activity;sid:84499790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/22072024071046/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636691/; classtype:trojan-activity;sid:84499791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/21082024074934/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636692/; classtype:trojan-activity;sid:84499792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/12072024073215/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636683/; classtype:trojan-activity;sid:84499783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/11082024113341/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636684/; classtype:trojan-activity;sid:84499784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/09092024080429/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636681/; classtype:trojan-activity;sid:84499781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8342/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636682/; classtype:trojan-activity;sid:84499782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/16092024071437/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636678/; classtype:trojan-activity;sid:84499778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/11092024070152/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636679/; classtype:trojan-activity;sid:84499779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/19072024082257/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636676/; classtype:trojan-activity;sid:84499776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/02092024173539/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636666/; classtype:trojan-activity;sid:84499766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/14062024074014/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636667/; classtype:trojan-activity;sid:84499767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/queue/info.zip"; depth:22; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636668/; classtype:trojan-activity;sid:84499768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/13082024112311/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636669/; classtype:trojan-activity;sid:84499769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/23072024112852/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636670/; classtype:trojan-activity;sid:84499770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/13092024094613/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636671/; classtype:trojan-activity;sid:84499771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/19082024113816/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636672/; classtype:trojan-activity;sid:84499772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/02082024121949/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636674/; classtype:trojan-activity;sid:84499774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/10092024185923/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636675/; classtype:trojan-activity;sid:84499775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/22072024130440/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636662/; classtype:trojan-activity;sid:84499762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8336/05072024082450/info.zip"; depth:46; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636663/; classtype:trojan-activity;sid:84499763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/09092024181236/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636664/; classtype:trojan-activity;sid:84499764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/20082024150907/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636665/; classtype:trojan-activity;sid:84499765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/22082024114017/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636656/; classtype:trojan-activity;sid:84499756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/14082024065337/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636657/; classtype:trojan-activity;sid:84499757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/8059/info.zip"; depth:31; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636658/; classtype:trojan-activity;sid:84499758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/03072024154958/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636659/; classtype:trojan-activity;sid:84499759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/24062024075130/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636660/; classtype:trojan-activity;sid:84499760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/18072024070807/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636654/; classtype:trojan-activity;sid:84499754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3635840)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"91.197.122.35"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_30; reference:url, urlhaus.abuse.ch/url/3635840/; classtype:trojan-activity;sid:84498940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3635467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/storage/v1/object/public/nano/image.jpg"; depth:40; endswith; nocase; http.host; content:"ybgctdtbzvgpdxjivafy.supabase.co"; depth:32; isdataat:!1,relative; metadata:created_at 2025_09_30; reference:url, urlhaus.abuse.ch/url/3635467/; classtype:trojan-activity;sid:84498567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3634292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ziobigiu84/site/raw/refs/heads/main/launcher.zip"; depth:49; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_29; reference:url, urlhaus.abuse.ch/url/3634292/; classtype:trojan-activity;sid:84497392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3632903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/bocavenue.exe"; depth:25; endswith; nocase; http.host; content:"versaclean.com.br"; depth:17; isdataat:!1,relative; metadata:created_at 2025_09_27; reference:url, urlhaus.abuse.ch/url/3632903/; classtype:trojan-activity;sid:84496003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/installer.exe"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631593/; classtype:trojan-activity;sid:84494693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/tlp.exe"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631583/; classtype:trojan-activity;sid:84494683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol11.exe"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631573/; classtype:trojan-activity;sid:84494673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/1488.exe"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631574/; classtype:trojan-activity;sid:84494674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/1210.exe"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631575/; classtype:trojan-activity;sid:84494675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol.exe"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631555/; classtype:trojan-activity;sid:84494655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/bsg.exe"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631554/; classtype:trojan-activity;sid:84494654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.48.13.117"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_24; reference:url, urlhaus.abuse.ch/url/3631250/; classtype:trojan-activity;sid:84494350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"188.95.148.167"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_24; reference:url, urlhaus.abuse.ch/url/3631233/; classtype:trojan-activity;sid:84494333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3630546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shaerrlys/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_23; reference:url, urlhaus.abuse.ch/url/3630546/; classtype:trojan-activity;sid:84493646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3628584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.164.117.74"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_21; reference:url, urlhaus.abuse.ch/url/3628584/; classtype:trojan-activity;sid:84491684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3627935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"36.154.188.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_20; reference:url, urlhaus.abuse.ch/url/3627935/; classtype:trojan-activity;sid:84491035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3627210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"36.154.188.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_19; reference:url, urlhaus.abuse.ch/url/3627210/; classtype:trojan-activity;sid:84490310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3626275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"74.62.255.234"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_18; reference:url, urlhaus.abuse.ch/url/3626275/; classtype:trojan-activity;sid:84489375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3624591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1y-uctjccdffz5o1fuqg1gp8mdwukvbla"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_09_15; reference:url, urlhaus.abuse.ch/url/3624591/; classtype:trojan-activity;sid:84487691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mise.exe"; depth:9; endswith; nocase; http.host; content:"210.16.163.207"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_14; reference:url, urlhaus.abuse.ch/url/3623786/; classtype:trojan-activity;sid:84486886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol1.exe"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623408/; classtype:trojan-activity;sid:84486508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/123.exe"; depth:8; endswith; nocase; http.host; content:"210.16.163.207"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623390/; classtype:trojan-activity;sid:84486490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rasadhlp.dll"; depth:13; endswith; nocase; http.host; content:"118.25.68.152"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623131/; classtype:trojan-activity;sid:84486231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ziobigiu84/site/refs/heads/main/launcher.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623126/; classtype:trojan-activity;sid:84486226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/midkourtbbe/network/refs/heads/main/software.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623123/; classtype:trojan-activity;sid:84486223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anno29/web/refs/heads/main/software.zip"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623122/; classtype:trojan-activity;sid:84486222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilpigna03/site/refs/heads/main/launcher.zip"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623121/; classtype:trojan-activity;sid:84486221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullarchive/request/refs/heads/main/software.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623120/; classtype:trojan-activity;sid:84486220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/storage/v1/object/public/hold/image.jpg"; depth:40; endswith; nocase; http.host; content:"ihmmkvkaiwnilneauhfn.supabase.co"; depth:32; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622759/; classtype:trojan-activity;sid:84485859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/storage/v1/object/public/hold/image.jpg|3f|12711343"; depth:52; endswith; nocase; http.host; content:"ihmmkvkaiwnilneauhfn.supabase.co"; depth:32; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622638/; classtype:trojan-activity;sid:84485738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"www.hcsnet.com.br"; depth:17; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622625/; classtype:trojan-activity;sid:84485725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_amd64"; depth:12; endswith; nocase; http.host; content:"www.hcsnet.com.br"; depth:17; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622623/; classtype:trojan-activity;sid:84485723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_x86"; depth:10; endswith; nocase; http.host; content:"www.hcsnet.com.br"; depth:17; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622624/; classtype:trojan-activity;sid:84485724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/125.bin"; depth:8; endswith; nocase; http.host; content:"39.105.223.127"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622541/; classtype:trojan-activity;sid:84485641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shellcode.bin"; depth:14; endswith; nocase; http.host; content:"39.105.223.127"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622545/; classtype:trojan-activity;sid:84485645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/er/45.bin"; depth:10; endswith; nocase; http.host; content:"39.105.223.127"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622547/; classtype:trojan-activity;sid:84485647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/er/326.bin"; depth:11; endswith; nocase; http.host; content:"39.105.223.127"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622548/; classtype:trojan-activity;sid:84485648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/er/46.bin"; depth:10; endswith; nocase; http.host; content:"39.105.223.127"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622549/; classtype:trojan-activity;sid:84485649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/er/1212.bin"; depth:12; endswith; nocase; http.host; content:"39.105.223.127"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622539/; classtype:trojan-activity;sid:84485639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3621757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1xisuc6psmmj5jzq7jgoffba7avfhzga_"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_09_11; reference:url, urlhaus.abuse.ch/url/3621757/; classtype:trojan-activity;sid:84484857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3621753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1okqdyr_kghanl7h_i1mwmlmzfesw_gx0"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_09_11; reference:url, urlhaus.abuse.ch/url/3621753/; classtype:trojan-activity;sid:84484853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3620132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.81.156.125"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_08; reference:url, urlhaus.abuse.ch/url/3620132/; classtype:trojan-activity;sid:84483232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3619986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_amd64"; depth:12; endswith; nocase; http.host; content:"hcsnet.com.br"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_08; reference:url, urlhaus.abuse.ch/url/3619986/; classtype:trojan-activity;sid:84483086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3619984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"hcsnet.com.br"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_08; reference:url, urlhaus.abuse.ch/url/3619984/; classtype:trojan-activity;sid:84483084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3619985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux_x86"; depth:10; endswith; nocase; http.host; content:"hcsnet.com.br"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_08; reference:url, urlhaus.abuse.ch/url/3619985/; classtype:trojan-activity;sid:84483085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.129.100.123"; depth:15; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617428/; classtype:trojan-activity;sid:84480528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.93.200.20"; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617421/; classtype:trojan-activity;sid:84480521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19000101/av.scr"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617201/; classtype:trojan-activity;sid:84480301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19000101/photo.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617196/; classtype:trojan-activity;sid:84480296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19000101/video.scr"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617193/; classtype:trojan-activity;sid:84480293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19000101/av.lnk"; depth:16; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617189/; classtype:trojan-activity;sid:84480289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19000101/video.lnk"; depth:19; endswith; nocase; http.host; content:"111.59.254.165"; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617190/; classtype:trojan-activity;sid:84480290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3615696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.55.126.179"; depth:12; isdataat:!1,relative; metadata:created_at 2025_09_02; reference:url, urlhaus.abuse.ch/url/3615696/; classtype:trojan-activity;sid:84478796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3614697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/windowsupdate.exe"; depth:18; endswith; nocase; http.host; content:"129.152.20.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_31; reference:url, urlhaus.abuse.ch/url/3614697/; classtype:trojan-activity;sid:84477797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3614696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/windows.x64.silent.cpu.exe"; depth:27; endswith; nocase; http.host; content:"129.152.20.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_31; reference:url, urlhaus.abuse.ch/url/3614696/; classtype:trojan-activity;sid:84477796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3614280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d/mzjfndu3ndewnzjf/dvgihou177.bin"; depth:34; endswith; nocase; http.host; content:"od.lk"; depth:5; isdataat:!1,relative; metadata:created_at 2025_08_30; reference:url, urlhaus.abuse.ch/url/3614280/; classtype:trojan-activity;sid:84477380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3614199)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/827-mh1-3t/827/main/t1.png"; depth:27; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_30; reference:url, urlhaus.abuse.ch/url/3614199/; classtype:trojan-activity;sid:84477299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3613629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/pinaview.exe"; depth:23; endswith; nocase; http.host; content:"pinaview.com"; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_29; reference:url, urlhaus.abuse.ch/url/3613629/; classtype:trojan-activity;sid:84476729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3613494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peterson643eu/projecttop/refs/heads/main/zjqppajn.exe"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_29; reference:url, urlhaus.abuse.ch/url/3613494/; classtype:trojan-activity;sid:84476594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3613214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.43.76.100"; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_28; reference:url, urlhaus.abuse.ch/url/3613214/; classtype:trojan-activity;sid:84476314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3612304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"95.43.76.100"; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_27; reference:url, urlhaus.abuse.ch/url/3612304/; classtype:trojan-activity;sid:84475404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3612153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vywerrzo27.hta"; depth:15; endswith; nocase; http.host; content:"1h.xeteloi4.ru"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_26; reference:url, urlhaus.abuse.ch/url/3612153/; classtype:trojan-activity;sid:84475253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3611504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/usbmmidd_v2.zip"; depth:26; endswith; nocase; http.host; content:"www.amyuni.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_25; reference:url, urlhaus.abuse.ch/url/3611504/; classtype:trojan-activity;sid:84474604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3611488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4pi3llms81.hta"; depth:15; endswith; nocase; http.host; content:"1h.vuregyy1.ru"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_25; reference:url, urlhaus.abuse.ch/url/3611488/; classtype:trojan-activity;sid:84474588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"94.72.35.59"; depth:11; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610702/; classtype:trojan-activity;sid:84473802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tfsoft/xftd/v2/ctf/"; depth:20; endswith; nocase; http.host; content:"tengfeidn.cn"; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610613/; classtype:trojan-activity;sid:84473713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tfsoft/xftd/v2/ctf/"; depth:20; endswith; nocase; http.host; content:"pcupd.com"; depth:9; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610612/; classtype:trojan-activity;sid:84473712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/upgrade/jd"; depth:15; endswith; nocase; http.host; content:"rdm.91yunma.cn"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610604/; classtype:trojan-activity;sid:84473704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api/upgrade/qcoin"; depth:18; endswith; nocase; http.host; content:"rdm.91yunma.cn"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610602/; classtype:trojan-activity;sid:84473702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/temp/mely.exe"; depth:14; endswith; nocase; http.host; content:"areyouready.co.za"; depth:17; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610401/; classtype:trojan-activity;sid:84473501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/loic/raw/refs/heads/master/loic.exe"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610381/; classtype:trojan-activity;sid:84473481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raizydaizy/steamcmd/raw/refs/heads/main/steamcmd.exe"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610380/; classtype:trojan-activity;sid:84473480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/22072024080730/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608522/; classtype:trojan-activity;sid:84471622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/17062024123023/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608521/; classtype:trojan-activity;sid:84471621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608520)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/14082024082341/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608520/; classtype:trojan-activity;sid:84471620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/09072024080408/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608519/; classtype:trojan-activity;sid:84471619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/11072024072520/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608518/; classtype:trojan-activity;sid:84471618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8029/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608517/; classtype:trojan-activity;sid:84471617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/10092024072747/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608511/; classtype:trojan-activity;sid:84471611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/23092024080311/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608513/; classtype:trojan-activity;sid:84471613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/02082024071413/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608506/; classtype:trojan-activity;sid:84471606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/23092024103542/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608503/; classtype:trojan-activity;sid:84471603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/15072024075523/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608500/; classtype:trojan-activity;sid:84471600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/13082024070204/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608487/; classtype:trojan-activity;sid:84471587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/14062024075221/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608488/; classtype:trojan-activity;sid:84471588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/12082024075637/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608491/; classtype:trojan-activity;sid:84471591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/16082024071234/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608492/; classtype:trojan-activity;sid:84471592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/13072024070443/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608493/; classtype:trojan-activity;sid:84471593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/18062024074945/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608496/; classtype:trojan-activity;sid:84471596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8051/22082024110801/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608497/; classtype:trojan-activity;sid:84471597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/12092024121832/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608482/; classtype:trojan-activity;sid:84471582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8461/info.zip"; depth:42; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608483/; classtype:trojan-activity;sid:84471583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/10092024080037/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608479/; classtype:trojan-activity;sid:84471579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/28082024112055/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608471/; classtype:trojan-activity;sid:84471571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/11062024140819/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608474/; classtype:trojan-activity;sid:84471574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/6011/25072024071607/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608470/; classtype:trojan-activity;sid:84471570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8059/17082024070657/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608466/; classtype:trojan-activity;sid:84471566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/8050/11072024122345/info.zip"; depth:57; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608467/; classtype:trojan-activity;sid:84471567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3607915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linpeas.sh"; depth:11; endswith; nocase; http.host; content:"34.70.102.215"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3607915/; classtype:trojan-activity;sid:84471015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d1ovu/pon/refs/heads/main/rustmedebyg.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606770/; classtype:trojan-activity;sid:84469870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d1ovu/pon/refs/heads/main/rustme.exe"; depth:37; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606767/; classtype:trojan-activity;sid:84469867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d1ovu/pon/refs/heads/main/debugconfig.bat"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606766/; classtype:trojan-activity;sid:84469866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atu.lim"; depth:8; endswith; nocase; http.host; content:"electri.billregulator.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606680/; classtype:trojan-activity;sid:84469780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3605993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"150.187.25.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_18; reference:url, urlhaus.abuse.ch/url/3605993/; classtype:trojan-activity;sid:84469093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3605878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot.zip"; depth:8; endswith; nocase; http.host; content:"130.61.147.74"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_18; reference:url, urlhaus.abuse.ch/url/3605878/; classtype:trojan-activity;sid:84468978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3604879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keepon.exe"; depth:11; endswith; nocase; http.host; content:"209.145.51.44"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_16; reference:url, urlhaus.abuse.ch/url/3604879/; classtype:trojan-activity;sid:84467979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3604243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"121.202.196.93"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_15; reference:url, urlhaus.abuse.ch/url/3604243/; classtype:trojan-activity;sid:84467343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3601597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/runtime/vc_redist.x64.exe"; depth:26; endswith; nocase; http.host; content:"checkfivem.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_13; reference:url, urlhaus.abuse.ch/url/3601597/; classtype:trojan-activity;sid:84464697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3599816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.147.91.21"; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_09; reference:url, urlhaus.abuse.ch/url/3599816/; classtype:trojan-activity;sid:84462916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3597379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.exe"; depth:6; endswith; nocase; http.host; content:"117.72.183.111"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_06; reference:url, urlhaus.abuse.ch/url/3597379/; classtype:trojan-activity;sid:84460479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3597150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zmyjungmin/img001.exe"; depth:22; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_05; reference:url, urlhaus.abuse.ch/url/3597150/; classtype:trojan-activity;sid:84460250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3595203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.241.78.146"; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_02; reference:url, urlhaus.abuse.ch/url/3595203/; classtype:trojan-activity;sid:84458303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3594962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.ssa/t1.png"; depth:12; endswith; nocase; http.host; content:"isiore.com.co"; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_02; reference:url, urlhaus.abuse.ch/url/3594962/; classtype:trojan-activity;sid:84458062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3594942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r00tnik8/zianr35524869492586/raw/refs/heads/main/plugin3.plg"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_08_02; reference:url, urlhaus.abuse.ch/url/3594942/; classtype:trojan-activity;sid:84458042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3592038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/image/cache/data/aksesuarlar/patch-yama-arma/skid-row-500x500.jpg"; depth:66; endswith; nocase; http.host; content:"xshop.com.tr"; depth:12; isdataat:!1,relative; metadata:created_at 2025_07_29; reference:url, urlhaus.abuse.ch/url/3592038/; classtype:trojan-activity;sid:84455138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amineamine284/d3dx11_45/refs/heads/main/d3dx11_45.dll"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590749/; classtype:trojan-activity;sid:84453849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amineamine284/rssdgxgr/refs/heads/main/garo%20x.exe"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590748/; classtype:trojan-activity;sid:84453848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amineamine284/edggqdsg/refs/heads/main/garo%20v1.dll"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590746/; classtype:trojan-activity;sid:84453846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hafiz12cyber/request/raw/refs/heads/main/launcher.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590552/; classtype:trojan-activity;sid:84453652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/midkourtbbe/network/raw/refs/heads/main/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590550/; classtype:trojan-activity;sid:84453650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anno29/web/raw/refs/heads/main/software.zip"; depth:44; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590549/; classtype:trojan-activity;sid:84453649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notcat999/sys/raw/refs/heads/main/software.zip"; depth:47; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590548/; classtype:trojan-activity;sid:84453648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gethalal-007/request/raw/refs/heads/main/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590547/; classtype:trojan-activity;sid:84453647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nullarchive/request/raw/refs/heads/main/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590546/; classtype:trojan-activity;sid:84453646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3589312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.24.52.121"; depth:12; isdataat:!1,relative; metadata:created_at 2025_07_25; reference:url, urlhaus.abuse.ch/url/3589312/; classtype:trojan-activity;sid:84452412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3589307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"88.24.52.121"; depth:12; isdataat:!1,relative; metadata:created_at 2025_07_25; reference:url, urlhaus.abuse.ch/url/3589307/; classtype:trojan-activity;sid:84452407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3587551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//2025/07/19/15/683192372.png"; depth:29; endswith; nocase; http.host; content:"www2.0zz0.com"; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_21; reference:url, urlhaus.abuse.ch/url/3587551/; classtype:trojan-activity;sid:84450651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3585169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.236.116.198"; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3585169/; classtype:trojan-activity;sid:84448269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3585053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/catalog/model/cummersmg.exe"; depth:28; endswith; nocase; http.host; content:"kavacanada.ca"; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3585053/; classtype:trojan-activity;sid:84448153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3585052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/catalog/model/cheekpiecegar.ps1"; depth:32; endswith; nocase; http.host; content:"kavacanada.ca"; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3585052/; classtype:trojan-activity;sid:84448152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3584739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"177.247.2.226"; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3584739/; classtype:trojan-activity;sid:84447839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3584733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"89.101.123.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3584733/; classtype:trojan-activity;sid:84447833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3584719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"61.2.45.191"; depth:11; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3584719/; classtype:trojan-activity;sid:84447819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3583571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"177.70.102.228"; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_15; reference:url, urlhaus.abuse.ch/url/3583571/; classtype:trojan-activity;sid:84446671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3583040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laurenxss/42429a19c72b875b93608f8cb0cab933/raw/"; depth:48; endswith; nocase; http.host; content:"gist.githubusercontent.com"; depth:26; isdataat:!1,relative; metadata:created_at 2025_07_14; reference:url, urlhaus.abuse.ch/url/3583040/; classtype:trojan-activity;sid:84446140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3582620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"61.2.45.172"; depth:11; isdataat:!1,relative; metadata:created_at 2025_07_13; reference:url, urlhaus.abuse.ch/url/3582620/; classtype:trojan-activity;sid:84445720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3580902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"61.2.45.141"; depth:11; isdataat:!1,relative; metadata:created_at 2025_07_11; reference:url, urlhaus.abuse.ch/url/3580902/; classtype:trojan-activity;sid:84444002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3580881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.240.70.185"; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_11; reference:url, urlhaus.abuse.ch/url/3580881/; classtype:trojan-activity;sid:84443981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3580884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"121.202.153.132"; depth:15; isdataat:!1,relative; metadata:created_at 2025_07_11; reference:url, urlhaus.abuse.ch/url/3580884/; classtype:trojan-activity;sid:84443984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3578386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invisiblebunny/records/main/bunny-mini/mini.shell.php"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_07; reference:url, urlhaus.abuse.ch/url/3578386/; classtype:trojan-activity;sid:84441486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3578385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ly4k/pwnkit/main/pwnkit"; depth:24; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_07; reference:url, urlhaus.abuse.ch/url/3578385/; classtype:trojan-activity;sid:84441485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/allbnc.jpg"; depth:11; endswith; nocase; http.host; content:"185.253.75.188"; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_05; reference:url, urlhaus.abuse.ch/url/3575978/; classtype:trojan-activity;sid:84439078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/auto.jpg"; depth:9; endswith; nocase; http.host; content:"185.253.75.188"; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_05; reference:url, urlhaus.abuse.ch/url/3575979/; classtype:trojan-activity;sid:84439079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.sh"; depth:5; endswith; nocase; http.host; content:"185.253.75.188"; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_05; reference:url, urlhaus.abuse.ch/url/3575971/; classtype:trojan-activity;sid:84439071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cata2.jpg"; depth:10; endswith; nocase; http.host; content:"185.253.75.188"; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_05; reference:url, urlhaus.abuse.ch/url/3575892/; classtype:trojan-activity;sid:84438992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labubu99999/localoco8386/main/shaman.zip"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_04; reference:url, urlhaus.abuse.ch/url/3575355/; classtype:trojan-activity;sid:84438455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labubu99999/localoco8386/raw/main/update0.bat"; depth:46; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_04; reference:url, urlhaus.abuse.ch/url/3575354/; classtype:trojan-activity;sid:84438454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3573965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"222.239.87.50"; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_02; reference:url, urlhaus.abuse.ch/url/3573965/; classtype:trojan-activity;sid:84437065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3573963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"110.227.197.204"; depth:15; isdataat:!1,relative; metadata:created_at 2025_07_02; reference:url, urlhaus.abuse.ch/url/3573963/; classtype:trojan-activity;sid:84437063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3573084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chrome_134.exe"; depth:15; endswith; nocase; http.host; content:"lomejordesalamanca.es"; depth:21; isdataat:!1,relative; metadata:created_at 2025_07_01; reference:url, urlhaus.abuse.ch/url/3573084/; classtype:trojan-activity;sid:84436184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3572294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"121.202.142.68"; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_01; reference:url, urlhaus.abuse.ch/url/3572294/; classtype:trojan-activity;sid:84435394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3570158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"90.8.83.87"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_25; reference:url, urlhaus.abuse.ch/url/3570158/; classtype:trojan-activity;sid:84433258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3569802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"90.8.83.87"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_24; reference:url, urlhaus.abuse.ch/url/3569802/; classtype:trojan-activity;sid:84432902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3569803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"90.8.83.87"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_24; reference:url, urlhaus.abuse.ch/url/3569803/; classtype:trojan-activity;sid:84432903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3569088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/images/trapapo.ps1"; depth:31; endswith; nocase; http.host; content:"www.vuelaviajero.com"; depth:20; isdataat:!1,relative; metadata:created_at 2025_06_22; reference:url, urlhaus.abuse.ch/url/3569088/; classtype:trojan-activity;sid:84432188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3568977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aminer.gz"; depth:10; endswith; nocase; http.host; content:"162.215.218.82"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_21; reference:url, urlhaus.abuse.ch/url/3568977/; classtype:trojan-activity;sid:84432077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3568976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install.tgz"; depth:12; endswith; nocase; http.host; content:"162.215.218.82"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_21; reference:url, urlhaus.abuse.ch/url/3568976/; classtype:trojan-activity;sid:84432076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3568837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"47.96.106.127"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_20; reference:url, urlhaus.abuse.ch/url/3568837/; classtype:trojan-activity;sid:84431937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3568238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new_image.jpg"; depth:14; endswith; nocase; http.host; content:"talentrecruitments.com"; depth:22; isdataat:!1,relative; metadata:created_at 2025_06_19; reference:url, urlhaus.abuse.ch/url/3568238/; classtype:trojan-activity;sid:84431338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3568230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/js/new_image.jpg"; depth:17; endswith; nocase; http.host; content:"talentrecruitments.com"; depth:22; isdataat:!1,relative; metadata:created_at 2025_06_19; reference:url, urlhaus.abuse.ch/url/3568230/; classtype:trojan-activity;sid:84431330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3568006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xl.txt"; depth:7; endswith; nocase; http.host; content:"mundocarnes.cl"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3568006/; classtype:trojan-activity;sid:84431106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/jurisdict/dao/info.zip"; depth:78; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565262/; classtype:trojan-activity;sid:84428362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp%20-%20copia/badmail/info.zip"; depth:36; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565260/; classtype:trojan-activity;sid:84428360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/1/info.zip"; depth:23; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565261/; classtype:trojan-activity;sid:84428361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/1/info.zip"; depth:37; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565259/; classtype:trojan-activity;sid:84428359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp%20-%20copia/info.zip"; depth:28; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565258/; classtype:trojan-activity;sid:84428358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/delcacheprodutoseg/info.zip"; depth:35; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565257/; classtype:trojan-activity;sid:84428357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bkp/info.zip"; depth:13; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565256/; classtype:trojan-activity;sid:84428356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp%20-%20copia/queue/info.zip"; depth:34; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565255/; classtype:trojan-activity;sid:84428355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/relftp/info.zip"; depth:16; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565254/; classtype:trojan-activity;sid:84428354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp%20-%20copia/drop/info.zip"; depth:33; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565253/; classtype:trojan-activity;sid:84428353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp/info.zip"; depth:16; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565252/; classtype:trojan-activity;sid:84428352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp%20-%20copia/pickup/info.zip"; depth:35; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565249/; classtype:trojan-activity;sid:84428349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/h4lud3ae/info.zip"; depth:18; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565244/; classtype:trojan-activity;sid:84428344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/info.zip"; depth:17; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565245/; classtype:trojan-activity;sid:84428345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/cons/info.zip"; depth:21; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565246/; classtype:trojan-activity;sid:84428346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/relftp/pdf/info.zip"; depth:20; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565243/; classtype:trojan-activity;sid:84428343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/1/info.zip"; depth:26; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565230/; classtype:trojan-activity;sid:84428330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/idi/info.zip"; depth:13; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565236/; classtype:trojan-activity;sid:84428336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmpftp/extcons/info.zip"; depth:24; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565239/; classtype:trojan-activity;sid:84428339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/exeftp%20-%20copia/idi/info.zip"; depth:32; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565240/; classtype:trojan-activity;sid:84428340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gdbftp/info.zip"; depth:16; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565241/; classtype:trojan-activity;sid:84428341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/cksy/info.zip"; depth:98; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565091/; classtype:trojan-activity;sid:84428191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/log/service/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565090/; classtype:trojan-activity;sid:84428190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/rgsy/info.zip"; depth:98; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565089/; classtype:trojan-activity;sid:84428189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/chkptwss/dto/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565088/; classtype:trojan-activity;sid:84428188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/entity/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565087/; classtype:trojan-activity;sid:84428187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/info.zip"; depth:62; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565085/; classtype:trojan-activity;sid:84428185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/info.zip"; depth:80; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565086/; classtype:trojan-activity;sid:84428186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/info.zip"; depth:74; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565084/; classtype:trojan-activity;sid:84428184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/entity/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565083/; classtype:trojan-activity;sid:84428183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/utils/constrant/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565082/; classtype:trojan-activity;sid:84428182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/nvrsetting/dao/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565081/; classtype:trojan-activity;sid:84428181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/info.zip"; depth:57; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565080/; classtype:trojan-activity;sid:84428180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/log/info.zip"; depth:78; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565079/; classtype:trojan-activity;sid:84428179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/log/info.zip"; depth:83; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565078/; classtype:trojan-activity;sid:84428178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565077/; classtype:trojan-activity;sid:84428177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/chkptwss/info.zip"; depth:80; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565076/; classtype:trojan-activity;sid:84428176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/static/images/new/info.zip"; depth:48; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565075/; classtype:trojan-activity;sid:84428175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/info.zip"; depth:54; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565074/; classtype:trojan-activity;sid:84428174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/photoset/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565073/; classtype:trojan-activity;sid:84428173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/templete/info.zip"; depth:55; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565072/; classtype:trojan-activity;sid:84428172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/service/impl/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565071/; classtype:trojan-activity;sid:84428171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/action/info.zip"; depth:76; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565070/; classtype:trojan-activity;sid:84428170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/vehiclereview/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565069/; classtype:trojan-activity;sid:84428169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/root/org/info.zip"; depth:50; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565068/; classtype:trojan-activity;sid:84428168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/static/css1/info.zip"; depth:42; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565066/; classtype:trojan-activity;sid:84428166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/cksy/base/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565067/; classtype:trojan-activity;sid:84428167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/zbawss/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565065/; classtype:trojan-activity;sid:84428165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/nvrsetting/entity/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565064/; classtype:trojan-activity;sid:84428164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/set/info.zip"; depth:75; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565062/; classtype:trojan-activity;sid:84428162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/dto/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565063/; classtype:trojan-activity;sid:84428163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/service/info.zip"; depth:91; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565061/; classtype:trojan-activity;sid:84428161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/root/org/apache/info.zip"; depth:57; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565060/; classtype:trojan-activity;sid:84428160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/templete/info.zip"; depth:59; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565059/; classtype:trojan-activity;sid:84428159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/photo/info.zip"; depth:36; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565057/; classtype:trojan-activity;sid:84428157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/service/info.zip"; depth:92; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565058/; classtype:trojan-activity;sid:84428158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/entity/info.zip"; depth:90; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565056/; classtype:trojan-activity;sid:84428156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/info.zip"; depth:78; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565054/; classtype:trojan-activity;sid:84428154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/service/impl/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565049/; classtype:trojan-activity;sid:84428149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/hdk/localxml.zip"; depth:54; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565050/; classtype:trojan-activity;sid:84428150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/static/info.zip"; depth:37; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565051/; classtype:trojan-activity;sid:84428151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/gbrwss/dto/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565048/; classtype:trojan-activity;sid:84428148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/viewwss/action/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565044/; classtype:trojan-activity;sid:84428144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/entity/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565043/; classtype:trojan-activity;sid:84428143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/cksy/servacpt/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565040/; classtype:trojan-activity;sid:84428140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/temp/info.zip"; depth:22; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565035/; classtype:trojan-activity;sid:84428135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/dto/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565034/; classtype:trojan-activity;sid:84428134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/pdauser/action/info.zip"; depth:94; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565030/; classtype:trojan-activity;sid:84428130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/sysparam/info.zip"; depth:80; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565029/; classtype:trojan-activity;sid:84428129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/info.zip"; depth:38; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565024/; classtype:trojan-activity;sid:84428124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/client/info.zip"; depth:70; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565017/; classtype:trojan-activity;sid:84428117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/info.zip"; depth:31; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565018/; classtype:trojan-activity;sid:84428118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/info.zip"; depth:81; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565016/; classtype:trojan-activity;sid:84428116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/info.zip"; depth:80; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565015/; classtype:trojan-activity;sid:84428115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/dao/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565014/; classtype:trojan-activity;sid:84428114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/interceptor/info.zip"; depth:81; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565008/; classtype:trojan-activity;sid:84428108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/plugin/info.zip"; depth:37; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565009/; classtype:trojan-activity;sid:84428109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/dto/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565010/; classtype:trojan-activity;sid:84428110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/info.zip"; depth:71; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565011/; classtype:trojan-activity;sid:84428111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/info.zip"; depth:77; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565004/; classtype:trojan-activity;sid:84428104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/info.zip"; depth:66; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565001/; classtype:trojan-activity;sid:84428101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/dto/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564999/; classtype:trojan-activity;sid:84428099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/service/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564992/; classtype:trojan-activity;sid:84428092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/mgr/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564993/; classtype:trojan-activity;sid:84428093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/visitwss/info.zip"; depth:90; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564990/; classtype:trojan-activity;sid:84428090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/info.zip"; depth:54; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564988/; classtype:trojan-activity;sid:84428088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/wss/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564986/; classtype:trojan-activity;sid:84428086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/pdawss/dto/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564985/; classtype:trojan-activity;sid:84428085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564984/; classtype:trojan-activity;sid:84428084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/info.zip"; depth:68; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564983/; classtype:trojan-activity;sid:84428083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/exception/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564980/; classtype:trojan-activity;sid:84428080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/dao/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564979/; classtype:trojan-activity;sid:84428079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564977/; classtype:trojan-activity;sid:84428077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/nvrsetting/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564975/; classtype:trojan-activity;sid:84428075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/dao/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564976/; classtype:trojan-activity;sid:84428076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/service/impl/info.zip"; depth:95; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564974/; classtype:trojan-activity;sid:84428074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/dao/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564972/; classtype:trojan-activity;sid:84428072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/hdk/localxml.zip"; depth:58; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564971/; classtype:trojan-activity;sid:84428071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/info.zip"; depth:17; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564969/; classtype:trojan-activity;sid:84428069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/jurisdict/service/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564968/; classtype:trojan-activity;sid:84428068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/rgsy/info.zip"; depth:59; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564966/; classtype:trojan-activity;sid:84428066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/dao/info.zip"; depth:92; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564965/; classtype:trojan-activity;sid:84428065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/info.zip"; depth:64; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564964/; classtype:trojan-activity;sid:84428064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/info.zip"; depth:71; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564960/; classtype:trojan-activity;sid:84428060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aspnet_client/system_web/info.zip"; depth:34; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564961/; classtype:trojan-activity;sid:84428061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/dto/info.zip"; depth:91; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564958/; classtype:trojan-activity;sid:84428058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/action/info.zip"; depth:96; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564957/; classtype:trojan-activity;sid:84428057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/conf/catalina/info.zip"; depth:31; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564956/; classtype:trojan-activity;sid:84428056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/info.zip"; depth:81; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564953/; classtype:trojan-activity;sid:84428053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/service/impl/info.zip"; depth:91; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564948/; classtype:trojan-activity;sid:84428048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/info.zip"; depth:50; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564949/; classtype:trojan-activity;sid:84428049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2345downloads/info.zip"; depth:23; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564944/; classtype:trojan-activity;sid:84428044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/lib/info.zip"; depth:46; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564937/; classtype:trojan-activity;sid:84428037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/info.zip"; depth:62; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564938/; classtype:trojan-activity;sid:84428038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/service/impl/info.zip"; depth:76; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564939/; classtype:trojan-activity;sid:84428039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/record/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564940/; classtype:trojan-activity;sid:84428040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/info.zip"; depth:69; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564935/; classtype:trojan-activity;sid:84428035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/jurisdict/info.zip"; depth:74; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564936/; classtype:trojan-activity;sid:84428036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/mgr/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564931/; classtype:trojan-activity;sid:84428031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/nvrsetting/info.zip"; depth:90; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564927/; classtype:trojan-activity;sid:84428027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/static/css1/_notes/info.zip"; depth:49; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564925/; classtype:trojan-activity;sid:84428025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/rgsy/system/info.zip"; depth:66; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564926/; classtype:trojan-activity;sid:84428026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/info.zip"; depth:77; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564924/; classtype:trojan-activity;sid:84428024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/base/dto/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564920/; classtype:trojan-activity;sid:84428020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/checksetting/web/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564908/; classtype:trojan-activity;sid:84428008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/info.zip"; depth:44; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564909/; classtype:trojan-activity;sid:84428009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/lib/info.zip"; depth:48; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564906/; classtype:trojan-activity;sid:84428006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/base/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564903/; classtype:trojan-activity;sid:84428003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/unusual/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564902/; classtype:trojan-activity;sid:84428002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/info.zip"; depth:78; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564900/; classtype:trojan-activity;sid:84428000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/pub/info.zip"; depth:58; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564899/; classtype:trojan-activity;sid:84427999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/info.zip"; depth:61; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564898/; classtype:trojan-activity;sid:84427998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/cyzpdytemp/info.zip"; depth:36; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564895/; classtype:trojan-activity;sid:84427995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/systemset/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564896/; classtype:trojan-activity;sid:84427996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/viewwss/info.zip"; depth:79; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564893/; classtype:trojan-activity;sid:84427993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/util/info.zip"; depth:68; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564894/; classtype:trojan-activity;sid:84427994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/wss/util/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564892/; classtype:trojan-activity;sid:84427992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/utils/info.zip"; depth:75; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564888/; classtype:trojan-activity;sid:84427988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/util/nvr/info.zip"; depth:72; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564889/; classtype:trojan-activity;sid:84427989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564882/; classtype:trojan-activity;sid:84427982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/cksy/info.zip"; depth:59; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564883/; classtype:trojan-activity;sid:84427983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/sysparam/info.zip"; depth:90; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564881/; classtype:trojan-activity;sid:84427981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/bin/tomcat8.exe"; depth:24; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564878/; classtype:trojan-activity;sid:84427978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/info.zip"; depth:58; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564876/; classtype:trojan-activity;sid:84427976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/info.zip"; depth:63; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564874/; classtype:trojan-activity;sid:84427974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/dao/info.zip"; depth:75; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564871/; classtype:trojan-activity;sid:84427971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/chkptwss/dao/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564866/; classtype:trojan-activity;sid:84427966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/action/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564861/; classtype:trojan-activity;sid:84427961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/info.zip"; depth:54; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564862/; classtype:trojan-activity;sid:84427962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/viewwss/dto/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564863/; classtype:trojan-activity;sid:84427963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/cksy/vehicleinformation/info.zip"; depth:98; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564858/; classtype:trojan-activity;sid:84427958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/logs/info.zip"; depth:22; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564859/; classtype:trojan-activity;sid:84427959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/entity/info.zip"; depth:81; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564855/; classtype:trojan-activity;sid:84427955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/log/entity/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564852/; classtype:trojan-activity;sid:84427952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/info.zip"; depth:83; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564850/; classtype:trojan-activity;sid:84427950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/gbrwrite/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564849/; classtype:trojan-activity;sid:84427949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/utils/excel/info.zip"; depth:81; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564847/; classtype:trojan-activity;sid:84427947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/service/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564845/; classtype:trojan-activity;sid:84427945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/szclient/info.zip"; depth:72; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564844/; classtype:trojan-activity;sid:84427944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/futai/info.zip"; depth:15; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564838/; classtype:trojan-activity;sid:84427938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564839/; classtype:trojan-activity;sid:84427939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/service/info.zip"; depth:81; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564832/; classtype:trojan-activity;sid:84427932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/checksetting/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564819/; classtype:trojan-activity;sid:84427919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/chkptwss/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564820/; classtype:trojan-activity;sid:84427920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/gbrwrite/dto/info.zip"; depth:92; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564821/; classtype:trojan-activity;sid:84427921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/service/impl/info.zip"; depth:97; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564822/; classtype:trojan-activity;sid:84427922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/info.zip"; depth:42; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564823/; classtype:trojan-activity;sid:84427923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/jurisdict/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564809/; classtype:trojan-activity;sid:84427909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/set/service/info.zip"; depth:83; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564810/; classtype:trojan-activity;sid:84427910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/utils/exception/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564812/; classtype:trojan-activity;sid:84427912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/hdk/hcnetsdkcom/info.zip"; depth:66; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564807/; classtype:trojan-activity;sid:84427907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564808/; classtype:trojan-activity;sid:84427908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/dao/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564804/; classtype:trojan-activity;sid:84427904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/chkptwss/mgr/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564801/; classtype:trojan-activity;sid:84427901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/info.zip"; depth:36; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564800/; classtype:trojan-activity;sid:84427900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/pub/info.zip"; depth:78; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564799/; classtype:trojan-activity;sid:84427899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/cksy/info.zip"; depth:79; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564797/; classtype:trojan-activity;sid:84427897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/info.zip"; depth:58; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564796/; classtype:trojan-activity;sid:84427896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/info.zip"; depth:50; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564794/; classtype:trojan-activity;sid:84427894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/info.zip"; depth:64; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564793/; classtype:trojan-activity;sid:84427893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/hdk/hcnetsdkcom/info.zip"; depth:62; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564791/; classtype:trojan-activity;sid:84427891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/info.zip"; depth:60; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564787/; classtype:trojan-activity;sid:84427887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/pub/info.zip"; depth:97; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564785/; classtype:trojan-activity;sid:84427885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/service/info.zip"; depth:71; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564783/; classtype:trojan-activity;sid:84427883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/viewwss/info.zip"; depth:81; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564784/; classtype:trojan-activity;sid:84427884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/info.zip"; depth:74; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564781/; classtype:trojan-activity;sid:84427881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/static/js/info.zip"; depth:40; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564782/; classtype:trojan-activity;sid:84427882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/com/info.zip"; depth:42; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564780/; classtype:trojan-activity;sid:84427880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/web/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564778/; classtype:trojan-activity;sid:84427878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/base/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564777/; classtype:trojan-activity;sid:84427877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/dto/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564776/; classtype:trojan-activity;sid:84427876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564769/; classtype:trojan-activity;sid:84427869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/meta-inf/info.zip"; depth:43; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564770/; classtype:trojan-activity;sid:84427870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/wss/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564771/; classtype:trojan-activity;sid:84427871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/root/org/apache/jsp/info.zip"; depth:61; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564766/; classtype:trojan-activity;sid:84427866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/utils/nvr/info.zip"; depth:79; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564761/; classtype:trojan-activity;sid:84427861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/web/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564760/; classtype:trojan-activity;sid:84427860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/meta-inf/info.zip"; depth:45; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564755/; classtype:trojan-activity;sid:84427855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/service/info.zip"; depth:92; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564756/; classtype:trojan-activity;sid:84427856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/conf/info.zip"; depth:22; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564757/; classtype:trojan-activity;sid:84427857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/mgr/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564753/; classtype:trojan-activity;sid:84427853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/gbrwrite/action/info.zip"; depth:95; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564752/; classtype:trojan-activity;sid:84427852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/visitwss/dao/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564749/; classtype:trojan-activity;sid:84427849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564748/; classtype:trojan-activity;sid:84427848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/dto/info.zip"; depth:91; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564747/; classtype:trojan-activity;sid:84427847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/static/css/info.zip"; depth:41; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564746/; classtype:trojan-activity;sid:84427846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/viewwss/mgr/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564743/; classtype:trojan-activity;sid:84427843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/service/impl/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564739/; classtype:trojan-activity;sid:84427839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/chkptwss/dto/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564740/; classtype:trojan-activity;sid:84427840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/gbrwss/action/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564737/; classtype:trojan-activity;sid:84427837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/exception/info.zip"; depth:99; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564734/; classtype:trojan-activity;sid:84427834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564735/; classtype:trojan-activity;sid:84427835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/dao/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564736/; classtype:trojan-activity;sid:84427836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/static/images/info.zip"; depth:44; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564731/; classtype:trojan-activity;sid:84427831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/download/info.zip"; depth:39; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564726/; classtype:trojan-activity;sid:84427826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/info.zip"; depth:64; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564724/; classtype:trojan-activity;sid:84427824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/hdk/info.zip"; depth:50; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564725/; classtype:trojan-activity;sid:84427825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/controller/info.zip"; depth:94; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564720/; classtype:trojan-activity;sid:84427820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/dto/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564717/; classtype:trojan-activity;sid:84427817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/info.zip"; depth:22; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564718/; classtype:trojan-activity;sid:84427818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xinheyuan/info.zip"; depth:19; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564715/; classtype:trojan-activity;sid:84427815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/dao/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564713/; classtype:trojan-activity;sid:84427813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/dao/info.zip"; depth:78; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564711/; classtype:trojan-activity;sid:84427811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/mgr/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564706/; classtype:trojan-activity;sid:84427806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/info.zip"; depth:46; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564703/; classtype:trojan-activity;sid:84427803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/service/impl/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564704/; classtype:trojan-activity;sid:84427804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/mgr/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564700/; classtype:trojan-activity;sid:84427800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/dao/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564697/; classtype:trojan-activity;sid:84427797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/info.zip"; depth:74; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564693/; classtype:trojan-activity;sid:84427793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/static/images/icons/info.zip"; depth:50; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564694/; classtype:trojan-activity;sid:84427794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/hdk/info.zip"; depth:54; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564685/; classtype:trojan-activity;sid:84427785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/info.zip"; depth:74; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564686/; classtype:trojan-activity;sid:84427786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/service/info.zip"; depth:79; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564687/; classtype:trojan-activity;sid:84427787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/mgr/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564681/; classtype:trojan-activity;sid:84427781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564682/; classtype:trojan-activity;sid:84427782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/lib/info.zip"; depth:42; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564675/; classtype:trojan-activity;sid:84427775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564674/; classtype:trojan-activity;sid:84427774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/bin/info.zip"; depth:21; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564673/; classtype:trojan-activity;sid:84427773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/pdauser/dao/info.zip"; depth:91; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564672/; classtype:trojan-activity;sid:84427772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/entity/info.zip"; depth:91; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564671/; classtype:trojan-activity;sid:84427771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/info.zip"; depth:54; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564669/; classtype:trojan-activity;sid:84427769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/jurisdict/service/impl/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564670/; classtype:trojan-activity;sid:84427770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/utils/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564666/; classtype:trojan-activity;sid:84427766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/gbrwrite/dao/info.zip"; depth:92; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564667/; classtype:trojan-activity;sid:84427767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/dao/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564665/; classtype:trojan-activity;sid:84427765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/service/impl/info.zip"; depth:97; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564659/; classtype:trojan-activity;sid:84427759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/spotckeck/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564660/; classtype:trojan-activity;sid:84427760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/entity/info.zip"; depth:91; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564653/; classtype:trojan-activity;sid:84427753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hengsheng/info.zip"; depth:19; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564654/; classtype:trojan-activity;sid:84427754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/info.zip"; depth:25; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564655/; classtype:trojan-activity;sid:84427755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/service/impl/info.zip"; depth:96; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564648/; classtype:trojan-activity;sid:84427748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/pdauser/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564644/; classtype:trojan-activity;sid:84427744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/base/dto/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564640/; classtype:trojan-activity;sid:84427740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/dao/info.zip"; depth:77; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564641/; classtype:trojan-activity;sid:84427741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/dto/info.zip"; depth:67; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564636/; classtype:trojan-activity;sid:84427736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/dao/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564638/; classtype:trojan-activity;sid:84427738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/visitwss/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564633/; classtype:trojan-activity;sid:84427733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/service/info.zip"; depth:77; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564634/; classtype:trojan-activity;sid:84427734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/info.zip"; depth:64; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564635/; classtype:trojan-activity;sid:84427735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/entity/info.zip"; depth:95; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564630/; classtype:trojan-activity;sid:84427730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/dept/info.zip"; depth:69; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564629/; classtype:trojan-activity;sid:84427729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/info.zip"; depth:41; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564620/; classtype:trojan-activity;sid:84427720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/service/info.zip"; depth:90; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564621/; classtype:trojan-activity;sid:84427721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/log/web/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564616/; classtype:trojan-activity;sid:84427716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/dept/web/info.zip"; depth:73; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564611/; classtype:trojan-activity;sid:84427711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guirui/info.zip"; depth:16; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564599/; classtype:trojan-activity;sid:84427699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/info.zip"; depth:30; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564600/; classtype:trojan-activity;sid:84427700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564601/; classtype:trojan-activity;sid:84427701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/action/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564602/; classtype:trojan-activity;sid:84427702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/action/info.zip"; depth:96; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564603/; classtype:trojan-activity;sid:84427703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/dao/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564597/; classtype:trojan-activity;sid:84427697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/gbrwss/info.zip"; depth:80; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564598/; classtype:trojan-activity;sid:84427698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/info.zip"; depth:67; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564594/; classtype:trojan-activity;sid:84427694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/info.zip"; depth:60; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564595/; classtype:trojan-activity;sid:84427695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/nvrsetting/service/info.zip"; depth:90; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564596/; classtype:trojan-activity;sid:84427696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/utils/excel/annotation/info.zip"; depth:92; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564593/; classtype:trojan-activity;sid:84427693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/set/service/impl/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564592/; classtype:trojan-activity;sid:84427692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/utils/info.zip"; depth:75; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564589/; classtype:trojan-activity;sid:84427689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/dao/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564590/; classtype:trojan-activity;sid:84427690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/service/info.zip"; depth:96; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564583/; classtype:trojan-activity;sid:84427683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/%e6%96%b0%e6%96%87%e4%bb%b6%e5%a4%b9%20(2)/info.zip"; depth:52; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564584/; classtype:trojan-activity;sid:84427684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/info.zip"; depth:34; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564585/; classtype:trojan-activity;sid:84427685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/checksetting/service/info.zip"; depth:92; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564581/; classtype:trojan-activity;sid:84427681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haohua/info.zip"; depth:16; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564578/; classtype:trojan-activity;sid:84427678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/base/info.zip"; depth:82; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564577/; classtype:trojan-activity;sid:84427677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/count/info.zip"; depth:85; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564576/; classtype:trojan-activity;sid:84427676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/checksetting/dao/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564574/; classtype:trojan-activity;sid:84427674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/info.zip"; depth:52; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564575/; classtype:trojan-activity;sid:84427675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/info.zip"; depth:69; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564569/; classtype:trojan-activity;sid:84427669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/service/impl/info.zip"; depth:101; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564568/; classtype:trojan-activity;sid:84427668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/rgsy/system/info.zip"; depth:105; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564566/; classtype:trojan-activity;sid:84427666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/chkpt/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564565/; classtype:trojan-activity;sid:84427665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/info.zip"; depth:63; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564563/; classtype:trojan-activity;sid:84427663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/controller/info.zip"; depth:89; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564561/; classtype:trojan-activity;sid:84427661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/info.zip"; depth:56; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564562/; classtype:trojan-activity;sid:84427662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/entity/info.zip"; depth:78; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564559/; classtype:trojan-activity;sid:84427659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/lib/info.zip"; depth:21; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564554/; classtype:trojan-activity;sid:84427654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/root/info.zip"; depth:46; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564542/; classtype:trojan-activity;sid:84427642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaifa/info.zip"; depth:15; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564543/; classtype:trojan-activity;sid:84427643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/dto/info.zip"; depth:93; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564544/; classtype:trojan-activity;sid:84427644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/info.zip"; depth:81; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564545/; classtype:trojan-activity;sid:84427645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/info.zip"; depth:71; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564539/; classtype:trojan-activity;sid:84427639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/viewws/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564540/; classtype:trojan-activity;sid:84427640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/pdawss/info.zip"; depth:78; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564541/; classtype:trojan-activity;sid:84427641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/web/info.zip"; depth:75; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564538/; classtype:trojan-activity;sid:84427638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/work/catalina/localhost/bfxt/info.zip"; depth:46; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564534/; classtype:trojan-activity;sid:84427634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/ckwss/info.zip"; depth:87; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564535/; classtype:trojan-activity;sid:84427635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564536)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/action/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564536/; classtype:trojan-activity;sid:84427636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/info.zip"; depth:79; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564537/; classtype:trojan-activity;sid:84427637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/info.zip"; depth:50; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564527/; classtype:trojan-activity;sid:84427627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aspnet_client/info.zip"; depth:23; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564528/; classtype:trojan-activity;sid:84427628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/web/info.zip"; depth:67; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564529/; classtype:trojan-activity;sid:84427629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/temp/poifiles/info.zip"; depth:31; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564526/; classtype:trojan-activity;sid:84427626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/report/info.zip"; depth:37; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564522/; classtype:trojan-activity;sid:84427622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/dao/info.zip"; depth:67; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564521/; classtype:trojan-activity;sid:84427621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/visitwss/dto/info.zip"; depth:86; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564519/; classtype:trojan-activity;sid:84427619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/entity/info.zip"; depth:80; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564518/; classtype:trojan-activity;sid:84427618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/info.zip"; depth:79; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564515/; classtype:trojan-activity;sid:84427615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/action/info.zip"; depth:70; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564514/; classtype:trojan-activity;sid:84427614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/dao/info.zip"; depth:88; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564509/; classtype:trojan-activity;sid:84427609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/info.zip"; depth:59; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564500/; classtype:trojan-activity;sid:84427600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/gbrwss/dao/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564502/; classtype:trojan-activity;sid:84427602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/dept/service/info.zip"; depth:77; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564498/; classtype:trojan-activity;sid:84427598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/dept/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564499/; classtype:trojan-activity;sid:84427599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/info.zip"; depth:84; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564497/; classtype:trojan-activity;sid:84427597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3563385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wxworkapis.dll"; depth:15; endswith; nocase; http.host; content:"43.139.88.161"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_17; reference:url, urlhaus.abuse.ch/url/3563385/; classtype:trojan-activity;sid:84426485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3563362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wxworkmultiopen.exe"; depth:20; endswith; nocase; http.host; content:"43.139.88.161"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_17; reference:url, urlhaus.abuse.ch/url/3563362/; classtype:trojan-activity;sid:84426462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3563068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.200.149.253"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_17; reference:url, urlhaus.abuse.ch/url/3563068/; classtype:trojan-activity;sid:84426168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mar10/wsgidav/archive/refs/heads/master.zip"; depth:44; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_17; reference:url, urlhaus.abuse.ch/url/3562926/; classtype:trojan-activity;sid:84426026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/flame/msglu32.ocx"; depth:28; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562778/; classtype:trojan-activity;sid:84425878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/energizertrojan-malware.zip"; depth:38; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562768/; classtype:trojan-activity;sid:84425868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/flame/advnetcfg.ocx"; depth:30; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562769/; classtype:trojan-activity;sid:84425869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malware/icecast2_2.0.0_vulnerable.exe"; depth:38; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562770/; classtype:trojan-activity;sid:84425870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/flame/mssecmgr.ocx"; depth:29; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562771/; classtype:trojan-activity;sid:84425871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/dnsmasq-2.73rc7.tar.gz"; depth:33; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562772/; classtype:trojan-activity;sid:84425872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/flame/boot32drv.sys"; depth:30; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562774/; classtype:trojan-activity;sid:84425874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malware/energizertrojan-malware.zip"; depth:36; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562775/; classtype:trojan-activity;sid:84425875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/flame/nteps32.ocx"; depth:28; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562766/; classtype:trojan-activity;sid:84425866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malware/dnsmasq-2.73rc7.tar.gz"; depth:31; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562767/; classtype:trojan-activity;sid:84425867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/icecast2_2.0.0_vulnerable.exe"; depth:40; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562765/; classtype:trojan-activity;sid:84425865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dangerous/flame/ccalc32.sys"; depth:28; endswith; nocase; http.host; content:"172.236.108.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562763/; classtype:trojan-activity;sid:84425863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tcp_linux_amd64"; depth:16; endswith; nocase; http.host; content:"101.43.49.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562757/; classtype:trojan-activity;sid:84425857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"191.33.171.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562707/; classtype:trojan-activity;sid:84425807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"31.28.31.6"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562674/; classtype:trojan-activity;sid:84425774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"93.116.56.78"; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562678/; classtype:trojan-activity;sid:84425778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zusyaku/malware-collection-part-2/refs/heads/main/666/666.exe"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562600/; classtype:trojan-activity;sid:84425700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp.bat"; depth:7; endswith; nocase; http.host; content:"92.127.156.174"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562599/; classtype:trojan-activity;sid:84425699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/live.lnk"; depth:9; endswith; nocase; http.host; content:"103.116.190.93"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562404/; classtype:trojan-activity;sid:84425504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uat.lnk"; depth:8; endswith; nocase; http.host; content:"103.116.190.93"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562403/; classtype:trojan-activity;sid:84425503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wyverntkc/cpuminer-gr-avx2/releases/download/1.2.4.1/cpuminer-gr-1.2.4.1-x86_64_windows.7z"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_14; reference:url, urlhaus.abuse.ch/url/3561991/; classtype:trojan-activity;sid:84425091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wyverntkc/cpuminer-gr-avx2/archive/refs/tags/1.2.4.1.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_14; reference:url, urlhaus.abuse.ch/url/3561989/; classtype:trojan-activity;sid:84425089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wyverntkc/cpuminer-gr-avx2/archive/refs/tags/1.2.4.1.tar.gz"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_14; reference:url, urlhaus.abuse.ch/url/3561990/; classtype:trojan-activity;sid:84425090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wyverntkc/cpuminer-gr-avx2/releases/download/1.2.4.1/cpuminer-gr-1.2.4.1-args-x86_64_linux.tar.gz"; depth:98; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_14; reference:url, urlhaus.abuse.ch/url/3561988/; classtype:trojan-activity;sid:84425088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invc/xfspeed/qqpcmgr/module_update/fid1746669868_runqmhunt.exe.zip"; depth:67; endswith; nocase; http.host; content:"dlied6.yz.tcdnos.com"; depth:20; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561860/; classtype:trojan-activity;sid:84424960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invc/xfspeed/qqpcmgr/module_update/fid1747308966_runqmhunt.exe.zip"; depth:67; endswith; nocase; http.host; content:"dlied6.bytes.tcdnos.com"; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561859/; classtype:trojan-activity;sid:84424959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invc/xfspeed/qqpcmgr/module_update/fid1747209335_runqmhunt.exe.zip"; depth:67; endswith; nocase; http.host; content:"dlied6.bytes.tcdnos.com"; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561858/; classtype:trojan-activity;sid:84424958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invc/xfspeed/qqpcmgr/module_update/fid1747732120_runqmhunt.exe.zip"; depth:67; endswith; nocase; http.host; content:"dlied6.bytes.tcdnos.com"; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561857/; classtype:trojan-activity;sid:84424957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invc/xfspeed/qqpcmgr/module_update/fid1747640975_runqmhunt.exe.zip"; depth:67; endswith; nocase; http.host; content:"dlied6.bytes.tcdnos.com"; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561856/; classtype:trojan-activity;sid:84424956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/data/drss/drbw.zip"; depth:25; endswith; nocase; http.host; content:"124.223.105.161"; depth:15; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561839/; classtype:trojan-activity;sid:84424939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/kedadecoder.zip"; depth:25; endswith; nocase; http.host; content:"123.232.43.185"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_12; reference:url, urlhaus.abuse.ch/url/3561639/; classtype:trojan-activity;sid:84424739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.88.234.44"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_11; reference:url, urlhaus.abuse.ch/url/3560938/; classtype:trojan-activity;sid:84424038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/ransomware/annabelle.exe"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560452/; classtype:trojan-activity;sid:84423552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/barrigudinha157/barrigudinha/master/ydrag.dll"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560445/; classtype:trojan-activity;sid:84423545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/loic/master/loic.exe"; depth:30; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560439/; classtype:trojan-activity;sid:84423539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantompeek/kematian/main/frontend-src/kematian_shellcode.ps1"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560434/; classtype:trojan-activity;sid:84423534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/ransomware/cryptowall.exe"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560418/; classtype:trojan-activity;sid:84423518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantompeek/kematian/main/frontend-src/main.ps1"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560419/; classtype:trojan-activity;sid:84423519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/ransomware/cryptolocker.exe"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560422/; classtype:trojan-activity;sid:84423522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/email-worm/prolin.exe"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560416/; classtype:trojan-activity;sid:84423516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phantompeek/kematian/main/frontend-src/main.bat"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560412/; classtype:trojan-activity;sid:84423512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/funbatchcode-malicousandnonmalicous/master/worm.bat"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560414/; classtype:trojan-activity;sid:84423514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noccenter/noccenter/main/huong%20dan%20xu%20ly%20tai%20khoan%20mail%20noi%20bo.zip"; depth:83; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560409/; classtype:trojan-activity;sid:84423509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pc/pdfconvert/pdfconverter_p2w154-zx-666.exe"; depth:45; endswith; nocase; http.host; content:"download.pdf00.com"; depth:18; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560385/; classtype:trojan-activity;sid:84423485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/rod_en_1.exe"; depth:23; endswith; nocase; http.host; content:"www.r-tt.com"; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560380/; classtype:trojan-activity;sid:84423480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/rmd_en_1.exe"; depth:23; endswith; nocase; http.host; content:"www.r-tt.com"; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560381/; classtype:trojan-activity;sid:84423481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/rxd_en_1.exe"; depth:23; endswith; nocase; http.host; content:"www.r-tt.com"; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560383/; classtype:trojan-activity;sid:84423483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cybertoxin/remcos-professional-cracked-by-alcatraz3222/raw/master/remcos%20professional%20cracked%20by%20alcatraz3222.zip"; depth:122; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560209/; classtype:trojan-activity;sid:84423309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"45.115.254.68"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_08; reference:url, urlhaus.abuse.ch/url/3559327/; classtype:trojan-activity;sid:84422427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/public/update/bmw_v1.7.exe"; depth:27; endswith; nocase; http.host; content:"acc.jiangsujiaxue.com"; depth:21; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559217/; classtype:trojan-activity;sid:84422317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/classticket.exe"; depth:16; endswith; nocase; http.host; content:"class1004.dothome.co.kr"; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559216/; classtype:trojan-activity;sid:84422316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/static/download/teleport-assist-windows.exe"; depth:44; endswith; nocase; http.host; content:"58.49.210.250"; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559211/; classtype:trojan-activity;sid:84422311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yx/dts/sqft/904576/yx_dts.exe"; depth:30; endswith; nocase; http.host; content:"d.14yaa.com"; depth:11; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559208/; classtype:trojan-activity;sid:84422308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nps.exe"; depth:8; endswith; nocase; http.host; content:"118.219.11.202"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559123/; classtype:trojan-activity;sid:84422223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/keystone.dll"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559040/; classtype:trojan-activity;sid:84422140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/sgn.exe"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559037/; classtype:trojan-activity;sid:84422137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/bsodlogicbomb.ps1"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559033/; classtype:trojan-activity;sid:84422133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/powersyringe.ps1"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559034/; classtype:trojan-activity;sid:84422134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/invoke-reflectivepeinjection.ps1"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559022/; classtype:trojan-activity;sid:84422122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/pe2shc.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559025/; classtype:trojan-activity;sid:84422125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/encrypted.enc"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559019/; classtype:trojan-activity;sid:84422119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/masquerade-peb.ps1"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559009/; classtype:trojan-activity;sid:84422109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/uacbstartup.ps1"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559012/; classtype:trojan-activity;sid:84422112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/invoke-shellcode-fixed.ps1"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559014/; classtype:trojan-activity;sid:84422114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/onedoesnotsimplybypassentirewindefender.ps1"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559015/; classtype:trojan-activity;sid:84422115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/migrate.rb"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559005/; classtype:trojan-activity;sid:84422105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/base64.rb"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559006/; classtype:trojan-activity;sid:84422106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/email-worm/bugsoft.exe"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558975/; classtype:trojan-activity;sid:84422075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/email-worm/brontok.exe"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558976/; classtype:trojan-activity;sid:84422076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/banking-malware/zloader.xlsm"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558977/; classtype:trojan-activity;sid:84422077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/email-worm/anap.a.exe"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558973/; classtype:trojan-activity;sid:84422073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/email-worm/axam.a.exe"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558974/; classtype:trojan-activity;sid:84422074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/banking-malware/emotet.zip"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558966/; classtype:trojan-activity;sid:84422066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/master/email-worm/amus.exe"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558967/; classtype:trojan-activity;sid:84422067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/rickware/master/rickroll.exe"; depth:38; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558969/; classtype:trojan-activity;sid:84422069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.26.97.59"; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_05; reference:url, urlhaus.abuse.ch/url/3558602/; classtype:trojan-activity;sid:84421702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g7_update.exe"; depth:14; endswith; nocase; http.host; content:"118.219.11.202"; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_05; reference:url, urlhaus.abuse.ch/url/3558501/; classtype:trojan-activity;sid:84421601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/amsibypass/main/newamsibypass.ps1"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558302/; classtype:trojan-activity;sid:84421402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/link-exe-test/main/matthew.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558300/; classtype:trojan-activity;sid:84421400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/second.bin"; depth:29; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558295/; classtype:trojan-activity;sid:84421395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/urbanvpn.exe"; depth:31; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558290/; classtype:trojan-activity;sid:84421390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/svhost.exe"; depth:29; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558291/; classtype:trojan-activity;sid:84421391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/second.exe"; depth:29; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558292/; classtype:trojan-activity;sid:84421392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/invoke-nicelittlekittieobf/main/invoke-nicelittlekittieobf.ps1"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558289/; classtype:trojan-activity;sid:84421389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/pvp.exe"; depth:26; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558285/; classtype:trojan-activity;sid:84421385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/darwin.exe"; depth:29; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558287/; classtype:trojan-activity;sid:84421387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/rust-dropper/main/src/main.rs"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558280/; classtype:trojan-activity;sid:84421380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c5hackr/phantom/main/phantom/bin/x64/release/phantom.exe"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558271/; classtype:trojan-activity;sid:84421371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/invoke-shell/main/reverse.ps1"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558266/; classtype:trojan-activity;sid:84421366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/iso-file-testing/main/pleaserunme.iso"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558264/; classtype:trojan-activity;sid:84421364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c5hackr/phantom/main/phantom/resources/uac64.dll"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558260/; classtype:trojan-activity;sid:84421360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/payload.bin"; depth:30; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558252/; classtype:trojan-activity;sid:84421352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/riende.exe"; depth:29; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558247/; classtype:trojan-activity;sid:84421347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c5hackr/phantom/main/phantom/resources/uac.dll"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558249/; classtype:trojan-activity;sid:84421349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/invoke-nicelittlekittie/main/invoke-nicelittlekittie.ps1"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558243/; classtype:trojan-activity;sid:84421343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/main/payload_encrypted.bin"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558235/; classtype:trojan-activity;sid:84421335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/meter/main/meter5555.ps1"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558237/; classtype:trojan-activity;sid:84421337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/js-file-test/main/loader.js"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558229/; classtype:trojan-activity;sid:84421329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/rust-revshell/main/src/main.rs"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558230/; classtype:trojan-activity;sid:84421330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3555192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/raw/refs/heads/master/ransomware/wannacry.exe"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_29; reference:url, urlhaus.abuse.ch/url/3555192/; classtype:trojan-activity;sid:84418292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3554430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rate.zip"; depth:9; endswith; nocase; http.host; content:"celebratingseniors.net"; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_28; reference:url, urlhaus.abuse.ch/url/3554430/; classtype:trojan-activity;sid:84417530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3554345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rats.zip"; depth:9; endswith; nocase; http.host; content:"celebratingseniors.net"; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_28; reference:url, urlhaus.abuse.ch/url/3554345/; classtype:trojan-activity;sid:84417445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3554334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oste.zip"; depth:9; endswith; nocase; http.host; content:"celebratingseniors.net"; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_28; reference:url, urlhaus.abuse.ch/url/3554334/; classtype:trojan-activity;sid:84417434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3553636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bufs.zip"; depth:9; endswith; nocase; http.host; content:"maidforyou1985.com"; depth:18; isdataat:!1,relative; metadata:created_at 2025_05_27; reference:url, urlhaus.abuse.ch/url/3553636/; classtype:trojan-activity;sid:84416736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3553629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mits.zip"; depth:9; endswith; nocase; http.host; content:"windomstatetheater.com"; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_27; reference:url, urlhaus.abuse.ch/url/3553629/; classtype:trojan-activity;sid:84416729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3553633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/osxs.zip"; depth:9; endswith; nocase; http.host; content:"windomstatetheater.com"; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_27; reference:url, urlhaus.abuse.ch/url/3553633/; classtype:trojan-activity;sid:84416733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3553609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rars.zip"; depth:9; endswith; nocase; http.host; content:"windomstatetheater.com"; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_27; reference:url, urlhaus.abuse.ch/url/3553609/; classtype:trojan-activity;sid:84416709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.81.156.123"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_26; reference:url, urlhaus.abuse.ch/url/3552756/; classtype:trojan-activity;sid:84415856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.81.156.124"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_26; reference:url, urlhaus.abuse.ch/url/3552757/; classtype:trojan-activity;sid:84415857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"223.83.211.82"; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_26; reference:url, urlhaus.abuse.ch/url/3552741/; classtype:trojan-activity;sid:84415841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bre"; depth:4; endswith; nocase; http.host; content:"109.74.204.206"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_26; reference:url, urlhaus.abuse.ch/url/3552617/; classtype:trojan-activity;sid:84415717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anonimusman00-2/xmr/refs/heads/main/silent%20miner.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552045/; classtype:trojan-activity;sid:84415145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/waf/dracula-cmd/master/dist/colortool.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552042/; classtype:trojan-activity;sid:84415142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iamsysadmin/setteamsbg/main/set-teams-backgrounds.zip"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552043/; classtype:trojan-activity;sid:84415143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anonimusman00-2/xmr/raw/refs/heads/main/silent%20miner.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552009/; classtype:trojan-activity;sid:84415109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alanparadis/stalker2simplemodmerger/releases/download/vortex-v1.4.9/stalker2simplemodmergerforvortex.zip"; depth:105; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552005/; classtype:trojan-activity;sid:84415105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3551493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.242.66.123"; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3551493/; classtype:trojan-activity;sid:84414593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3550735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/macmid_sonoma_14_5.exe"; depth:23; endswith; nocase; http.host; content:"107.198.40.184"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_23; reference:url, urlhaus.abuse.ch/url/3550735/; classtype:trojan-activity;sid:84413835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3549998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/server.exe"; depth:11; endswith; nocase; http.host; content:"106.14.68.26"; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_22; reference:url, urlhaus.abuse.ch/url/3549998/; classtype:trojan-activity;sid:84413098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3549645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"186.87.82.140"; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_22; reference:url, urlhaus.abuse.ch/url/3549645/; classtype:trojan-activity;sid:84412745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3547880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ed2w0zvvx53_mfifdszyslleurub40zo"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_05_20; reference:url, urlhaus.abuse.ch/url/3547880/; classtype:trojan-activity;sid:84410980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3547784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.84.143"; depth:11; isdataat:!1,relative; metadata:created_at 2025_05_20; reference:url, urlhaus.abuse.ch/url/3547784/; classtype:trojan-activity;sid:84410884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3547782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"201.98.176.195"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_20; reference:url, urlhaus.abuse.ch/url/3547782/; classtype:trojan-activity;sid:84410882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3546975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"87.119.108.21"; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_19; reference:url, urlhaus.abuse.ch/url/3546975/; classtype:trojan-activity;sid:84410075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3546969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"84.236.147.129"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_19; reference:url, urlhaus.abuse.ch/url/3546969/; classtype:trojan-activity;sid:84410069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3544992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/nk/wunbbnvf102.bin"; depth:31; endswith; nocase; http.host; content:"planetariumobil.ro"; depth:18; isdataat:!1,relative; metadata:created_at 2025_05_16; reference:url, urlhaus.abuse.ch/url/3544992/; classtype:trojan-activity;sid:84408092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3543803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.239.97"; depth:11; isdataat:!1,relative; metadata:created_at 2025_05_15; reference:url, urlhaus.abuse.ch/url/3543803/; classtype:trojan-activity;sid:84406903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3543805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.239.98"; depth:11; isdataat:!1,relative; metadata:created_at 2025_05_15; reference:url, urlhaus.abuse.ch/url/3543805/; classtype:trojan-activity;sid:84406905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3543801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.83.40"; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_15; reference:url, urlhaus.abuse.ch/url/3543801/; classtype:trojan-activity;sid:84406901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3543392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.50.222.238"; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_14; reference:url, urlhaus.abuse.ch/url/3543392/; classtype:trojan-activity;sid:84406492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3542563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1wvxiyf_ryvgg_x3x7uceicqrndhb7lul"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_05_13; reference:url, urlhaus.abuse.ch/url/3542563/; classtype:trojan-activity;sid:84405663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/giphy.gif"; depth:21; endswith; nocase; http.host; content:"onfiltre.com.tr"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_12; reference:url, urlhaus.abuse.ch/url/3541826/; classtype:trojan-activity;sid:84404926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.sh4"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541464/; classtype:trojan-activity;sid:84404564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.arm"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541468/; classtype:trojan-activity;sid:84404568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.x86"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541469/; classtype:trojan-activity;sid:84404569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.m68k"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541471/; classtype:trojan-activity;sid:84404571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.ppc"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541473/; classtype:trojan-activity;sid:84404573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.arm5"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541474/; classtype:trojan-activity;sid:84404574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.mips"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541476/; classtype:trojan-activity;sid:84404576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.arm6"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541477/; classtype:trojan-activity;sid:84404577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.spc"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541479/; classtype:trojan-activity;sid:84404579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.mpsl"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541481/; classtype:trojan-activity;sid:84404581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.mpsl"; depth:24; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541456/; classtype:trojan-activity;sid:84404556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.mips"; depth:24; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541457/; classtype:trojan-activity;sid:84404557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.arm7"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541458/; classtype:trojan-activity;sid:84404558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.x86_64"; depth:26; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541459/; classtype:trojan-activity;sid:84404559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.arm5"; depth:24; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541460/; classtype:trojan-activity;sid:84404560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/arm7"; depth:11; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541461/; classtype:trojan-activity;sid:84404561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.arm7"; depth:24; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541446/; classtype:trojan-activity;sid:84404546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.arm"; depth:23; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541447/; classtype:trojan-activity;sid:84404547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/x86_64"; depth:13; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541448/; classtype:trojan-activity;sid:84404548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.arm6"; depth:24; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541449/; classtype:trojan-activity;sid:84404549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.spc"; depth:23; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541450/; classtype:trojan-activity;sid:84404550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.ppc"; depth:23; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541451/; classtype:trojan-activity;sid:84404551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.m68k"; depth:24; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541452/; classtype:trojan-activity;sid:84404552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.x86"; depth:23; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541453/; classtype:trojan-activity;sid:84404553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/vcimanagement.sh4"; depth:23; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541454/; classtype:trojan-activity;sid:84404554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/kwari.x86_64"; depth:18; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541455/; classtype:trojan-activity;sid:84404555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/m68k"; depth:11; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541365/; classtype:trojan-activity;sid:84404465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/arm"; depth:10; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541355/; classtype:trojan-activity;sid:84404455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/arm5"; depth:11; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541356/; classtype:trojan-activity;sid:84404456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/x86"; depth:10; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541358/; classtype:trojan-activity;sid:84404458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/ppc"; depth:10; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541359/; classtype:trojan-activity;sid:84404459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/mips"; depth:11; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541360/; classtype:trojan-activity;sid:84404460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/sh4"; depth:10; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541361/; classtype:trojan-activity;sid:84404461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/mpsl"; depth:11; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541362/; classtype:trojan-activity;sid:84404462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/arm6"; depth:11; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541363/; classtype:trojan-activity;sid:84404463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/spc"; depth:10; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3541364/; classtype:trojan-activity;sid:84404464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.12.2/xmrig-6.12.2-linux-static-x64.tar.gz"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3540931/; classtype:trojan-activity;sid:84404031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/c.sh"; depth:10; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540430/; classtype:trojan-activity;sid:84403530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/w.sh"; depth:10; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540431/; classtype:trojan-activity;sid:84403531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.arm6"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540409/; classtype:trojan-activity;sid:84403509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.arm5"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540400/; classtype:trojan-activity;sid:84403500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.arm"; depth:14; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540401/; classtype:trojan-activity;sid:84403501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540402)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.ppc"; depth:14; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540402/; classtype:trojan-activity;sid:84403502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.mips"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540403/; classtype:trojan-activity;sid:84403503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.x86"; depth:14; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540404/; classtype:trojan-activity;sid:84403504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.sh4"; depth:14; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540405/; classtype:trojan-activity;sid:84403505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.mpsl"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540406/; classtype:trojan-activity;sid:84403506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.m68k"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540407/; classtype:trojan-activity;sid:84403507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/sora.spc"; depth:14; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540408/; classtype:trojan-activity;sid:84403508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.x/pax.txt"; depth:11; endswith; nocase; http.host; content:"13.71.2.244"; depth:11; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540085/; classtype:trojan-activity;sid:84403185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3539686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/js_bo/werkstastt/shotstar.prm"; depth:30; endswith; nocase; http.host; content:"www.silver-hubdachwohnwagen.de"; depth:30; isdataat:!1,relative; metadata:created_at 2025_05_09; reference:url, urlhaus.abuse.ch/url/3539686/; classtype:trojan-activity;sid:84402786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3539028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.22.42.232"; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3539028/; classtype:trojan-activity;sid:84402128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"121.202.208.237"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538763/; classtype:trojan-activity;sid:84401863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"121.202.209.31"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538762/; classtype:trojan-activity;sid:84401862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"201.94.181.7"; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538761/; classtype:trojan-activity;sid:84401861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"121.202.209.46"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538755/; classtype:trojan-activity;sid:84401855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"201.94.181.7"; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538747/; classtype:trojan-activity;sid:84401847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"201.94.181.7"; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538741/; classtype:trojan-activity;sid:84401841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"201.94.181.7"; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538744/; classtype:trojan-activity;sid:84401844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"121.202.208.107"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538670/; classtype:trojan-activity;sid:84401770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"188.162.88.253"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538667/; classtype:trojan-activity;sid:84401767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.22.42.232"; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538179/; classtype:trojan-activity;sid:84401279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/wget.sh"; depth:14; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536597/; classtype:trojan-activity;sid:84399697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.arm5"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536598/; classtype:trojan-activity;sid:84399698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.mips"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536618/; classtype:trojan-activity;sid:84399718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/w.sh"; depth:11; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536583/; classtype:trojan-activity;sid:84399683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.arm6"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536582/; classtype:trojan-activity;sid:84399682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.m68k"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536575/; classtype:trojan-activity;sid:84399675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.mpsl"; depth:16; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536576/; classtype:trojan-activity;sid:84399676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/c.sh"; depth:11; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536577/; classtype:trojan-activity;sid:84399677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.x86"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536578/; classtype:trojan-activity;sid:84399678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.arm"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536579/; classtype:trojan-activity;sid:84399679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.spc"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536580/; classtype:trojan-activity;sid:84399680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3536581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/where/botx.sh4"; depth:15; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_06; reference:url, urlhaus.abuse.ch/url/3536581/; classtype:trojan-activity;sid:84399681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3534886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"103.153.93.18"; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_04; reference:url, urlhaus.abuse.ch/url/3534886/; classtype:trojan-activity;sid:84397986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3533582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kokotpycauholica/ultraundetecteddrv/refs/heads/main/hbvtmbp46iieehp1.exe"; depth:73; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_05_03; reference:url, urlhaus.abuse.ch/url/3533582/; classtype:trojan-activity;sid:84396682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3532855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"176.102.198.226"; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_02; reference:url, urlhaus.abuse.ch/url/3532855/; classtype:trojan-activity;sid:84395955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3532847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"114.129.49.131"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_02; reference:url, urlhaus.abuse.ch/url/3532847/; classtype:trojan-activity;sid:84395947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3532848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"114.129.49.131"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_02; reference:url, urlhaus.abuse.ch/url/3532848/; classtype:trojan-activity;sid:84395948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3532849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"114.129.49.131"; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_02; reference:url, urlhaus.abuse.ch/url/3532849/; classtype:trojan-activity;sid:84395949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3530891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.127.68.162"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_30; reference:url, urlhaus.abuse.ch/url/3530891/; classtype:trojan-activity;sid:84393991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3530248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.31.8.25"; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_29; reference:url, urlhaus.abuse.ch/url/3530248/; classtype:trojan-activity;sid:84393348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mir1ce/hawkeye/releases/download/v0319/hawkeye.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_28; reference:url, urlhaus.abuse.ch/url/3528280/; classtype:trojan-activity;sid:84391380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yarahq/yara-forge/releases/latest/download/yara-forge-rules-core.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_28; reference:url, urlhaus.abuse.ch/url/3528279/; classtype:trojan-activity;sid:84391379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meckazin/chromekatz/releases/download/0.6.1/chromekatzbofs.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_28; reference:url, urlhaus.abuse.ch/url/3528277/; classtype:trojan-activity;sid:84391377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/19831362/alpha.zip"; depth:42; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528171/; classtype:trojan-activity;sid:84391271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/decalage2/oletools/releases/download/v0.60.2/oletools-0.60.2.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528170/; classtype:trojan-activity;sid:84391270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/19831288/crack.nurik.zip"; depth:48; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528165/; classtype:trojan-activity;sid:84391265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/19831450/solara.zip"; depth:43; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528162/; classtype:trojan-activity;sid:84391262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/19835739/solarus.zip"; depth:44; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528154/; classtype:trojan-activity;sid:84391254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zxc5wezxc/new/main/dllbase64reverse.txt"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528128/; classtype:trojan-activity;sid:84391228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/androidmalware/android_hid/f25d0234cff288ab8384689685e37b1b4bbaf2ba/test.exe"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528127/; classtype:trojan-activity;sid:84391227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/monkeyadece/v-f/releases/download/1.4.2/vector-fixer-v1.4.2.exe"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528108/; classtype:trojan-activity;sid:84391208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ui.exe"; depth:7; endswith; nocase; http.host; content:"public.demo.securecloudsandbox.com"; depth:34; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528105/; classtype:trojan-activity;sid:84391205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lbormann/darts-gif/releases/download/v1.1.0/darts-gif.exe"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528107/; classtype:trojan-activity;sid:84391207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lbormann/darts-pixelit/releases/download/v1.2.2/darts-pixelit.exe"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528100/; classtype:trojan-activity;sid:84391200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lbormann/darts-wled/releases/download/v1.8.1/darts-wled.exe"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528101/; classtype:trojan-activity;sid:84391201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528097)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harelba/q/releases/download/2.0.19/q-amd64-windows.exe"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528097/; classtype:trojan-activity;sid:84391197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikf/gallery-dl/releases/download/v1.15.0/gallery-dl.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528098/; classtype:trojan-activity;sid:84391198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3527856)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"78.36.11.185"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3527856/; classtype:trojan-activity;sid:84390956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3526930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/verify-sec"; depth:11; endswith; nocase; http.host; content:"msoftdatastore.z22.web.core.windows.net"; depth:39; isdataat:!1,relative; metadata:created_at 2025_04_26; reference:url, urlhaus.abuse.ch/url/3526930/; classtype:trojan-activity;sid:84390030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3526832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.252.69.10"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_26; reference:url, urlhaus.abuse.ch/url/3526832/; classtype:trojan-activity;sid:84389932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3525979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/debug.dbg"; depth:10; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_04_26; reference:url, urlhaus.abuse.ch/url/3525979/; classtype:trojan-activity;sid:84389079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3525151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"80.110.37.104"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3525151/; classtype:trojan-activity;sid:84388251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3525021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linux"; depth:6; endswith; nocase; http.host; content:"47.83.203.183"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3525021/; classtype:trojan-activity;sid:84388121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3524811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vaxilu/x-ui/releases/latest/download/x-ui-linux-amd64.tar.gz"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3524811/; classtype:trojan-activity;sid:84387911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3524779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"195.158.88.156"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3524779/; classtype:trojan-activity;sid:84387879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3524506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ccjlbddgjhpeeff1b1hfkgp3x16c_tj1"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3524506/; classtype:trojan-activity;sid:84387606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3524454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1bpc5z-hv6kosk6artkfmbtsnnwwpdghy"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3524454/; classtype:trojan-activity;sid:84387554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3523738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"23.239.12.230"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_24; reference:url, urlhaus.abuse.ch/url/3523738/; classtype:trojan-activity;sid:84386838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3523621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"213.47.243.57"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_24; reference:url, urlhaus.abuse.ch/url/3523621/; classtype:trojan-activity;sid:84386721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3522943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/oto"; depth:4; endswith; nocase; http.host; content:"162.215.218.82"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_23; reference:url, urlhaus.abuse.ch/url/3522943/; classtype:trojan-activity;sid:84386043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3522687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ltrdqlgcl6smoqujfs1pb2ernzhsbydh"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_23; reference:url, urlhaus.abuse.ch/url/3522687/; classtype:trojan-activity;sid:84385787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3522201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eed8989/u/main/ud.bat"; depth:22; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_22; reference:url, urlhaus.abuse.ch/url/3522201/; classtype:trojan-activity;sid:84385301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3522159)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"188.243.36.33"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_22; reference:url, urlhaus.abuse.ch/url/3522159/; classtype:trojan-activity;sid:84385259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.12.2/xmrig-6.12.2-linux-x64.tar.gz"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_21; reference:url, urlhaus.abuse.ch/url/3520366/; classtype:trojan-activity;sid:84383466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"77.226.241.197"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520082/; classtype:trojan-activity;sid:84383182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"202.57.43.234"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520081/; classtype:trojan-activity;sid:84383181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"179.63.168.2"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520073/; classtype:trojan-activity;sid:84383173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"61.244.254.110"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520077/; classtype:trojan-activity;sid:84383177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"2.136.63.232"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520070/; classtype:trojan-activity;sid:84383170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"93.182.77.20"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520068/; classtype:trojan-activity;sid:84383168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.229.20.42"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519584/; classtype:trojan-activity;sid:84382684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519540)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/_autovlbs19_new/trainjx2.exe"; depth:29; endswith; nocase; http.host; content:"thtp2.volamngayxua.net"; depth:22; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519540/; classtype:trojan-activity;sid:84382640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/_autovlbs19_new/trainjx.exe"; depth:28; endswith; nocase; http.host; content:"thtp2.volamngayxua.net"; depth:22; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519529/; classtype:trojan-activity;sid:84382629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/linm_free/tg_linm_data_image_free.dll"; depth:43; endswith; nocase; http.host; content:"tiwanlinm.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519525/; classtype:trojan-activity;sid:84382625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fb/32.exe"; depth:10; endswith; nocase; http.host; content:"ny.lshdw.cc"; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519518/; classtype:trojan-activity;sid:84382618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/install/namu832.exe"; depth:20; endswith; nocase; http.host; content:"www.namuvpn.com"; depth:15; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519513/; classtype:trojan-activity;sid:84382613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/versions/gestioniccv20.21.8.51/gestionicc.exe"; depth:46; endswith; nocase; http.host; content:"icoffeecloud.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519485/; classtype:trojan-activity;sid:84382585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/static/files/bootstrappernew.exe"; depth:42; endswith; nocase; http.host; content:"60aaf9c6.salamanderprocessing.pages.dev"; depth:39; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519469/; classtype:trojan-activity;sid:84382569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/linm_free/tg_linm_data_map_free.dll"; depth:41; endswith; nocase; http.host; content:"tiwanlinm.duckdns.org"; depth:21; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519467/; classtype:trojan-activity;sid:84382567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fb/sm.exe"; depth:10; endswith; nocase; http.host; content:"ny.lshdw.cc"; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519464/; classtype:trojan-activity;sid:84382564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pds/mogimall/giftorder/giftorder.exe"; depth:37; endswith; nocase; http.host; content:"mogimall.com"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519459/; classtype:trojan-activity;sid:84382559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/static/files/bootstrappernew.exe"; depth:42; endswith; nocase; http.host; content:"2cfc0222.salamanderprocessing.pages.dev"; depth:39; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519451/; classtype:trojan-activity;sid:84382551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newchaisupon/vendor/bin/psysh.bat"; depth:34; endswith; nocase; http.host; content:"99194034-96-20180108171507.webstarterz.com"; depth:42; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519446/; classtype:trojan-activity;sid:84382546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/diaclients/doitallmain.exe"; depth:27; endswith; nocase; http.host; content:"www.salonmarketing.ca"; depth:21; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519442/; classtype:trojan-activity;sid:84382542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sa0611/systemsa32.dll"; depth:22; endswith; nocase; http.host; content:"www.ss-01.com"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519443/; classtype:trojan-activity;sid:84382543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update/pubdata/hpsocket4c.dll"; depth:30; endswith; nocase; http.host; content:"114.55.106.136"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519429/; classtype:trojan-activity;sid:84382529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519415)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/static/files/bootstrappernew.exe"; depth:42; endswith; nocase; http.host; content:"c3436037.salamanderprocessing.pages.dev"; depth:39; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519415/; classtype:trojan-activity;sid:84382515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rh/setup.exe"; depth:13; endswith; nocase; http.host; content:"d3cciiowg5l3jx.cloudfront.net"; depth:29; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519408/; classtype:trojan-activity;sid:84382508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pds/mogimall/giftorder/updater.exe"; depth:35; endswith; nocase; http.host; content:"mogimall.com"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519404/; classtype:trojan-activity;sid:84382504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/media/video_file/round_setup.exe"; depth:33; endswith; nocase; http.host; content:"tapestryoftruth.com"; depth:19; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519392/; classtype:trojan-activity;sid:84382492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r0400/yahoodll.dll"; depth:19; endswith; nocase; http.host; content:"www.ss-01.com"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519368/; classtype:trojan-activity;sid:84382468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/driveapplet.exe"; depth:16; endswith; nocase; http.host; content:"noithaticon.vn"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519369/; classtype:trojan-activity;sid:84382469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/licensing/updates/addmefast%20bot.exe"; depth:38; endswith; nocase; http.host; content:"www.blackhattoolz.com"; depth:21; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519354/; classtype:trojan-activity;sid:84382454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nircmd.exe"; depth:11; endswith; nocase; http.host; content:"pub-0478b308b8cf46709a73d0eed5afd633.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519356/; classtype:trojan-activity;sid:84382456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.22.2/xmrig-6.22.2-msvc-win64.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519066/; classtype:trojan-activity;sid:84382166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vinhuptoday/testbn/raw/refs/heads/main/brbotnet.exe"; depth:52; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519063/; classtype:trojan-activity;sid:84382163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/disbalancer-project/main/releases/latest/download/disbalancer-go-client-windows-386.exe"; depth:88; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519035/; classtype:trojan-activity;sid:84382135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uniondown/haozip_tiny.201805.exe"; depth:33; endswith; nocase; http.host; content:"download.haozip.com"; depth:19; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519028/; classtype:trojan-activity;sid:84382128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cosmicdevv/icarus-lite/releases/download/v1.1.13/icaruslite-v1.1.13-win.exe"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519027/; classtype:trojan-activity;sid:84382127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sebaxakerhtc/rdpwrap/releases/download/v1.8.9.9/rdpw_installer.exe"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519025/; classtype:trojan-activity;sid:84382125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dax009yt/chilledwindows-gui/releases/download/1.0/chilledwindows.gui.exe"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519026/; classtype:trojan-activity;sid:84382126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jackson2323/mohradiant/blob/master/updt.exe|3f|raw=true"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519019/; classtype:trojan-activity;sid:84382119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/pkexu0ytxar3.exe"; depth:22; endswith; nocase; http.host; content:"115.159.149.113"; depth:15; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519020/; classtype:trojan-activity;sid:84382120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bol-van/zapret/releases/download/v70.6/zapret-v70.6.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519016/; classtype:trojan-activity;sid:84382116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3518999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2590057.s21d-2.faiusrd.com/0/abuiabblgaagytxhtauo1pck0ge.exe|3f|f=ghost%e7%bd%91%e5%85%8b%e9%9a%86%e6%a3%80%e6%b5%8b%e5%b7%a5%e5%85%b7.exe|7c|26|7c|v=1452829385|7c|26|7c|wsiphost=local|7c|26|7c|wsrid_tag=61c52eb2_psmgzjgord1de87_17635-16713"; depth:241; endswith; nocase; http.host; content:"157.185.170.200"; depth:15; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3518999/; classtype:trojan-activity;sid:84382099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vexcentry/vex/raw/refs/heads/main/runtimebroker.exe"; depth:52; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519000/; classtype:trojan-activity;sid:84382100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3518861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ns3.jpg"; depth:8; endswith; nocase; http.host; content:"162.215.218.82"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3518861/; classtype:trojan-activity;sid:84381961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3518860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ns1.jpg"; depth:8; endswith; nocase; http.host; content:"162.215.218.82"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3518860/; classtype:trojan-activity;sid:84381960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3517040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mig"; depth:4; endswith; nocase; http.host; content:"2.57.122.121"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_18; reference:url, urlhaus.abuse.ch/url/3517040/; classtype:trojan-activity;sid:84380140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3516658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vinhuptoday/testbn/raw/refs/heads/main/brbotnet.exe"; depth:52; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_18; reference:url, urlhaus.abuse.ch/url/3516658/; classtype:trojan-activity;sid:84379758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3516584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"211.219.49.173"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_18; reference:url, urlhaus.abuse.ch/url/3516584/; classtype:trojan-activity;sid:84379684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3515978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"120.79.64.164"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_17; reference:url, urlhaus.abuse.ch/url/3515978/; classtype:trojan-activity;sid:84379078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3515922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"113.45.253.80"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_17; reference:url, urlhaus.abuse.ch/url/3515922/; classtype:trojan-activity;sid:84379022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3514570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1hrp9lnasbplclnhppp1abwb1uwv4kdvs"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_17; reference:url, urlhaus.abuse.ch/url/3514570/; classtype:trojan-activity;sid:84377670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3514066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nkminash/my-codd/raw/896d806a9b4569c9c3a275f200ebe7d2ecec5702/snd16061.exe"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_17; reference:url, urlhaus.abuse.ch/url/3514066/; classtype:trojan-activity;sid:84377166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3509907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rahmounben/lc/refs/heads/main/xclient.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_13; reference:url, urlhaus.abuse.ch/url/3509907/; classtype:trojan-activity;sid:84373007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3509904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justjzero/ahh/refs/heads/main/cloudy.exe"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_13; reference:url, urlhaus.abuse.ch/url/3509904/; classtype:trojan-activity;sid:84373004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3509901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justjzero/ahh/raw/refs/heads/main/cloudy.exe"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_13; reference:url, urlhaus.abuse.ch/url/3509901/; classtype:trojan-activity;sid:84373001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3509872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/niggedddx/dependenciuesfeife/raw/refs/heads/main/bruterv3.1.exe"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_13; reference:url, urlhaus.abuse.ch/url/3509872/; classtype:trojan-activity;sid:84372972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3507942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.60.246.15"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_11; reference:url, urlhaus.abuse.ch/url/3507942/; classtype:trojan-activity;sid:84371042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3507452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/misterlobster22/mimik/blob/main/mimikatz.exe|3f|raw=true"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_11; reference:url, urlhaus.abuse.ch/url/3507452/; classtype:trojan-activity;sid:84370552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3506392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deepakmeena2006/lib/6753a65f543afe81079459a8439ec1e0c0a660b4/s86.txt"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_10; reference:url, urlhaus.abuse.ch/url/3506392/; classtype:trojan-activity;sid:84369492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3506391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deepakmeena2006/lib/6753a65f543afe81079459a8439ec1e0c0a660b4/s64.txt"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_10; reference:url, urlhaus.abuse.ch/url/3506391/; classtype:trojan-activity;sid:84369491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3506346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1kcbhxhjt-bdxszgxt1nfnzdt5hpvkwk4"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_10; reference:url, urlhaus.abuse.ch/url/3506346/; classtype:trojan-activity;sid:84369446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1muftth-5lscdi3ovd5vn7sjkeit2h9k1"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505672/; classtype:trojan-activity;sid:84368772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/electrichermit/vegas-pro-version/releases/download/v2.0/software.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505377/; classtype:trojan-activity;sid:84368477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ergin3432432/movie-mates/releases/download/v1.0/application.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505382/; classtype:trojan-activity;sid:84368482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yumyumdonuts/free-youtube-to-mp3-converter-free/releases/download/1.1.2/freeyoutubetomp3converterfree-1.1.2.zip"; depth:112; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505334/; classtype:trojan-activity;sid:84368434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nmattioni/upload/raw/refs/heads/master/software.zip"; depth:52; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505313/; classtype:trojan-activity;sid:84368413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anamesias580/upload/refs/heads/master/software.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505307/; classtype:trojan-activity;sid:84368407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phanu85/upload/raw/refs/heads/master/software.zip"; depth:50; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505305/; classtype:trojan-activity;sid:84368405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pantay/upload/raw/refs/heads/master/software.zip"; depth:49; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505304/; classtype:trojan-activity;sid:84368404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3504713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.238.31"; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_08; reference:url, urlhaus.abuse.ch/url/3504713/; classtype:trojan-activity;sid:84367813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3503677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"179.60.216.19"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_07; reference:url, urlhaus.abuse.ch/url/3503677/; classtype:trojan-activity;sid:84366777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3503657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.43.17.123"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_07; reference:url, urlhaus.abuse.ch/url/3503657/; classtype:trojan-activity;sid:84366757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3503409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tirtekeka/rat-client/zip/refs/heads/main"; depth:41; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2025_04_07; reference:url, urlhaus.abuse.ch/url/3503409/; classtype:trojan-activity;sid:84366509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3503003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/konsol.exe"; depth:20; endswith; nocase; http.host; content:"backupso.com"; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_06; reference:url, urlhaus.abuse.ch/url/3503003/; classtype:trojan-activity;sid:84366103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3502701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.210.214.48"; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_06; reference:url, urlhaus.abuse.ch/url/3502701/; classtype:trojan-activity;sid:84365801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3500891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chin/ifjjmktge.mp3"; depth:19; endswith; nocase; http.host; content:"dcrun.co.uk"; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_04; reference:url, urlhaus.abuse.ch/url/3500891/; classtype:trojan-activity;sid:84363991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3500747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.185.1.70"; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_04; reference:url, urlhaus.abuse.ch/url/3500747/; classtype:trojan-activity;sid:84363847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3500733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"82.102.74.238"; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_04; reference:url, urlhaus.abuse.ch/url/3500733/; classtype:trojan-activity;sid:84363833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3499993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roniel8/apex-no-recoil/releases/download/v2.5.1-alpha.3/apex-no-recoil-v2-5-1-alpha-3.zip"; depth:90; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_03; reference:url, urlhaus.abuse.ch/url/3499993/; classtype:trojan-activity;sid:84363093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/juanbustoss/src/raw/refs/heads/master/application.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498482/; classtype:trojan-activity;sid:84361582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shellyacm/imgx/releases/download/v1.0/software.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498084/; classtype:trojan-activity;sid:84361184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shellyacm/imgx/releases/download/v2.0/software.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498082/; classtype:trojan-activity;sid:84361182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/demonsofhe/onion-rings/releases/download/3.1.7/onion-rings-3.1.7.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498070/; classtype:trojan-activity;sid:84361170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jxx1234567890jxx/datatransformationchecker/releases/download/v2.0/software.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498076/; classtype:trojan-activity;sid:84361176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frank698/localocr/releases/download/v2.3.3/localocr_v2.3.3.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498067/; classtype:trojan-activity;sid:84361167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wfeifefeifef/pokemon-crud/releases/download/v1.1/soft.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498056/; classtype:trojan-activity;sid:84361156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ushii/weather_app/releases/download/v1.0/installer.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498045/; classtype:trojan-activity;sid:84361145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rahulpa045/cphishtermux/releases/download/v1.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498047/; classtype:trojan-activity;sid:84361147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wfeifefeifef/pokemon-crud/releases/download/v1.2/soft.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498050/; classtype:trojan-activity;sid:84361150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jxx1234567890jxx/datatransformationchecker/releases/download/v1.0/application.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498053/; classtype:trojan-activity;sid:84361153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamer615/acdsee-photo-studio-professional-download/releases/download/v1.0/software.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498033/; classtype:trojan-activity;sid:84361133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ushii/weather_app/releases/download/v2.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498034/; classtype:trojan-activity;sid:84361134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamer615/acdsee-photo-studio-professional-download/releases/download/v2.0/software.zip"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498036/; classtype:trojan-activity;sid:84361136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eltrapico2/php-library-system/releases/download/v1.0/software.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498038/; classtype:trojan-activity;sid:84361138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itznaviya/hamster-kombat-bot/releases/download/v2.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497826/; classtype:trojan-activity;sid:84360926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itznaviya/hamster-kombat-bot/releases/download/v2.0/program.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497822/; classtype:trojan-activity;sid:84360922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itznaviya/hamster-kombat-bot/releases/download/v1.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497825/; classtype:trojan-activity;sid:84360925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ffxjevefi/nix-system-services-hardened/releases/download/v2.0/software.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497805/; classtype:trojan-activity;sid:84360905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supreme-snaze/permutations/releases/download/v1.0/program.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497797/; classtype:trojan-activity;sid:84360897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ander12342/pugdns/releases/download/1.3.1/pugdns_v1.3.1.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497739/; classtype:trojan-activity;sid:84360839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/devpev777/d/refs/heads/main/r.msi"; depth:34; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497677/; classtype:trojan-activity;sid:84360777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dodobaba25/repo/refs/heads/master/s64.txt"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3497120/; classtype:trojan-activity;sid:84360220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dodobaba25/repo/refs/heads/master/s86.txt"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3497121/; classtype:trojan-activity;sid:84360221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/benkku25/assets/raw/41f4f8f16b76af39e1bc3f8024b66010dd2617c7/software.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496952/; classtype:trojan-activity;sid:84360052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syklon99/ai-chatbot-svelte/releases/download/v1.4.9/ai-chatbot-svelte-v1.4.9.zip"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496664/; classtype:trojan-activity;sid:84359764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sigarikafat/xeet/releases/download/1.6.4/xeet_v1.6.4.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496662/; classtype:trojan-activity;sid:84359762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naoval19/tacos/releases/download/v1.0/program.zip"; depth:50; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496645/; classtype:trojan-activity;sid:84359745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naoval19/tacos/releases/download/v2.0/software.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496646/; classtype:trojan-activity;sid:84359746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rle123/ai-self-coding-book/releases/download/v1.0/program.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496631/; classtype:trojan-activity;sid:84359731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skibidi-crypto/quarkus-openapi-problem/releases/download/v1.4.2/quarkus-openapi-problem-v1.4.2.zip"; depth:99; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496594/; classtype:trojan-activity;sid:84359694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stepbox23/assets/60af1f798cc4708a2872a66cebab351e529e43f8/software.zip"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496564/; classtype:trojan-activity;sid:84359664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new_image.jpg"; depth:14; endswith; nocase; http.host; content:"talentrecruitments.com"; depth:22; isdataat:!1,relative; metadata:created_at 2025_03_30; reference:url, urlhaus.abuse.ch/url/3496067/; classtype:trojan-activity;sid:84359167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eed8989/u/raw/refs/heads/main/ud.bat"; depth:37; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_30; reference:url, urlhaus.abuse.ch/url/3496061/; classtype:trojan-activity;sid:84359161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eed8989/u/raw/main/ud.bat"; depth:26; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_30; reference:url, urlhaus.abuse.ch/url/3496058/; classtype:trojan-activity;sid:84359158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3495857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tsl/downloader.exe"; depth:19; endswith; nocase; http.host; content:"tobecation.github.io"; depth:20; isdataat:!1,relative; metadata:created_at 2025_03_30; reference:url, urlhaus.abuse.ch/url/3495857/; classtype:trojan-activity;sid:84358957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/w.sh"; depth:5; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_29; reference:url, urlhaus.abuse.ch/url/3494818/; classtype:trojan-activity;sid:84357918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c.sh"; depth:5; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_29; reference:url, urlhaus.abuse.ch/url/3494816/; classtype:trojan-activity;sid:84357916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm5"; depth:5; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494037/; classtype:trojan-activity;sid:84357137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494038)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mpsl"; depth:5; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494038/; classtype:trojan-activity;sid:84357138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm"; depth:4; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494039/; classtype:trojan-activity;sid:84357139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ppc"; depth:4; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494040/; classtype:trojan-activity;sid:84357140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86"; depth:4; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494041/; classtype:trojan-activity;sid:84357141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm6"; depth:5; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494042/; classtype:trojan-activity;sid:84357142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sh4"; depth:4; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494043/; classtype:trojan-activity;sid:84357143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spc"; depth:4; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494044/; classtype:trojan-activity;sid:84357144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m68k"; depth:5; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494045/; classtype:trojan-activity;sid:84357145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3494046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mips"; depth:5; endswith; nocase; http.host; content:"160.187.146.122"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3494046/; classtype:trojan-activity;sid:84357146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3493608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aussieonzaza/assets/refs/heads/master/launcher.zip"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3493608/; classtype:trojan-activity;sid:84356708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3493604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rafael1679/assets/raw/refs/heads/master/launcher.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3493604/; classtype:trojan-activity;sid:84356704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abdeu-cpu/coap-mqtt-encryption/releases/download/v1.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492622/; classtype:trojan-activity;sid:84355722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/forzon96/cataclismo/releases/download/1.4.6/cataclismo_1.4.6.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492611/; classtype:trojan-activity;sid:84355711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mjunaid87/tokenset/releases/download/v2.8.1/tokenset.v2.8.1.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492613/; classtype:trojan-activity;sid:84355713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joacokia/oopd/releases/download/bretschneideraceae/oopd_bretschneideraceae.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492608/; classtype:trojan-activity;sid:84355708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mardecilnonp568/assasin-creed-shadows/releases/download/v2.7.5/assassin-creed-shadows-v2.7.5.zip"; depth:97; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492600/; classtype:trojan-activity;sid:84355700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reninstem/productlisting/releases/download/2.6.1/productlisting-2.6.1.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492563/; classtype:trojan-activity;sid:84355663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uragon005/ai-chatbot-svelte/releases/download/v2.4.5/ai-chatbot-svelte_v2.4.5.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492160/; classtype:trojan-activity;sid:84355260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aussieonzaza/assets/raw/refs/heads/master/launcher.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492056/; classtype:trojan-activity;sid:84355156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phamkhanhhung208/assets/refs/heads/master/launcher.zip"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490432/; classtype:trojan-activity;sid:84353532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rafael1679/assets/refs/heads/master/launcher.zip"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490427/; classtype:trojan-activity;sid:84353527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/beast2122006/assignment/238415a963aab57f18fd2c2ef60995d7c0b39fe0/library.txt"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490409/; classtype:trojan-activity;sid:84353509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilganrat342/dertyom/refs/heads/main/setup.exe"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490350/; classtype:trojan-activity;sid:84353450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rh/setup.exe"; depth:13; endswith; nocase; http.host; content:"d3cciiowg5l3jx.cloudfront.net"; depth:29; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490349/; classtype:trojan-activity;sid:84353449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kammywammyman/boyboy/main/chromeupdate.exe"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490313/; classtype:trojan-activity;sid:84353413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tacocat2222/materia-fivem/refs/heads/main/loader.exe"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490294/; classtype:trojan-activity;sid:84353394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aldenpogznet22/hamster-bot/releases/download/v1.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489509/; classtype:trojan-activity;sid:84352609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thurynw/uoffice_library_uot/releases/download/v1.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489502/; classtype:trojan-activity;sid:84352602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toanminh2004/duan1/releases/download/v2.0/software.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489474/; classtype:trojan-activity;sid:84352574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tatooo29/loco/releases/download/v1.0/application.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489476/; classtype:trojan-activity;sid:84352576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tatooo29/loco/releases/download/v2.0/software.zip"; depth:50; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489478/; classtype:trojan-activity;sid:84352578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmanykwim/simple-2/releases/download/v1.0/application.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489479/; classtype:trojan-activity;sid:84352579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cistelsa/predictive-sentiment-analysis-of-twitter-for-btc/releases/download/v1.0/software.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489480/; classtype:trojan-activity;sid:84352580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmanykwim/simple-proxytv/releases/download/v2.0/software.zip"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489481/; classtype:trojan-activity;sid:84352581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cistelsa/predictive-sentiment-analysis-of-twitter-for-btc/releases/download/v2.0/software.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489471/; classtype:trojan-activity;sid:84352571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmanykwim/simple-proxytv/releases/download/v1.0/application.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489472/; classtype:trojan-activity;sid:84352572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmanykwim/simple-2/releases/download/v2.0/software.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489473/; classtype:trojan-activity;sid:84352573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iampriam-dev/new/releases/download/v2.0/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489333/; classtype:trojan-activity;sid:84352433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akashnilrecovered/text-formatting-crash-course/releases/download/v2.0/software.zip"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489336/; classtype:trojan-activity;sid:84352436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/akashnilrecovered/text-formatting-crash-course/releases/download/v1.0/software.zip"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489340/; classtype:trojan-activity;sid:84352440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iampriam-dev/new/releases/download/v1.0/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489331/; classtype:trojan-activity;sid:84352431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/laravel-authentication-breeze/releases/download/v1.0/software.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489310/; classtype:trojan-activity;sid:84352410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/githubtutorial/releases/download/v1.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489313/; classtype:trojan-activity;sid:84352413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/laravel-authentication-breeze/releases/download/v2.0/software.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489314/; classtype:trojan-activity;sid:84352414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/fortify-auth-laravel/releases/download/v1.0/software.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489315/; classtype:trojan-activity;sid:84352415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/newlaravel/releases/download/v2.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489317/; classtype:trojan-activity;sid:84352417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/fortify-auth-laravel/releases/download/v2.0/software.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489307/; classtype:trojan-activity;sid:84352407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/book-e-commerce/releases/download/v2.0/software.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489308/; classtype:trojan-activity;sid:84352408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/book-e-commerce/releases/download/v1.0/software.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489300/; classtype:trojan-activity;sid:84352400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/newlaravel/releases/download/v1.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489303/; classtype:trojan-activity;sid:84352403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samueltonao/frontendmentor/releases/download/v1.0/application.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489274/; classtype:trojan-activity;sid:84352374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/ui-package-email-verify/releases/download/v2.0/software.zip"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489275/; classtype:trojan-activity;sid:84352375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samueltonao/frontendmentor/releases/download/v2.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489280/; classtype:trojan-activity;sid:84352380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/ui-package-email-verify/releases/download/v1.0/software.zip"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489288/; classtype:trojan-activity;sid:84352388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_bootable_recovery/releases/download/v2.0/software.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489266/; classtype:trojan-activity;sid:84352366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489265)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackslash-nitp/healthcare-web-page/releases/download/v2.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489265/; classtype:trojan-activity;sid:84352365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_tinycompress/releases/download/v2.0/software.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489263/; classtype:trojan-activity;sid:84352363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amandwivedi0/device_xiaomi_santoni/releases/download/v1.0/application.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489264/; classtype:trojan-activity;sid:84352364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_build/releases/download/v2.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489247/; classtype:trojan-activity;sid:84352347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489248)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_json-c/releases/download/v1.0/application.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489248/; classtype:trojan-activity;sid:84352348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/laravel-ecommerce-project/releases/download/v1.0/software.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489251/; classtype:trojan-activity;sid:84352351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_tinycompress/releases/download/v1.0/application.zip"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489252/; classtype:trojan-activity;sid:84352352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_build/releases/download/v1.0/application.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489253/; classtype:trojan-activity;sid:84352353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_selinux/releases/download/v1.0/application.zip"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489255/; classtype:trojan-activity;sid:84352355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_json-c/releases/download/v2.0/software.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489256/; classtype:trojan-activity;sid:84352356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amandwivedi0/device_xiaomi_santoni/releases/download/v2.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489260/; classtype:trojan-activity;sid:84352360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_tinyxml/releases/download/v1.0/application.zip"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489261/; classtype:trojan-activity;sid:84352361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_sqlite/releases/download/v1.0/application.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489231/; classtype:trojan-activity;sid:84352331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_bootable_recovery/releases/download/v1.0/application.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489232/; classtype:trojan-activity;sid:84352332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_bionic/releases/download/v1.0/application.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489240/; classtype:trojan-activity;sid:84352340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_sqlite/releases/download/v2.0/software.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489242/; classtype:trojan-activity;sid:84352342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/laravel-ecommerce-project/releases/download/v2.0/software.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489243/; classtype:trojan-activity;sid:84352343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ambassadorscoders/togonon_motiv.poster/releases/download/v2.0/software.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489227/; classtype:trojan-activity;sid:84352327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_bionic/releases/download/v2.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489228/; classtype:trojan-activity;sid:84352328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eltrapico2/12-03assignment/releases/download/v1.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489214/; classtype:trojan-activity;sid:84352314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cvm010/nucleus/releases/download/v1.0/software.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489215/; classtype:trojan-activity;sid:84352315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489218)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eltrapico2/eltrapico2/releases/download/v1.0/software.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489218/; classtype:trojan-activity;sid:84352318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/puram-supriya/amazon/releases/download/v1.0/software.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489219/; classtype:trojan-activity;sid:84352319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eltrapico2/fri-app/releases/download/v1.0/software.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489205/; classtype:trojan-activity;sid:84352305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/puram-supriya/ecommerce/releases/download/v1.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489207/; classtype:trojan-activity;sid:84352307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/student-chicken/fit-track-goal-progress/releases/download/v1.0/software.zip"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489211/; classtype:trojan-activity;sid:84352311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/puram-supriya/resume/releases/download/v1.0/software.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489212/; classtype:trojan-activity;sid:84352312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cvm010/movie/releases/download/v1.0/software.zip"; depth:49; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489202/; classtype:trojan-activity;sid:84352302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vernaloqui/farmer-shubreact/releases/download/v1.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489203/; classtype:trojan-activity;sid:84352303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boomerxd69/fixing-error-0xc00000ba/releases/download/v2.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489173/; classtype:trojan-activity;sid:84352273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matimazzia/worldgame-web/releases/download/v1.0/software.zip"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489171/; classtype:trojan-activity;sid:84352271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489155)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yosif9999/hamster-clicker/releases/download/v3.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489155/; classtype:trojan-activity;sid:84352255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yosif9999/hamster-clicker/releases/download/v1.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489151/; classtype:trojan-activity;sid:84352251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drankrych/fakebtcsend/releases/download/v2.0/software.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489127/; classtype:trojan-activity;sid:84352227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/atom3dx/array-base-scatter-filled/releases/download/v2.0/software.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489128/; classtype:trojan-activity;sid:84352228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489129)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bluecheatah123/apex/releases/download/v2.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489129/; classtype:trojan-activity;sid:84352229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lethanhdat0403/earnorm/releases/download/v1.0/software.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489131/; classtype:trojan-activity;sid:84352231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/firematheo00x/chat-app-mern/releases/download/v1.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489135/; classtype:trojan-activity;sid:84352235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/monyigamer/bliss_browser_janet/releases/download/v1.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489137/; classtype:trojan-activity;sid:84352237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/monyigamer/bliss_browser_janet/releases/download/v2.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489118/; classtype:trojan-activity;sid:84352218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/firematheo00x/chat-app-mern/releases/download/v2.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489120/; classtype:trojan-activity;sid:84352220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lilanders123/act/releases/download/v2.0/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489090/; classtype:trojan-activity;sid:84352190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tatooo29/project-hub/releases/download/v2.0/software.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489088/; classtype:trojan-activity;sid:84352188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tatooo29/project-hub/releases/download/v1.0/application.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489083/; classtype:trojan-activity;sid:84352183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/booody123/manual-brick-breaker/releases/download/v1.0/program.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489054/; classtype:trojan-activity;sid:84352154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/booody123/manual-brick-breaker/releases/download/v2.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489047/; classtype:trojan-activity;sid:84352147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pedrokax/webscraper-to-identify-which-girls-and-how-many-of-them-my-boyfriend-follows-on-github/releases/download/v1.0/application.zip"; depth:135; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489032/; classtype:trojan-activity;sid:84352132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nash-abella/organization-service/releases/download/v1.0.0/application.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489035/; classtype:trojan-activity;sid:84352135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nash-abella/organization-service/releases/download/v2.0/software.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489027/; classtype:trojan-activity;sid:84352127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pedrokax/webscraper-to-identify-which-girls-and-how-many-of-them-my-boyfriend-follows-on-github/releases/download/v2.0/software.zip"; depth:132; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489028/; classtype:trojan-activity;sid:84352128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tailstheflyingfox/subghost/releases/download/v2.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489020/; classtype:trojan-activity;sid:84352120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/majorclient/html-crypto-currency-chart-snippets/releases/download/v2.0/software.zip"; depth:84; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488996/; classtype:trojan-activity;sid:84352096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whathedogding/bitpay-crypto-signal-trading-bot-analysis-signal-masters-trading-crypto/releases/download/v1.0/release.zip"; depth:121; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489002/; classtype:trojan-activity;sid:84352102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tailstheflyingfox/subghost/releases/download/v1.0/release.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489003/; classtype:trojan-activity;sid:84352103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zilts345890/golang-html-parsing/releases/download/v1.0/application.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489004/; classtype:trojan-activity;sid:84352104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seiolonmsk/contextindent.nvim/releases/download/v2.0/software.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489006/; classtype:trojan-activity;sid:84352106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nuclearcatlegit/simple_bank/releases/download/v1.0/application.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489009/; classtype:trojan-activity;sid:84352109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seiolonmsk/contextindent.nvim/releases/download/v1.0/application.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489010/; classtype:trojan-activity;sid:84352110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zilts345890/golang-html-parsing/releases/download/v1.0/program.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489011/; classtype:trojan-activity;sid:84352111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whathedogding/bitpay-crypto-signal-trading-bot-analysis-signal-masters-trading-crypto/releases/download/v2.0/software.zip"; depth:122; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489014/; classtype:trojan-activity;sid:84352114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naiahahah/musicbox/releases/download/v1.0/release.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489015/; classtype:trojan-activity;sid:84352115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nuclearcatlegit/simple_bank/releases/download/v2.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488994/; classtype:trojan-activity;sid:84352094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/seiolonmsk/contextindent.nvim/releases/download/v1.0/program.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488995/; classtype:trojan-activity;sid:84352095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/majorclient/html-crypto-currency-chart-snippets/releases/download/v1.0/release.zip"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488983/; classtype:trojan-activity;sid:84352083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peloixitu35/javascript-questions-pro/releases/download/v2.0/software.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488966/; classtype:trojan-activity;sid:84352066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/peloixitu35/javascript-questions-pro/releases/download/v1.0/program.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488969/; classtype:trojan-activity;sid:84352069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/konnuyu/0xbuilder/releases/download/v1.0/release_x64.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488950/; classtype:trojan-activity;sid:84352050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/finn9633/batchgenie/releases/download/v1.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488940/; classtype:trojan-activity;sid:84352040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/konnuyu/0xbuilder/releases/download/v2.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488941/; classtype:trojan-activity;sid:84352041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rakkunsatura/p.e.n.i.s./releases/download/v2.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488943/; classtype:trojan-activity;sid:84352043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thiagx08/bue-introduction-to-programming-and-problem-solving/releases/download/v1.0/release_x64.zip"; depth:100; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488945/; classtype:trojan-activity;sid:84352045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thiagx08/bue-introduction-to-programming-and-problem-solving/releases/download/v2.0/software.zip"; depth:97; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488946/; classtype:trojan-activity;sid:84352046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samix151210/ndarray-base-normalize-indices/releases/download/v2.0/software.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488890/; classtype:trojan-activity;sid:84351990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asdadadsaasdsadas991/database-project/releases/download/v2.0/software.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488880/; classtype:trojan-activity;sid:84351980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/merosegamerx/pizza_webapp/releases/download/v2.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488874/; classtype:trojan-activity;sid:84351974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/merosegamerx/pizza_webapp/releases/download/v1.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488879/; classtype:trojan-activity;sid:84351979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kleteee/injectra/releases/download/v1.0/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488850/; classtype:trojan-activity;sid:84351950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/feelingfishy/challenge-backend-anotaai/releases/download/v2.0/software.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488821/; classtype:trojan-activity;sid:84351921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nsgaming999/lottery/releases/download/v1.0/application.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488822/; classtype:trojan-activity;sid:84351922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ruka232323/network-traffic-visualizer/releases/download/v1.0/application.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488799/; classtype:trojan-activity;sid:84351899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/feelingfishy/challenge-backend-anotaai/releases/download/v1.0/application.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488800/; classtype:trojan-activity;sid:84351900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ruka232323/network-traffic-visualizer/releases/download/v2.0/software.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488802/; classtype:trojan-activity;sid:84351902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pietro152/tgbot-for-orders/releases/download/v1.0/application.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488806/; classtype:trojan-activity;sid:84351906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nsgaming999/lottery/releases/download/v2.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488793/; classtype:trojan-activity;sid:84351893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pietro152/tgbot-for-orders/releases/download/v2.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488795/; classtype:trojan-activity;sid:84351895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hza3o/covid-19_dashboard/releases/download/v2.0/software.zip"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488779/; classtype:trojan-activity;sid:84351879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488780)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hza3o/covid-19_dashboard/releases/download/v1.0.0/application.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488780/; classtype:trojan-activity;sid:84351880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1set-t/ai-model/releases/download/v1.0.0/application.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488765/; classtype:trojan-activity;sid:84351865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1set-t/ai-model/releases/download/v2.0/software.zip"; depth:52; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488758/; classtype:trojan-activity;sid:84351858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mah-22/room-occupancy-prediction-using-environmental-sensor-data/releases/download/v1.0/application.zip"; depth:104; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488755/; classtype:trojan-activity;sid:84351855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488746)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mah-22/room-occupancy-prediction-using-environmental-sensor-data/releases/download/v2.0/software.zip"; depth:101; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488746/; classtype:trojan-activity;sid:84351846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488751)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/serbianty/eureka-framework/releases/download/v1.0/soft.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488751/; classtype:trojan-activity;sid:84351851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/serbianty/eureka-framework/releases/download/v2.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488752/; classtype:trojan-activity;sid:84351852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaylnjohnart/vertex-ai-chat-prompting-tablular-data-bq/releases/download/v2.0/software.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488729/; classtype:trojan-activity;sid:84351829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrx-slayer/ai-resume-parser/releases/download/v1.0/application.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488730/; classtype:trojan-activity;sid:84351830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrx-slayer/ai-resume-parser/releases/download/v2.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488732/; classtype:trojan-activity;sid:84351832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/papajszef/web-devapp/releases/download/v2.0/software.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488733/; classtype:trojan-activity;sid:84351833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gopuatop100/badan-hukum/releases/download/v1.0/release.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488734/; classtype:trojan-activity;sid:84351834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jobetsison/working-with-form-validation-in-an-asp.net-core-rich-text-editor/releases/download/v1.0/program.zip"; depth:111; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488735/; classtype:trojan-activity;sid:84351835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/papajszef/web-devapp/releases/download/v1.0/application.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488736/; classtype:trojan-activity;sid:84351836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mrx-slayer/ai-resume-parser/releases/download/v1.0/program.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488739/; classtype:trojan-activity;sid:84351839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/as3dyasen/portfolio/releases/download/v2.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488740/; classtype:trojan-activity;sid:84351840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/as3dyasen/portfolio/releases/download/v1.0/release.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488742/; classtype:trojan-activity;sid:84351842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gopuatop100/badan-hukum/releases/download/v2.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488725/; classtype:trojan-activity;sid:84351825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jobetsison/working-with-form-validation-in-an-asp.net-core-rich-text-editor/releases/download/v2.0/software.zip"; depth:112; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488728/; classtype:trojan-activity;sid:84351828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jaylnjohnart/vertex-ai-chat-prompting-tablular-data-bq/releases/download/v1.0/program.zip"; depth:90; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488722/; classtype:trojan-activity;sid:84351822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/papajszef/web-devapp/releases/download/v1.0/program.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488723/; classtype:trojan-activity;sid:84351823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azw1/suction-funnel-for-bosch-click-clean-system/releases/download/v1.0/program.zip"; depth:84; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488720/; classtype:trojan-activity;sid:84351820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zrty456/web-development-project-2/releases/download/v1.0/program.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488711/; classtype:trojan-activity;sid:84351811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tekin441/urban_company_clone/releases/download/v1.0/program.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488712/; classtype:trojan-activity;sid:84351812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tekin441/urban_company_clone/releases/download/v1.0/application.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488713/; classtype:trojan-activity;sid:84351813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flameoptics/xkucoinbot-script-autoclicker/releases/download/v1.0/program.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488714/; classtype:trojan-activity;sid:84351814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flameoptics/xkucoinbot-script-autoclicker/releases/download/v2.0/software.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488716/; classtype:trojan-activity;sid:84351816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psxdupes028/comfyui-bs_kokoro-onnx/releases/download/v1.0/application.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488717/; classtype:trojan-activity;sid:84351817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zrty456/web-development-project-2/releases/download/v2.0/software.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488706/; classtype:trojan-activity;sid:84351806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azw1/suction-funnel-for-bosch-click-clean-system/releases/download/v1.0/application.zip"; depth:88; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488708/; classtype:trojan-activity;sid:84351808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tekin441/urban_company_clone/releases/download/v2.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488702/; classtype:trojan-activity;sid:84351802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azw1/suction-funnel-for-bosch-click-clean-system/releases/download/v2.0/software.zip"; depth:85; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488703/; classtype:trojan-activity;sid:84351803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psxdupes028/comfyui-bs_kokoro-onnx/releases/download/v2.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488704/; classtype:trojan-activity;sid:84351804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/psxdupes028/comfyui-bs_kokoro-onnx/releases/download/v1.0/program.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488699/; classtype:trojan-activity;sid:84351799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/antonio12gkn71/underlayer/releases/download/v1.0/application.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488684/; classtype:trojan-activity;sid:84351784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sundarlalji/autoimport/releases/download/v2.0/software.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488686/; classtype:trojan-activity;sid:84351786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sundarlalji/autoimport/releases/download/v1.0.0/application.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488682/; classtype:trojan-activity;sid:84351782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/antonio12gkn71/underlayer/releases/download/v2.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488679/; classtype:trojan-activity;sid:84351779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samueltonao/lauth/releases/download/v2.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488673/; classtype:trojan-activity;sid:84351773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hadesxyzz/baichuan-m1-14b/releases/download/v2.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488674/; classtype:trojan-activity;sid:84351774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hadesxyzz/baichuan-m1-14b/releases/download/v1.0/application.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488663/; classtype:trojan-activity;sid:84351763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/samueltonao/lauth/releases/download/v1.0/application.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488666/; classtype:trojan-activity;sid:84351766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muum1209/couplers/releases/download/v2.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488647/; classtype:trojan-activity;sid:84351747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/muum1209/couplers/releases/download/v1.0/application.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488649/; classtype:trojan-activity;sid:84351749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/npcgamingyt-thegoat/telegram-robot-handler/releases/download/v2.0/software.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488654/; classtype:trojan-activity;sid:84351754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/npcgamingyt-thegoat/telegram-robot-handler/releases/download/v1.0/application.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488643/; classtype:trojan-activity;sid:84351743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/18630095/software.zip"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488636/; classtype:trojan-activity;sid:84351736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ericsribas/linux-studies/releases/download/v2.0/software.zip"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488637/; classtype:trojan-activity;sid:84351737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/18630095/software.zip"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488632/; classtype:trojan-activity;sid:84351732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saninmysore/aws-face-recognition/releases/download/v1.0/software.zip/"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488620/; classtype:trojan-activity;sid:84351720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ericsribas/linux-studies/releases/download/v2.0/software.zip"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488599/; classtype:trojan-activity;sid:84351699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qaqmmw/music-recommendation-based-on-facial-expression/releases/download/v1.0/software.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488602/; classtype:trojan-activity;sid:84351702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/binnizenobiocordovaleandro/apachimuhkayqui-server/releases/download/v2.0/software.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488605/; classtype:trojan-activity;sid:84351705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bryandejesusrt/reconocimiento-de-placas-con-ia-bytecoders/releases/download/v2.0/software.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488606/; classtype:trojan-activity;sid:84351706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boomerxd69/amog-os-lts/releases/download/v2.0/software.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488608/; classtype:trojan-activity;sid:84351708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kasonsh2450/bananan-shooter-hack-interna-/releases/download/v2.0/software.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488614/; classtype:trojan-activity;sid:84351714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/18722098/application.zip"; depth:48; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488615/; classtype:trojan-activity;sid:84351715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/18722098/application.zip"; depth:48; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488595/; classtype:trojan-activity;sid:84351695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toe2132313/zorvex-cat/releases/download/v1.0/software.zip/"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488549/; classtype:trojan-activity;sid:84351649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xaviertya/.dotfiles/releases/download/v2.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488550/; classtype:trojan-activity;sid:84351650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zilts345890/golang-html-parsing/releases/download/v2.0/software.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488552/; classtype:trojan-activity;sid:84351652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naiahahah/musicbox/releases/download/v2.0/software.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488555/; classtype:trojan-activity;sid:84351655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xaviertya/.dotfiles/releases/download/v2.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488533/; classtype:trojan-activity;sid:84351633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aufahuhs/advanced-machine-learning-personal-project/releases/download/v1.0/software.zip"; depth:88; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488537/; classtype:trojan-activity;sid:84351637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ggusercool/pancakeswapbnbprediction/releases/download/v2.0/software.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488543/; classtype:trojan-activity;sid:84351643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12301530/pump-fun-frontend/releases/download/v1.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488511/; classtype:trojan-activity;sid:84351611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huizuohaode/ai-image-generator/releases/download/v1.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488505/; classtype:trojan-activity;sid:84351605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rahulpa045/cphishtermux/releases/download/v2.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488478/; classtype:trojan-activity;sid:84351578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/davinjoeevano/batch-project-scaffolds/releases/download/v2.0/software.zip/"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488483/; classtype:trojan-activity;sid:84351583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qaqmmw/music-recommendation-based-on-facial-expression/releases/download/v2.0/software.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488487/; classtype:trojan-activity;sid:84351587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bashspicerb/quasarrat-remote-access-tool/releases/download/v2.0/software.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488488/; classtype:trojan-activity;sid:84351588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cartervr/taxdatabase-sql-tableau/releases/download/v2.0/software.zip/"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488492/; classtype:trojan-activity;sid:84351592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/githubtutorial/releases/download/v2.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488496/; classtype:trojan-activity;sid:84351596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/globalnewsory/layeredge-auto-bot/releases/download/v2.0/software.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488497/; classtype:trojan-activity;sid:84351597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_tinyxml/releases/download/v2.0/software.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488501/; classtype:trojan-activity;sid:84351601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loudwens/displayindex/releases/download/v2.0/software.zip/"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488460/; classtype:trojan-activity;sid:84351560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pufferfish420/fixing-error-0x8007000e/releases/download/v2.0/program.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488441/; classtype:trojan-activity;sid:84351541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoodxsp5dda/domain-executor/releases/download/v2.0/program.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488443/; classtype:trojan-activity;sid:84351543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488436)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elijahhx/dead1ock-h4ck/releases/download/v2.0/program.zip/"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488436/; classtype:trojan-activity;sid:84351536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elijahhx/dead1ock-h4ck/releases/download/v2.0/program.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488433/; classtype:trojan-activity;sid:84351533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rag7720/coretech-solutions-custom-odoo-module/releases/download/v1.0/software.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488426/; classtype:trojan-activity;sid:84351526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rag7720/coretech-solutions-custom-odoo-module/releases/download/v2.0/software.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488425/; classtype:trojan-activity;sid:84351525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevinborgesz/the-data-engineering-academy/releases/download/v2.0/software.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488403/; classtype:trojan-activity;sid:84351503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kevinborgesz/the-data-engineering-academy/releases/download/v1.0/software.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488406/; classtype:trojan-activity;sid:84351506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notready155/whatsapp-chat-analysis/releases/download/v2.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488368/; classtype:trojan-activity;sid:84351468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilovedoo/ted-lasso-gpt/releases/download/v1.0/application.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488350/; classtype:trojan-activity;sid:84351450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/notready155/whatsapp-chat-analysis/releases/download/v1.0/application.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488359/; classtype:trojan-activity;sid:84351459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilovedoo/ted-lasso-gpt/releases/download/v2.0/software.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488360/; classtype:trojan-activity;sid:84351460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488346)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bigdaveyy/react-form-validator-pro/releases/download/v2.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488346/; classtype:trojan-activity;sid:84351446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin49/gym-management-system-/releases/download/v1.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488334/; classtype:trojan-activity;sid:84351434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bin49/gym-management-system-/releases/download/v2.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488336/; classtype:trojan-activity;sid:84351436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bigdaveyy/react-form-validator-pro/releases/download/v1.0/installer.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488339/; classtype:trojan-activity;sid:84351439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yunichi/livekit-voice-ai-agent-setup/releases/download/v2.0/software.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488325/; classtype:trojan-activity;sid:84351425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hvkleon/text-classification-sentiment-analysis/releases/download/v2.0/software.zip"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488314/; classtype:trojan-activity;sid:84351414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hvkleon/text-classification-sentiment-analysis/releases/download/v1.0/installer.zip"; depth:84; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488306/; classtype:trojan-activity;sid:84351406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thandoman/seedtool/releases/download/v2.0/software.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488307/; classtype:trojan-activity;sid:84351407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thandoman/seedtool/releases/download/v1.0/application.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488304/; classtype:trojan-activity;sid:84351404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/solana-trading-bot/releases/download/v2.0/software.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488294/; classtype:trojan-activity;sid:84351394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bashspicerb/quasarrat-remote-access-tool/releases/download/v1.0/installer.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488268/; classtype:trojan-activity;sid:84351368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marig1204/dmail_classicemail/releases/download/v2.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488269/; classtype:trojan-activity;sid:84351369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itztoastie/email2_classicemail/releases/download/v1.0/installer.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488273/; classtype:trojan-activity;sid:84351373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/marig1204/dmail_classicemail/releases/download/v1.0/installer.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488274/; classtype:trojan-activity;sid:84351374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488278)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/solana-trading-bot/releases/download/v1.0/software.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488278/; classtype:trojan-activity;sid:84351378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cartervr/taxdatabase-sql-tableau/releases/download/v1.0/release.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488282/; classtype:trojan-activity;sid:84351382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itztoastie/email2_classicemail/releases/download/v2.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488264/; classtype:trojan-activity;sid:84351364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bashspicerb/quasarrat-remote-access-tool/releases/download/v2.0/software.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488261/; classtype:trojan-activity;sid:84351361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pyc888/dbcachinglayer/releases/download/v2.0/software.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488243/; classtype:trojan-activity;sid:84351343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bolfymcplayer/intermag/releases/download/v1.0/software.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488233/; classtype:trojan-activity;sid:84351333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bolfymcplayer/intermag/releases/download/v2.0/software.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488234/; classtype:trojan-activity;sid:84351334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pyc888/dbcachinglayer/releases/download/v1.0/software.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488239/; classtype:trojan-activity;sid:84351339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kirito1110/licenses/releases/download/v1.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488214/; classtype:trojan-activity;sid:84351314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vsparedes/pycalc/releases/download/v1.0/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488213/; classtype:trojan-activity;sid:84351313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skibiditoilet123xx/sinav-otomasyonu-prototip/releases/download/v2.0/software.zip"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488208/; classtype:trojan-activity;sid:84351308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skibiditoilet123xx/sinav-otomasyonu-prototip/releases/download/v1.0/software.zip"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488209/; classtype:trojan-activity;sid:84351309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fluidx2/roombooking_application/releases/download/v1.0/software.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488210/; classtype:trojan-activity;sid:84351310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488211)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/viper700pro/serum-vst-installer-2024-free/releases/download/v1.0/software.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488211/; classtype:trojan-activity;sid:84351311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ella00311/erugo/releases/download/v1.0/software.zip"; depth:52; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488203/; classtype:trojan-activity;sid:84351303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nour10381/cosmicstar/releases/download/v2.0/software.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488182/; classtype:trojan-activity;sid:84351282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nour10381/cosmicstar/releases/download/v1.0/software.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488184/; classtype:trojan-activity;sid:84351284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/powerangermerah/esp8266_esp32_web_file_manager/releases/download/v2.0/software.zip"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488185/; classtype:trojan-activity;sid:84351285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/powerangermerah/esp8266_esp32_web_file_manager/releases/download/v1.0/software.zip"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488186/; classtype:trojan-activity;sid:84351286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aufahuhs/advanced-machine-learning-personal-project/releases/download/v1.0/software.zip"; depth:88; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488181/; classtype:trojan-activity;sid:84351281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/berstarhunter/deepseek-start/releases/download/v2.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488162/; classtype:trojan-activity;sid:84351262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/davinjoeevano/batch-project-scaffolds/releases/download/v2.0/software.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488157/; classtype:trojan-activity;sid:84351257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/irfanr-source/synthtweet/releases/download/v2.0/software.zip"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488156/; classtype:trojan-activity;sid:84351256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arya-gg/axium/releases/download/v1.0/software.zip"; depth:50; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488147/; classtype:trojan-activity;sid:84351247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/davinjoeevano/batch-project-scaffolds/releases/download/v1.0/software.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488148/; classtype:trojan-activity;sid:84351248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/berstarhunter/deepseek-start/releases/download/v1.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488152/; classtype:trojan-activity;sid:84351252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toe2132313/zorvex-cat/releases/download/v1.0/software.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488153/; classtype:trojan-activity;sid:84351253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/irfanr-source/synthtweet/releases/download/v1.0/software.zip"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488146/; classtype:trojan-activity;sid:84351246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loudwens/displayindex/releases/download/v2.0/software.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488128/; classtype:trojan-activity;sid:84351228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12301530/pump-fun-frontend/releases/download/v1.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488131/; classtype:trojan-activity;sid:84351231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loudwens/displayindex/releases/download/v1.0/software.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488132/; classtype:trojan-activity;sid:84351232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12301530/pump-fun-frontend/releases/download/v2.0/software.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488125/; classtype:trojan-activity;sid:84351225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saninmysore/aws-face-recognition/releases/download/v1.0/software.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488103/; classtype:trojan-activity;sid:84351203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flarerealfr/url-biblioteca-web/releases/download/v2.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488110/; classtype:trojan-activity;sid:84351210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prakrititz/deepwater/releases/download/v1.0/software.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488098/; classtype:trojan-activity;sid:84351198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huizuohaode/leaf/releases/download/v1.0/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488100/; classtype:trojan-activity;sid:84351200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/futurinav/esteai/releases/download/v1.0/software.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488102/; classtype:trojan-activity;sid:84351202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alsooory/svg-templates/releases/download/v1.0/software.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488079/; classtype:trojan-activity;sid:84351179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bobbysaremine/hb2/releases/download/v2.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488085/; classtype:trojan-activity;sid:84351185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_airbnb-lottie/releases/download/v2.0/software.zip"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488075/; classtype:trojan-activity;sid:84351175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ayobcoding/deep-research-py/releases/download/v1.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488061/; classtype:trojan-activity;sid:84351161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keanusmall/sahimatch.ai/releases/download/v1.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488054/; classtype:trojan-activity;sid:84351154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488057)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alejandro5486/infestuswebapp/releases/download/v1.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488057/; classtype:trojan-activity;sid:84351157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kossiw/olievra/releases/download/v1.0/software.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488035/; classtype:trojan-activity;sid:84351135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yogeshnicks/loader-ldtk/releases/download/v2.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488034/; classtype:trojan-activity;sid:84351134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vukhang16/ggg/releases/download/v1.0/software.zip"; depth:50; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488023/; classtype:trojan-activity;sid:84351123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_airbnb-lottie/releases/download/v1.0/application.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488021/; classtype:trojan-activity;sid:84351121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iampriam-dev/invenstock/releases/download/v1.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488000/; classtype:trojan-activity;sid:84351100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeidmakic/quorixjwt/releases/download/v1.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487983/; classtype:trojan-activity;sid:84351083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zeidmakic/quorixjwt/releases/download/v2.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487977/; classtype:trojan-activity;sid:84351077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amoni2019/fonepaw-screen-recorder-free/releases/download/v1.0/software.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487974/; classtype:trojan-activity;sid:84351074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brotimer24/chargingassignment.withtests/releases/download/v1.0/software.zip"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487975/; classtype:trojan-activity;sid:84351075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jay3x/auto-commit/releases/download/v2.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487947/; classtype:trojan-activity;sid:84351047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brotimer24/chargingassignment.withtests/releases/download/v2.0/software.zip"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487950/; classtype:trojan-activity;sid:84351050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/amoni2019/fonepaw-screen-recorder-free/releases/download/v2.0/software.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487952/; classtype:trojan-activity;sid:84351052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daveyisbricked/movie-finder-react/releases/download/v1.0/software.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487953/; classtype:trojan-activity;sid:84351053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daveyisbricked/movie-finder-react/releases/download/v2.0/software.zip"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487954/; classtype:trojan-activity;sid:84351054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jay3x/auto-commit/releases/download/v1.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487955/; classtype:trojan-activity;sid:84351055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quynh814/teafibot/releases/download/v2.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487956/; classtype:trojan-activity;sid:84351056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hafijulkhan786/fhnw-dashboard/releases/download/v2.0/software.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487944/; classtype:trojan-activity;sid:84351044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quynh814/teafibot/releases/download/v1.0/software.zip"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487939/; classtype:trojan-activity;sid:84351039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iampriam-dev/invenstock/releases/download/v2.0/software.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487935/; classtype:trojan-activity;sid:84351035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justnem/deep-research/releases/download/v2.0/software.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487930/; classtype:trojan-activity;sid:84351030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rofix12/spring-microservices/releases/download/v2.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487931/; classtype:trojan-activity;sid:84351031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justnem/deep-research/releases/download/v1.0/app.zip"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487929/; classtype:trojan-activity;sid:84351029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487918)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeff2807/githubaipy/releases/download/v1.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487918/; classtype:trojan-activity;sid:84351018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rahul110110/rocket-telemetry-logger-using-raspberry-pi-pico/releases/download/v1.0/software.zip"; depth:96; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487920/; classtype:trojan-activity;sid:84351020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jeff2807/githubaipy/releases/download/v2.0/software.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487921/; classtype:trojan-activity;sid:84351021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/binnizenobiocordovaleandro/apachimuhkayqui-server/releases/download/v2.0/software.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487916/; classtype:trojan-activity;sid:84351016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rofix12/spring-microservices/releases/download/v1.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487909/; classtype:trojan-activity;sid:84351009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rahul110110/rocket-telemetry-logger-using-raspberry-pi-pico/releases/download/v2.0/software.zip"; depth:96; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487905/; classtype:trojan-activity;sid:84351005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bryandejesusrt/reconocimiento-de-placas-con-ia-bytecoders/releases/download/v2.0/software.zip"; depth:94; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487902/; classtype:trojan-activity;sid:84351002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wer812/bhh666666666666/raw/refs/heads/main/service.exe"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_23; reference:url, urlhaus.abuse.ch/url/3487360/; classtype:trojan-activity;sid:84350460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wer812/vbvgghjjio999000/raw/refs/heads/main/bnoaprihjatuasss.exe"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_23; reference:url, urlhaus.abuse.ch/url/3487363/; classtype:trojan-activity;sid:84350463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wer812/bbgy555555551/raw/refs/heads/main/ntladlklthawd.exe"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_23; reference:url, urlhaus.abuse.ch/url/3487364/; classtype:trojan-activity;sid:84350464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3486184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ilganrat342/dgasgxc/refs/heads/main/setup.exe"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_22; reference:url, urlhaus.abuse.ch/url/3486184/; classtype:trojan-activity;sid:84349284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3485144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1k4idibw1vtsntpbqtvbfabfgm2h5s14d"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_21; reference:url, urlhaus.abuse.ch/url/3485144/; classtype:trojan-activity;sid:84348244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3485126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1km_hwk7sn_amuk7q2dk9kttzwk1taelw"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_21; reference:url, urlhaus.abuse.ch/url/3485126/; classtype:trojan-activity;sid:84348226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3485125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ek4th7ucqd9_h2yf9orhzhuallukeo0n"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_21; reference:url, urlhaus.abuse.ch/url/3485125/; classtype:trojan-activity;sid:84348225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoodxsp5dda/domain-executor/releases/download/v2.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483995/; classtype:trojan-activity;sid:84347095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoodxsp5dda/domain-executor/releases/download/v3.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483984/; classtype:trojan-activity;sid:84347084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoodxsp5dda/domain-executor/releases/download/v2.0/program.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483979/; classtype:trojan-activity;sid:84347079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoodxsp5dda/domain-executor/releases/download/v1.0/software.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483980/; classtype:trojan-activity;sid:84347080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1q6iji-1uq5ksrr3luufy3to-jfs4ec4d"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483406/; classtype:trojan-activity;sid:84346506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1g4q6iay5qjzlgigjqnwftkdc5-o_2pqx"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483317/; classtype:trojan-activity;sid:84346417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1cl-nvhrrue_wg2zkpuxmvk40tk3knacb"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483309/; classtype:trojan-activity;sid:84346409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/omio-saha/spotify_data_pipe_snowflake/releases/download/v1.0/release_x64.zip"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482360/; classtype:trojan-activity;sid:84345460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qaqmmw/music-recommendation-based-on-facial-expression/releases/download/v1.0/software.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482367/; classtype:trojan-activity;sid:84345467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qaqmmw/music-recommendation-based-on-facial-expression/releases/download/v2.0/software.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482368/; classtype:trojan-activity;sid:84345468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/css/colors/sunrise/xundfaxgnsp84.bin"; depth:46; endswith; nocase; http.host; content:"www.automobile-bk.de"; depth:20; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482262/; classtype:trojan-activity;sid:84345362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bear/2020/goldarnedest.aca"; depth:27; endswith; nocase; http.host; content:"www.support-data.com"; depth:20; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482257/; classtype:trojan-activity;sid:84345357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3481956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/numonehittaboy/cdn/refs/heads/main/cvf.exe"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3481956/; classtype:trojan-activity;sid:84345056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3481344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/alishazara/api/refs/heads/master/rh_s.txt"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_18; reference:url, urlhaus.abuse.ch/url/3481344/; classtype:trojan-activity;sid:84344444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3480616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty9989/u/raw/main/ud.bat"; depth:25; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_17; reference:url, urlhaus.abuse.ch/url/3480616/; classtype:trojan-activity;sid:84343716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3480361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/elijahhx/dead1ock-h4ck/releases/download/v2.0/program.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_17; reference:url, urlhaus.abuse.ch/url/3480361/; classtype:trojan-activity;sid:84343461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3480359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nurraif/mytonwallet/releases/download/v2.0/program.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_17; reference:url, urlhaus.abuse.ch/url/3480359/; classtype:trojan-activity;sid:84343459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3480274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gollfinho/browser-testing/releases/download/v2.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_17; reference:url, urlhaus.abuse.ch/url/3480274/; classtype:trojan-activity;sid:84343374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3478732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"96.9.87.21"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_15; reference:url, urlhaus.abuse.ch/url/3478732/; classtype:trojan-activity;sid:84341832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pufferfish420/fixing-error-0x8007000e/releases/download/v2.0/software.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475656/; classtype:trojan-activity;sid:84338756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/githubtutorial/releases/download/v2.0/software.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475642/; classtype:trojan-activity;sid:84338742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/phamtaino/fixing-error-0x80004005-unspecified/releases/download/v2.0/software.zip"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475644/; classtype:trojan-activity;sid:84338744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attorneywenn/pragati_backend_2025/releases/download/v2.0/application.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475645/; classtype:trojan-activity;sid:84338745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475646)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pufferfish420/fixing-error-0x8007000e/releases/download/v2.0/program.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475646/; classtype:trojan-activity;sid:84338746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_selinux/releases/download/v2.0/software.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475651/; classtype:trojan-activity;sid:84338751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/boomerxd69/amog-os-lts/releases/download/v2.0/software.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475624/; classtype:trojan-activity;sid:84338724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coltostemp/platform_external_tinyxml/releases/download/v2.0/software.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475630/; classtype:trojan-activity;sid:84338730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mehedihasanfarabi10/realtime-chat-app/releases/download/v2.0/software.zip"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475635/; classtype:trojan-activity;sid:84338735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/itznaviya/hamster-kombat-bot/releases/download/v3.0/software.zip"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475636/; classtype:trojan-activity;sid:84338736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kasonsh2450/fixing-error-0x80070005-access-denied/releases/download/v2.0/software.zip"; depth:86; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475637/; classtype:trojan-activity;sid:84338737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toanminh2004/fixing-error-0x80070424-specified-service/releases/download/v2.0/software.zip"; depth:91; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475639/; classtype:trojan-activity;sid:84338739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/naiahahah/musicbox/releases/download/v2.0/software.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475615/; classtype:trojan-activity;sid:84338715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kasonsh2450/bananan-shooter-hack-interna-/releases/download/v2.0/software.zip"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475620/; classtype:trojan-activity;sid:84338720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zilts345890/golang-html-parsing/releases/download/v2.0/software.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475623/; classtype:trojan-activity;sid:84338723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cartervr/taxdatabase-sql-tableau/releases/download/v2.0/software.zip"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473787/; classtype:trojan-activity;sid:84336887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ggusercool/pancakeswapbnbprediction/releases/download/v2.0/software.zip"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473766/; classtype:trojan-activity;sid:84336866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huizuohaode/ai-image-generator/releases/download/v1.0/software.zip"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473774/; classtype:trojan-activity;sid:84336874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yosif9999/hamster-clicker/releases/download/v2.0/software.zip"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473777/; classtype:trojan-activity;sid:84336877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/led-sol/mental-health-chatbot/releases/download/v1.0/software.zip"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473779/; classtype:trojan-activity;sid:84336879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473160)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1d4aper-gjv3agk8yeny5scayonlc68yo"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_10; reference:url, urlhaus.abuse.ch/url/3473160/; classtype:trojan-activity;sid:84336260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3472675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_10; reference:url, urlhaus.abuse.ch/url/3472675/; classtype:trojan-activity;sid:84335775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3468872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xraqwapfu.pdf"; depth:14; endswith; nocase; http.host; content:"galerisenimutiara.com"; depth:21; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3468872/; classtype:trojan-activity;sid:84331972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1eczx8yjtfxwos26grqtdixajed3ukcao"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467628/; classtype:trojan-activity;sid:84330728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1drptefwc7xybtum52bikrhp4j4l6lttc"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467629/; classtype:trojan-activity;sid:84330729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f2d42ffe-779b-4107-ac42-7f36375aab37/downloads/fojik.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467546/; classtype:trojan-activity;sid:84330646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/61705749605.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467537/; classtype:trojan-activity;sid:84330637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467538)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/dd3b43cd-389e-413e-87b9-e21f40c2630d/downloads/guledazawabumoda.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467538/; classtype:trojan-activity;sid:84330638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467533)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/637623a6-af9b-4a69-90a8-85cd562c999e/downloads/niwexokaburule.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467533/; classtype:trojan-activity;sid:84330633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/96f90b6e-3939-4cac-a3ad-eba9fb8219bf/downloads/71599608952.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467528/; classtype:trojan-activity;sid:84330628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3e712c63-2f24-4e6b-a5dc-ff3233100bea/downloads/72290413200.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467523/; classtype:trojan-activity;sid:84330623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2eabcd0a-1fbf-48aa-8399-71392232a891/downloads/rafubagosewuniwudob.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467524/; classtype:trojan-activity;sid:84330624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/70485427967.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467525/; classtype:trojan-activity;sid:84330625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e9dc005a-39e6-474d-bf2f-ef67b812a261/downloads/xenogipojadamomixaxulute.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467526/; classtype:trojan-activity;sid:84330626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/9089368795.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467527/; classtype:trojan-activity;sid:84330627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/96b6a2f4-8317-413b-a7e3-44adb2eb81f5/downloads/safari_magazine_2019_download.pdf"; depth:91; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467516/; classtype:trojan-activity;sid:84330616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8014aeaa-17b8-4bcd-a9d7-094ad1ff7644/downloads/fusoze.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467517/; classtype:trojan-activity;sid:84330617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467519)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/plan_technique_piscine_a_debordement.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467519/; classtype:trojan-activity;sid:84330619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/83838390139.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467521/; classtype:trojan-activity;sid:84330621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6104a42e-c9ca-496d-9156-92538fddca06/downloads/vevowezirebojikidebof.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467510/; classtype:trojan-activity;sid:84330610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/temisipilotiba.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467513/; classtype:trojan-activity;sid:84330613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/79427765137.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467501/; classtype:trojan-activity;sid:84330601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/examples_of_employee_goals_for_performance_review.pdf"; depth:111; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467478/; classtype:trojan-activity;sid:84330578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/50228966329.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467477/; classtype:trojan-activity;sid:84330577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/educational_leadership_philosophy_examples.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467475/; classtype:trojan-activity;sid:84330575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/299c0676-bac5-4db6-8fea-3075091e1687/downloads/61526216713.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467476/; classtype:trojan-activity;sid:84330576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/gumofeke.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467465/; classtype:trojan-activity;sid:84330565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/mawanigokur.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467466/; classtype:trojan-activity;sid:84330566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/36054141231.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467469/; classtype:trojan-activity;sid:84330569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a37fc73a-27ae-4e8d-87b6-7c807b298be6/downloads/85925649248.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467470/; classtype:trojan-activity;sid:84330570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/educacion_financiera_avanzada_partiendo_de_cero_autor_gregor.pdf"; depth:122; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467471/; classtype:trojan-activity;sid:84330571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/663ae0bf-1142-4d7a-8653-755553f6852e/downloads/lejafarezafig.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467472/; classtype:trojan-activity;sid:84330572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/biwejukajurel.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467474/; classtype:trojan-activity;sid:84330574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/6083216094.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467458/; classtype:trojan-activity;sid:84330558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/62128af0-82d0-4bae-b967-d393a4304003/downloads/69065118383.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467459/; classtype:trojan-activity;sid:84330559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/51e053ea-8122-46e3-bee6-6c00a935619c/downloads/40061082597.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467461/; classtype:trojan-activity;sid:84330561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/94224235634.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467462/; classtype:trojan-activity;sid:84330562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/739cff78-28a4-4749-8c7f-abf371b6a947/downloads/62789327536.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467463/; classtype:trojan-activity;sid:84330563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ee12fbcb-3848-4c54-8690-0d9c760d3837/downloads/5683334295.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467464/; classtype:trojan-activity;sid:84330564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d9b3f7f8-355a-428e-bb44-74bff775274d/downloads/supix.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467453/; classtype:trojan-activity;sid:84330553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/670646a4-4ce8-4367-bccc-c52d2083c9a3/downloads/chronogramme_dune_these_de_doctorat.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467454/; classtype:trojan-activity;sid:84330554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467455)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1e222df8-d197-4254-b90b-be3d3b023ef4/downloads/zopawakabubijipek.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467455/; classtype:trojan-activity;sid:84330555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/27590969755.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467456/; classtype:trojan-activity;sid:84330556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kudokexogikekuporeso.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467457/; classtype:trojan-activity;sid:84330557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/48255006417.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467452/; classtype:trojan-activity;sid:84330552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/09540d0c-1db9-4e3c-a32d-6eed7b48ae00/downloads/3841723103.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467448/; classtype:trojan-activity;sid:84330548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/exemple_de_dossier_raep_redige.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467443/; classtype:trojan-activity;sid:84330543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3007465f-aa28-4ea8-964e-00ec10d6daef/downloads/reinforced_concrete_wall_design_examples.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467444/; classtype:trojan-activity;sid:84330544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/munich_tourist_attractions_map.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467445/; classtype:trojan-activity;sid:84330545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c4a17de4-bdbb-4d1a-aaee-49990939d4cf/downloads/problue_7_nordson_manual.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467438/; classtype:trojan-activity;sid:84330538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/30229793875.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467440/; classtype:trojan-activity;sid:84330540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/cooling_tower_working.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467433/; classtype:trojan-activity;sid:84330533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/corporate_signature_authority_matrix_template_printable.pdf"; depth:117; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467434/; classtype:trojan-activity;sid:84330534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467425)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bb45e14d-29c5-4287-b67f-843105f3b091/downloads/continental_online_assessment_test_answers.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467425/; classtype:trojan-activity;sid:84330525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/465f36af-7a24-4906-9c2a-986dcb6b15f8/downloads/where_can_i_get_edo_state_of_origin_certificate_in_lagos.pdf"; depth:118; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467426/; classtype:trojan-activity;sid:84330526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/sample_testimonials_for_employees.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467427/; classtype:trojan-activity;sid:84330527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bf8d6b31-0867-4cc2-b138-2d2dbb23ec3a/downloads/bawananulufobomoderawulen.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467428/; classtype:trojan-activity;sid:84330528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/90dc87b4-fd7e-4412-9a6a-76e20db16dbd/downloads/23425133870.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467429/; classtype:trojan-activity;sid:84330529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a37fc73a-27ae-4e8d-87b6-7c807b298be6/downloads/86119351354.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467422/; classtype:trojan-activity;sid:84330522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/kagoferoxotopelabalim.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467423/; classtype:trojan-activity;sid:84330523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/how_to_write_letter_against_show_cause_notice.pdf"; depth:107; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467411/; classtype:trojan-activity;sid:84330511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/bevakabopodo.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467412/; classtype:trojan-activity;sid:84330512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/55669141050.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467416/; classtype:trojan-activity;sid:84330516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fb13673c-7b10-403f-be9e-1b04622101d6/downloads/61656569082.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467417/; classtype:trojan-activity;sid:84330517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/98264302577.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467418/; classtype:trojan-activity;sid:84330518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467408)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/grammar_plus_class_8.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467408/; classtype:trojan-activity;sid:84330508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/32575227287.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467409/; classtype:trojan-activity;sid:84330509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/xavibow.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467410/; classtype:trojan-activity;sid:84330510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b566d4a5-149a-4042-a2b5-fa837a998781/downloads/62246613540.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467400/; classtype:trojan-activity;sid:84330500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a5d43283-67be-4a3b-9041-1427b691166f/downloads/dotadaxokokimidupoz.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467401/; classtype:trojan-activity;sid:84330501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a19a3dcf-f832-45fe-91ff-ed566d492286/downloads/31803450103.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467403/; classtype:trojan-activity;sid:84330503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/26449761459.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467404/; classtype:trojan-activity;sid:84330504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/manual_de_uso_cummins_insite.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467395/; classtype:trojan-activity;sid:84330495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/83127272265.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467397/; classtype:trojan-activity;sid:84330497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/50013116393.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467389/; classtype:trojan-activity;sid:84330489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/sowuluxoranevoxivobu.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467391/; classtype:trojan-activity;sid:84330491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/jw_public_talk_outlines.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467392/; classtype:trojan-activity;sid:84330492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/muxem.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467386/; classtype:trojan-activity;sid:84330486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467381)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aa930190-2e12-4ce7-8bd7-0454f2ef6721/downloads/remonstration_visum_ablehnung_muster.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467381/; classtype:trojan-activity;sid:84330481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1cd14ca4-3aaa-4349-a92b-5919cb2c71ee/downloads/37493963429.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467382/; classtype:trojan-activity;sid:84330482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467383)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/26417869572.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467383/; classtype:trojan-activity;sid:84330483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/zutufukatozoxogunubikok.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467384/; classtype:trojan-activity;sid:84330484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/vawazu.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467385/; classtype:trojan-activity;sid:84330485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c4240411-5b76-4ebe-95b9-c00242399cf6/downloads/libevisuxalozusofaze.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467370/; classtype:trojan-activity;sid:84330470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d07e2353-3643-42fe-ba11-ffa772b1a28d/downloads/61695596025.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467371/; classtype:trojan-activity;sid:84330471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/remebemakuvomurixulat.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467372/; classtype:trojan-activity;sid:84330472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/35713869772.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467377/; classtype:trojan-activity;sid:84330477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/popezefere.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467363/; classtype:trojan-activity;sid:84330463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/57373027197.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467365/; classtype:trojan-activity;sid:84330465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1e00f0b9-c207-4cb1-9a9a-c11d057e31a3/downloads/request_letter_for_hold_amount_release.pdf"; depth:100; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467367/; classtype:trojan-activity;sid:84330467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9569c183-65dc-4f14-a45e-e7944584cb65/downloads/58650400832.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467369/; classtype:trojan-activity;sid:84330469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0684881f-11f6-455b-9188-fb070acdb368/downloads/you_too_can_be_prosperous.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467358/; classtype:trojan-activity;sid:84330458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e51c42a2-48a1-43ea-b124-a034de3679a6/downloads/sizusobimemitu.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467359/; classtype:trojan-activity;sid:84330459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/fosodevo.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467360/; classtype:trojan-activity;sid:84330460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/her_yonuyle_modern_almanca_dursun_zengin.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467353/; classtype:trojan-activity;sid:84330453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/towedokunorazageleside.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467354/; classtype:trojan-activity;sid:84330454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/65604431763.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467355/; classtype:trojan-activity;sid:84330455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/ruwuxa.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467357/; classtype:trojan-activity;sid:84330457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467347)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c725aa89-ce3b-4b0b-861e-e7c40702153d/downloads/sulupob.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467347/; classtype:trojan-activity;sid:84330447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0a2e88a7-385b-4aed-a81e-123c037cba5d/downloads/57067255053.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467348/; classtype:trojan-activity;sid:84330448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2ad58263-1b5c-4da7-bc4a-7b8f99e22218/downloads/2544897802.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467350/; classtype:trojan-activity;sid:84330450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/66812037618.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467352/; classtype:trojan-activity;sid:84330452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b4da0e1a-7caf-4ed8-aaa9-0949952990f3/downloads/49347806429.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467344/; classtype:trojan-activity;sid:84330444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467339)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7399f648-106b-4174-b8c0-6d6694895ad3/downloads/vakoxumem.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467339/; classtype:trojan-activity;sid:84330439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/gununemedusotojipime.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467340/; classtype:trojan-activity;sid:84330440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/92c7bb30-769c-4722-92cc-8b01b59910e0/downloads/36512394005.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467334/; classtype:trojan-activity;sid:84330434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7592d1e2-3dca-48f2-9f42-bb08c23dfb67/downloads/zutav.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467337/; classtype:trojan-activity;sid:84330437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8f97cb07-1cfa-4fca-b6d8-3f1bf47f56b3/downloads/dulerugufep.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467326/; classtype:trojan-activity;sid:84330426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/nopurumonufulelu.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467328/; classtype:trojan-activity;sid:84330428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467329)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2b44aaa8-926a-4cbd-9774-e30385fa65ac/downloads/zexesotusipedelew.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467329/; classtype:trojan-activity;sid:84330429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/security_daily_activity_report_template.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467321/; classtype:trojan-activity;sid:84330421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a3d7189d-efc6-47e1-bbe5-dc5eeaf610a0/downloads/rtca_do-160g.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467312/; classtype:trojan-activity;sid:84330412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ac66f4da-754b-4df9-b080-4728fb201349/downloads/nimoma.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467313/; classtype:trojan-activity;sid:84330413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c877865a-29ce-446f-b8f8-42c8a2318eff/downloads/personal_loan_closure_letter_format_in_word.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467314/; classtype:trojan-activity;sid:84330414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/11677680583.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467317/; classtype:trojan-activity;sid:84330417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/elkonin_boxes_word_list.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467318/; classtype:trojan-activity;sid:84330418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f4482b02-adbc-4511-a01d-8f5a32444a75/downloads/zudelejanegine.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467320/; classtype:trojan-activity;sid:84330420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c3d6560-d229-4015-8af2-a70ad89bde0a/downloads/80071621679.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467307/; classtype:trojan-activity;sid:84330407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/lapeke.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467305/; classtype:trojan-activity;sid:84330405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/kapabemirowajuzaxadirokef.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467303/; classtype:trojan-activity;sid:84330403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/modexad.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467304/; classtype:trojan-activity;sid:84330404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467298)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0bdc9896-149c-4815-8e37-9e55432c4120/downloads/bofugesugipufibutunida.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467298/; classtype:trojan-activity;sid:84330398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467300)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9c30937d-c8da-4e7b-9f7a-432344b46400/downloads/xuguxupevubitutuzoju.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467300/; classtype:trojan-activity;sid:84330400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/rubejemi.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467301/; classtype:trojan-activity;sid:84330401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/atividades_de_concordancia_verbal_5o_ano_com_gabarito.pdf"; depth:115; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467286/; classtype:trojan-activity;sid:84330386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/78c14b69-39ed-4d94-8d63-a7b29776e43c/downloads/45524925955.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467287/; classtype:trojan-activity;sid:84330387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/cyberark_psmp_admin_guide.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467292/; classtype:trojan-activity;sid:84330392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467295)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/kitab_shams_al_maarif.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467295/; classtype:trojan-activity;sid:84330395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3298be68-ecf2-4e6e-8fa7-1bf1d7657489/downloads/xagoje.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467283/; classtype:trojan-activity;sid:84330383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/83df8ca9-16c2-4244-8f9e-8be918c4b8a3/downloads/86611585002.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467279/; classtype:trojan-activity;sid:84330379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/41138401642.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467280/; classtype:trojan-activity;sid:84330380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467281)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ddc49093-0792-428b-8073-6170b30113a2/downloads/hepatorenales_syndrom.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467281/; classtype:trojan-activity;sid:84330381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467271)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fae029f6-27b1-4578-94bc-ae0bbaeebde4/downloads/53744052149.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467271/; classtype:trojan-activity;sid:84330371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9927c1c5-c61c-4f5e-807e-67bd1833b3e4/downloads/nijalox.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467274/; classtype:trojan-activity;sid:84330374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/how_to_change_font_size_in_xchange_editor.pdf"; depth:103; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467275/; classtype:trojan-activity;sid:84330375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/limitorque_mx_ordering_guide.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467277/; classtype:trojan-activity;sid:84330377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/timex_expedition_indiglo_wr50m_manual.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467266/; classtype:trojan-activity;sid:84330366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7a3b63b5-3e6a-48ac-8e49-14ed0037cbc4/downloads/hitachi_cd_sem_operation_manual.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467269/; classtype:trojan-activity;sid:84330369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/87483152555.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467264/; classtype:trojan-activity;sid:84330364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/36672004653.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467259/; classtype:trojan-activity;sid:84330359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9dc6fd8e-b629-406d-be34-231dfc94d5e9/downloads/catia_v5_simulation_tutorial.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467260/; classtype:trojan-activity;sid:84330360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/80e9e7c7-d97b-4b5a-96c4-9a83854a3065/downloads/vuzabovamipavowaseke.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467262/; classtype:trojan-activity;sid:84330362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/09077edc-9c07-4d95-9708-b2f62b12ca6a/downloads/jikiluwuruwewomurenix.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467254/; classtype:trojan-activity;sid:84330354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467258)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/weguma.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467258/; classtype:trojan-activity;sid:84330358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467246)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/119d5b03-e78f-4725-87b7-ed496b267f6d/downloads/attributes_of_a_good_research_topic_ppt.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467246/; classtype:trojan-activity;sid:84330346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1663535d-289f-4a17-902d-0bb53881ce69/downloads/kurupojofuxerixutalo.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467249/; classtype:trojan-activity;sid:84330349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467250)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/mizibatazikitawejubidodog.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467250/; classtype:trojan-activity;sid:84330350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/gibabasakofalulizuwa.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467251/; classtype:trojan-activity;sid:84330351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/meravinuvisudome.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467240/; classtype:trojan-activity;sid:84330340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/64114a94-94a3-4f5d-866a-beee254b955f/downloads/70815730326.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467241/; classtype:trojan-activity;sid:84330341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/86649529175.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467235/; classtype:trojan-activity;sid:84330335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/nims_703_b_answers.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467236/; classtype:trojan-activity;sid:84330336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cf660a09-f805-468d-bb57-fa3593615f41/downloads/tojanigawexulametuzuk.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467237/; classtype:trojan-activity;sid:84330337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bc2ad79b-5832-4a2d-a335-92537db54849/downloads/pinestars_choice.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467230/; classtype:trojan-activity;sid:84330330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/vupegazezo.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467231/; classtype:trojan-activity;sid:84330331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/18985117210.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467221/; classtype:trojan-activity;sid:84330321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467223)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/03167ecf-a61c-49ea-b541-7a074a81e1da/downloads/6655537579.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467223/; classtype:trojan-activity;sid:84330323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/41957679215.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467225/; classtype:trojan-activity;sid:84330325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/exemple_de_livret_2_vae_rempli.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467226/; classtype:trojan-activity;sid:84330326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f569f34e-b7af-41eb-9a21-0f9939c54b3f/downloads/64195657437.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467228/; classtype:trojan-activity;sid:84330328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/aspen_pims_manual.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467220/; classtype:trojan-activity;sid:84330320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/fivojudu.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467219/; classtype:trojan-activity;sid:84330319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/20019605198.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467210/; classtype:trojan-activity;sid:84330310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d258c0c8-b9d9-4d64-b965-01378617d9c6/downloads/45706940387.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467212/; classtype:trojan-activity;sid:84330312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/xajuxe.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467213/; classtype:trojan-activity;sid:84330313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/81f7a7ad-d4fe-4147-943f-584c2d1e9bf5/downloads/because_of_mr_terupt_online.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467214/; classtype:trojan-activity;sid:84330314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/fajupip.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467215/; classtype:trojan-activity;sid:84330315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/minetest_wiki_commands.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467205/; classtype:trojan-activity;sid:84330305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/ohanian_physics_volume_1.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467206/; classtype:trojan-activity;sid:84330306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1c97d706-1093-417b-afec-0c60fc1d8547/downloads/74906999263.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467207/; classtype:trojan-activity;sid:84330307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/900d123a-2557-4fa9-92f6-1446b602b979/downloads/deporiramuga.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467208/; classtype:trojan-activity;sid:84330308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/traffic_light_risk_assessment_template_mental_health.pdf"; depth:114; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467209/; classtype:trojan-activity;sid:84330309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/suritotowid.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467202/; classtype:trojan-activity;sid:84330302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/41821413009.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467196/; classtype:trojan-activity;sid:84330296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/804274b4-5f10-4c26-9de6-df56f38aac7c/downloads/14312384720.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467200/; classtype:trojan-activity;sid:84330300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/37654458598.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467187/; classtype:trojan-activity;sid:84330287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/23776368177.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467188/; classtype:trojan-activity;sid:84330288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/eb8ff9f7-37bb-4420-bfa0-f018b38dcfa6/downloads/17065535031.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467190/; classtype:trojan-activity;sid:84330290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/432a6cf0-f63b-4132-8b03-52615cd2c1c3/downloads/41591669011.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467191/; classtype:trojan-activity;sid:84330291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/2634956565.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467193/; classtype:trojan-activity;sid:84330293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/437a989b-0a84-4105-b8c7-1870eb56af29/downloads/sbi_disbursement_request_form.pdf"; depth:91; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467177/; classtype:trojan-activity;sid:84330277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/27f26436-44ad-4647-8929-a76a4ea0ea67/downloads/sample_query_letter_for_negligence_of_duty.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467180/; classtype:trojan-activity;sid:84330280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/sapebufuj.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467181/; classtype:trojan-activity;sid:84330281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4365da4a-8d29-4708-8e67-b3b566794d83/downloads/fovizijazobupukototofosop.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467184/; classtype:trojan-activity;sid:84330284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/93759555539.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467186/; classtype:trojan-activity;sid:84330286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/ligitove.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467175/; classtype:trojan-activity;sid:84330275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/62404701972.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467176/; classtype:trojan-activity;sid:84330276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/069f5eef-b21d-41b6-aaa6-569b53af1c5a/downloads/rawidesukusutalunug.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467171/; classtype:trojan-activity;sid:84330271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d102a54e-7197-4308-a937-d70c58240642/downloads/26442784020.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467172/; classtype:trojan-activity;sid:84330272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/83882971503.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467167/; classtype:trojan-activity;sid:84330267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/modelo_carta_entrega_de_inmueble_word.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467168/; classtype:trojan-activity;sid:84330268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467163)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/61905f2a-55dd-4144-8c7c-fce5e91063a8/downloads/british_army_all_arms_tactical_aide_memoire.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467163/; classtype:trojan-activity;sid:84330263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/rakotojifodonosanilorefa.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467166/; classtype:trojan-activity;sid:84330266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1ec2f808-78a9-4c99-aa80-be96e23bf450/downloads/gewikunobapizati.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467157/; classtype:trojan-activity;sid:84330257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7dda8154-e680-4c60-8651-19cf13768d49/downloads/jadol.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467158/; classtype:trojan-activity;sid:84330258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/nojivurajojirezizi.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467154/; classtype:trojan-activity;sid:84330254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98571e96-4bd9-4ee2-bb76-481ac550907e/downloads/genebugutisevijuk.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467156/; classtype:trojan-activity;sid:84330256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ddc49093-0792-428b-8073-6170b30113a2/downloads/jiwekonuwokesarejibezan.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467148/; classtype:trojan-activity;sid:84330248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/159e5f7b-5078-45c9-9b36-63f21684101f/downloads/94962104148.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467149/; classtype:trojan-activity;sid:84330249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9483bc30-bb1c-4c04-9cf3-38d205924dab/downloads/jugilususosu.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467150/; classtype:trojan-activity;sid:84330250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/virapajoridubibakoxofa.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467151/; classtype:trojan-activity;sid:84330251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/319984769.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467152/; classtype:trojan-activity;sid:84330252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/makusikarubikowaxosop.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467142/; classtype:trojan-activity;sid:84330242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467143)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/gikuxuze.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467143/; classtype:trojan-activity;sid:84330243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/voxuba.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467146/; classtype:trojan-activity;sid:84330246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/wokaselu.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467147/; classtype:trojan-activity;sid:84330247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/963d457e-5dea-4a7e-aae8-47aada2a7cc0/downloads/velafeke.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467135/; classtype:trojan-activity;sid:84330235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/97fcff61-ad1b-4591-bfda-ed7d6d6690f0/downloads/49593663309.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467137/; classtype:trojan-activity;sid:84330237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5e489076-b026-43ca-95da-8c6fe49f6d00/downloads/49103789197.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467138/; classtype:trojan-activity;sid:84330238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/zafekupegagasaza.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467132/; classtype:trojan-activity;sid:84330232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/55585429936.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467133/; classtype:trojan-activity;sid:84330233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/siwevewedelo.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467125/; classtype:trojan-activity;sid:84330225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/fedex_air_waybill_form.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467126/; classtype:trojan-activity;sid:84330226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d567d1b9-5a9f-4b97-a387-65a7c02f8ff4/downloads/barapinawowaja.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467127/; classtype:trojan-activity;sid:84330227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/44443741873.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467114/; classtype:trojan-activity;sid:84330214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/ravibopegaxipodek.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467115/; classtype:trojan-activity;sid:84330215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/haojue_chopper_road_150_manual.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467116/; classtype:trojan-activity;sid:84330216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/23c146af-6c5b-426f-944d-9bf55106e4d8/downloads/de_quien_es_hija_elisa_salinas.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467117/; classtype:trojan-activity;sid:84330217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/rewekawejujawidubekafebur.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467118/; classtype:trojan-activity;sid:84330218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3425f1f9-2741-4cdd-9a85-f51cd8a77838/downloads/pyidaungsu_font_keyboard_layout.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467121/; classtype:trojan-activity;sid:84330221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/carte_du_voyage_d_ulysse.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467123/; classtype:trojan-activity;sid:84330223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9f11cc6f-a645-4f71-bee4-e3848f35abf2/downloads/livro_domain_driven_design_portugues.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467109/; classtype:trojan-activity;sid:84330209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kulefenev.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467110/; classtype:trojan-activity;sid:84330210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/lobola_letter_example.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467111/; classtype:trojan-activity;sid:84330211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/acquisition_value_negative_in_area_01_aa617.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467108/; classtype:trojan-activity;sid:84330208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d8f5bd9b-2c75-4c1f-8d4d-84a7de1d3443/downloads/widavizuxorig.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467101/; classtype:trojan-activity;sid:84330201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/chris_mccandless_travel_route.pdf"; depth:91; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467102/; classtype:trojan-activity;sid:84330202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467103)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/17ef1a7d-be6f-43bc-ac3a-a9c4fb65005e/downloads/powejavatunepoxaj.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467103/; classtype:trojan-activity;sid:84330203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/937a3a5d-28a9-4a6d-983b-63f9d4fe1460/downloads/90328489234.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467106/; classtype:trojan-activity;sid:84330206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0319bbe-78e1-4446-90fc-2b4b4cc85a3e/downloads/wurowujezodabod.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467098/; classtype:trojan-activity;sid:84330198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pubobagawu.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467099/; classtype:trojan-activity;sid:84330199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/forest_fire_causes_and_effects.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467100/; classtype:trojan-activity;sid:84330200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6b07c7a9-24ea-41b4-835a-7daa4871c250/downloads/16_personality_factors_by_cattell.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467086/; classtype:trojan-activity;sid:84330186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/725aea16-586d-4b26-8216-cd50b4981a76/downloads/wiley_organic_chemistry_solutions_manual.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467087/; classtype:trojan-activity;sid:84330187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2224247e-29ce-4f8d-b838-abfcbdf269c0/downloads/psicoweb_respuestas_2019.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467088/; classtype:trojan-activity;sid:84330188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8e32f5a5-6a1a-4ade-b57e-fa54871724ef/downloads/2040244551.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467091/; classtype:trojan-activity;sid:84330191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/koxisiranarigavod.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467092/; classtype:trojan-activity;sid:84330192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467093)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59d4bc6c-1e33-45d9-a430-f89e52f3f795/downloads/subazituwa.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467093/; classtype:trojan-activity;sid:84330193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b6f72d87-e560-495a-a5bd-684e976b53e4/downloads/lettre_promesse_dembauche.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467094/; classtype:trojan-activity;sid:84330194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467080)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/971e893d-d96e-4c35-b8d0-897850ea3ce6/downloads/ice_quarterly_development_report_example.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467080/; classtype:trojan-activity;sid:84330180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/testigos_tablero_foton.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467081/; classtype:trojan-activity;sid:84330181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/how_to_get_gst_invoice_for_amazon_purchase.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467082/; classtype:trojan-activity;sid:84330182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8df58291-e0db-425a-9cda-a9882386ada6/downloads/24365322622.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467083/; classtype:trojan-activity;sid:84330183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4831e354-44dc-4759-9d14-0dd6cfda589f/downloads/91284214985.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467085/; classtype:trojan-activity;sid:84330185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c5dd25fc-7740-402b-aa70-862b15f3342c/downloads/8958005659.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467078/; classtype:trojan-activity;sid:84330178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/wewofolivofometu.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467079/; classtype:trojan-activity;sid:84330179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9e5b6b40-f934-4273-a65f-cbaee9aa4b00/downloads/9665669589.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467072/; classtype:trojan-activity;sid:84330172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/konibaxixim.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467073/; classtype:trojan-activity;sid:84330173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/20a6346a-1701-43f8-be7d-6426912a09c2/downloads/self_introduction_during_interview_example.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467074/; classtype:trojan-activity;sid:84330174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ff494cbe-9d2a-4ae4-802e-f50cfad48f0a/downloads/74334894285.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467075/; classtype:trojan-activity;sid:84330175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/55534301355.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467077/; classtype:trojan-activity;sid:84330177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/tevolutirasuvujivol.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467065/; classtype:trojan-activity;sid:84330165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3f5ecf8d-ba74-430f-ac11-9eb6ace92d02/downloads/73100246338.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467066/; classtype:trojan-activity;sid:84330166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b6f72d87-e560-495a-a5bd-684e976b53e4/downloads/earth_making_of_a_planet_national_geographic_worksheet.pdf"; depth:116; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467067/; classtype:trojan-activity;sid:84330167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/exercice_vitesse_6eme_physique.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467068/; classtype:trojan-activity;sid:84330168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/rapport_de_stage_3eme_agence_immobiliere.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467069/; classtype:trojan-activity;sid:84330169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/bisebinalujivefiwugagabu.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467070/; classtype:trojan-activity;sid:84330170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/miludafat.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467064/; classtype:trojan-activity;sid:84330164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ea6e6a77-ad86-47ad-bec1-a500695628d4/downloads/66906319004.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467061/; classtype:trojan-activity;sid:84330161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b77102f9-1066-4a92-8a14-af011902d081/downloads/75162502331.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467062/; classtype:trojan-activity;sid:84330162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/mapisirukuw.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467063/; classtype:trojan-activity;sid:84330163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/guzupuzuradadutov.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467058/; classtype:trojan-activity;sid:84330158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/081e0348-3bf0-4a3e-a723-749adc1aa630/downloads/teks_ratib_al_attas.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467059/; classtype:trojan-activity;sid:84330159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d07e2353-3643-42fe-ba11-ffa772b1a28d/downloads/49693757117.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467060/; classtype:trojan-activity;sid:84330160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/800cff82-04ba-4c47-9f8b-d21367acb04d/downloads/sabre_red_workspace_commands.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467050/; classtype:trojan-activity;sid:84330150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6702c9de-d943-4d22-b78e-7985c91f7713/downloads/84525111813.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467051/; classtype:trojan-activity;sid:84330151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/26bbb7e6-2f83-462e-b1a0-c9b7b5a50d38/downloads/training_needs_assessment_questionnaire_for_sales.pdf"; depth:111; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467052/; classtype:trojan-activity;sid:84330152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/najovozulubameto.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467053/; classtype:trojan-activity;sid:84330153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/225bb15f-2915-4639-a3a1-bcedb142b1ef/downloads/letter_format_for_reply_to_show_cause_notice.pdf"; depth:106; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467054/; classtype:trojan-activity;sid:84330154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c718f9e1-28ba-4c02-b434-4456f7af09a8/downloads/masizaz.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467055/; classtype:trojan-activity;sid:84330155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/51274200809.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467049/; classtype:trojan-activity;sid:84330149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/rolinejagogid.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467044/; classtype:trojan-activity;sid:84330144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/buxam.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467042/; classtype:trojan-activity;sid:84330142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6be9a470-c465-4776-ab76-53713c51537a/downloads/nokura.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467032/; classtype:trojan-activity;sid:84330132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/69da2f53-c229-4dc7-a889-7b67b52b1a78/downloads/nokejafowikazuvojoj.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467033/; classtype:trojan-activity;sid:84330133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e43067a0-6374-4a70-a00d-00ee3b01ce8d/downloads/93917384180.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467035/; classtype:trojan-activity;sid:84330135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0336533-680f-4ead-a55e-7e292796b70a/downloads/veteluruxoge.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467037/; classtype:trojan-activity;sid:84330137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/sirijega.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467024/; classtype:trojan-activity;sid:84330124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5c2804a6-aa9c-48a0-92fa-b4e2830d3e94/downloads/ladakh_tourist_map.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467025/; classtype:trojan-activity;sid:84330125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cc5e3c0a-70ce-48cf-a48d-87f83c6b3256/downloads/major_problems_in_african_american_history.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467027/; classtype:trojan-activity;sid:84330127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d38d43db-37ad-45ec-b237-63ac8c84a196/downloads/latovin.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467029/; classtype:trojan-activity;sid:84330129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c10f3982-2d8c-41ef-9c88-95b9c7e0984b/downloads/exagrid_admin_guide.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467018/; classtype:trojan-activity;sid:84330118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/2880955338.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467019/; classtype:trojan-activity;sid:84330119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9f4350e3-635b-45ba-b69f-b1a7e95f309e/downloads/24638138520.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467020/; classtype:trojan-activity;sid:84330120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/54349718441.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467022/; classtype:trojan-activity;sid:84330122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/satyanarayan_puja_vidhi_in_sanskrit.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467023/; classtype:trojan-activity;sid:84330123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/sample_letter_to_be_excused_from_jury_service.pdf"; depth:107; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467016/; classtype:trojan-activity;sid:84330116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cf660a09-f805-468d-bb57-fa3593615f41/downloads/vumemaxexepemetesa.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467011/; classtype:trojan-activity;sid:84330111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/93a7eb93-9eef-4244-8f20-7f48de1f8294/downloads/95493308607.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467012/; classtype:trojan-activity;sid:84330112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/91589198920.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467013/; classtype:trojan-activity;sid:84330113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/learn_korean_language_in_30_days.pdf"; depth:94; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467014/; classtype:trojan-activity;sid:84330114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/right_to_information_act_application_form_malayalam.pdf"; depth:113; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467015/; classtype:trojan-activity;sid:84330115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/zesowafasunufezef.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467006/; classtype:trojan-activity;sid:84330106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8e46fb0c-8d21-4b8c-82fc-88315c96ddde/downloads/bevurusip.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467008/; classtype:trojan-activity;sid:84330108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/09d72da9-ee58-43de-9ce0-8696fa874a10/downloads/zanozibiwakixubunifelok.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467002/; classtype:trojan-activity;sid:84330102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5d8bfe2e-b91e-431f-9bdc-3f0ea97e388e/downloads/hbc_radiomatic_fse_727_manual.pdf"; depth:91; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467003/; classtype:trojan-activity;sid:84330103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e4335d81-d2e5-4638-9638-30640b1be91f/downloads/sofipidegib.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466999/; classtype:trojan-activity;sid:84330099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/54040f30-acd4-4a4c-a314-5c4c261b537d/downloads/printable_foods_high_in_uric_acid_chart.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467000/; classtype:trojan-activity;sid:84330100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/15318963311.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466992/; classtype:trojan-activity;sid:84330092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c0f7f4ed-2d7c-4134-aa94-503b1eb6600b/downloads/pagulabomezex.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466993/; classtype:trojan-activity;sid:84330093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/katisugenifikipevas.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466996/; classtype:trojan-activity;sid:84330096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/xowawetavudazinomo.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466997/; classtype:trojan-activity;sid:84330097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7662afb9-5d02-4eb9-bd3b-6426a66215ee/downloads/2312138967.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466985/; classtype:trojan-activity;sid:84330085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/evaluation_geographie_6eme_habiter_une_metropole.pdf"; depth:110; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466986/; classtype:trojan-activity;sid:84330086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9441f8ad-6e79-4d4a-9602-3585b1269b7e/downloads/kobumedigudopixemevuwef.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466987/; classtype:trojan-activity;sid:84330087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8fc62093-f93e-447d-8e21-b1e235f4d9cc/downloads/vadigoxevujo.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466989/; classtype:trojan-activity;sid:84330089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/64414313920.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466991/; classtype:trojan-activity;sid:84330091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/mizoxuloniwi.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466979/; classtype:trojan-activity;sid:84330079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/66244318284.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466984/; classtype:trojan-activity;sid:84330084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6cdacb6d-7fbf-4d09-a986-56cdfa4edeb2/downloads/15247939327.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466971/; classtype:trojan-activity;sid:84330071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/example_of_a_lobola_letter_in_zulu.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466972/; classtype:trojan-activity;sid:84330072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466973)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ea25ddad-ebb0-4880-b714-a3f2cdadcbd9/downloads/notas_de_dinheiro_para_imprimir.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466973/; classtype:trojan-activity;sid:84330073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/606585da-2917-4da6-a9df-810ae6e7fbc1/downloads/asme_sec_8_div_1_appendix_8.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466975/; classtype:trojan-activity;sid:84330075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/segaxifalawanevake.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466976/; classtype:trojan-activity;sid:84330076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/3d_converter_for_autodesk_navisworks.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466968/; classtype:trojan-activity;sid:84330068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2c827e54-9a2c-449a-9d97-e20f9555c87a/downloads/pearson_iit_foundation_class_9_maths.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466969/; classtype:trojan-activity;sid:84330069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3d2c6212-591e-450b-b673-947709e569a9/downloads/jidikegegudafipi.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466970/; classtype:trojan-activity;sid:84330070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/62bebe3a-24c2-4a56-9b26-65d7a4a8233d/downloads/gupira.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466966/; classtype:trojan-activity;sid:84330066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/79599984772.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466958/; classtype:trojan-activity;sid:84330058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/actaris_meter_manual.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466957/; classtype:trojan-activity;sid:84330057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/passaic_county_technical_institute_salary_guide.pdf"; depth:109; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466946/; classtype:trojan-activity;sid:84330046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0c2227e9-a807-4022-9307-9c68c8629142/downloads/59021495355.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466950/; classtype:trojan-activity;sid:84330050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3abea8f6-1776-4586-b4e6-47b414d29e30/downloads/mozosadoboligemuwisuwet.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466951/; classtype:trojan-activity;sid:84330051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466952)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/malaysia_company_employee_handbook.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466952/; classtype:trojan-activity;sid:84330052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/988c0021-e131-496b-8725-ae310052894b/downloads/berakigevep.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466937/; classtype:trojan-activity;sid:84330037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c0325f5e-ab4f-48af-8631-8757a310624e/downloads/87631223928.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466938/; classtype:trojan-activity;sid:84330038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/majisumilorenanevivo.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466941/; classtype:trojan-activity;sid:84330041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466944)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/risukepidupapa.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466944/; classtype:trojan-activity;sid:84330044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c272bee0-a4e4-45f4-a8ce-0b066973e0cb/downloads/gateman_wk_20_english_manual.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466933/; classtype:trojan-activity;sid:84330033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/koxid.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466934/; classtype:trojan-activity;sid:84330034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/sasufazovosonufowam.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466935/; classtype:trojan-activity;sid:84330035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/6554737977.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466929/; classtype:trojan-activity;sid:84330029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4b7c63a1-8c4d-413e-83dc-2db6954011c6/downloads/42942412664.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466931/; classtype:trojan-activity;sid:84330031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/43589756342.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466928/; classtype:trojan-activity;sid:84330028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/juporuko.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466923/; classtype:trojan-activity;sid:84330023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1d231bc1-15b8-4d3d-b451-c05909392126/downloads/71014366481.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466924/; classtype:trojan-activity;sid:84330024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/29389545569.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466920/; classtype:trojan-activity;sid:84330020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fbb7d95c-19ce-4e6b-832c-1ccce7746b31/downloads/jebagokapinezax.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466915/; classtype:trojan-activity;sid:84330015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cb46680e-64d4-4308-8a44-9926381d0750/downloads/85747587751.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466916/; classtype:trojan-activity;sid:84330016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/ending_a_lease_letter_to_landlord.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466919/; classtype:trojan-activity;sid:84330019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/possession_letter_format_from_builder.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466909/; classtype:trojan-activity;sid:84330009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/mopuma.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466910/; classtype:trojan-activity;sid:84330010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a618ca0f-2608-47c2-ab22-bbc2ca127bb7/downloads/saziva.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466911/; classtype:trojan-activity;sid:84330011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/229e00b6-6232-4273-bd27-55f919ca28b8/downloads/financas_corporativas_teoria_e_pratica.pdf"; depth:100; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466912/; classtype:trojan-activity;sid:84330012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/76c40511-888a-4b14-bb65-87429974a9ff/downloads/gemotukuwitawusagulobez.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466913/; classtype:trojan-activity;sid:84330013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/vupenamubow.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466903/; classtype:trojan-activity;sid:84330003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/10269055308.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466904/; classtype:trojan-activity;sid:84330004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6ab86f22-a419-4e4f-91d4-5a654823f744/downloads/21711123451.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466905/; classtype:trojan-activity;sid:84330005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9e5b6b40-f934-4273-a65f-cbaee9aa4b00/downloads/14203617612.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466900/; classtype:trojan-activity;sid:84330000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e4ad6e04-69d1-4aa9-ba9f-c194e0ac5eef/downloads/lotavawofasopupe.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466902/; classtype:trojan-activity;sid:84330002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/mental_state_examination_checklist.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466898/; classtype:trojan-activity;sid:84329998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e5728c18-e5b3-4c69-bf59-a4be42aea8ac/downloads/22515332125.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466893/; classtype:trojan-activity;sid:84329993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/metso_neles_positioner_manual.pdf"; depth:91; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466894/; classtype:trojan-activity;sid:84329994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/9840498620.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466895/; classtype:trojan-activity;sid:84329995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3fffd8a4-4d1d-42f8-a3e8-f124f6724c06/downloads/kejawisenukasi.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466897/; classtype:trojan-activity;sid:84329997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/72065953692.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466885/; classtype:trojan-activity;sid:84329985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1ecb10a4-49e9-4fe5-a6bc-f0f227949dd2/downloads/60627448414.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466890/; classtype:trojan-activity;sid:84329990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/ramevedasap.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466881/; classtype:trojan-activity;sid:84329981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fbb7d95c-19ce-4e6b-832c-1ccce7746b31/downloads/67882203250.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466882/; classtype:trojan-activity;sid:84329982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/df312c7d-f650-4c0e-a98f-02aee1a43694/downloads/77125885812.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466877/; classtype:trojan-activity;sid:84329977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a37e9011-77af-43eb-9e7b-dd6853450512/downloads/27721436213.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466864/; classtype:trojan-activity;sid:84329964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6abf7f7e-d12c-48f3-aa9a-703f4ccff8d7/downloads/81403469667.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466866/; classtype:trojan-activity;sid:84329966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/zikirifusotuxusomel.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466869/; classtype:trojan-activity;sid:84329969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/antibiotic_sensitivity_chart_sanford_guide.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466870/; classtype:trojan-activity;sid:84329970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9c8a6489-894f-4446-8722-19ef31b6a173/downloads/26803015720.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466872/; classtype:trojan-activity;sid:84329972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4d2b55bf-cda3-4071-bf2e-8c27282b789f/downloads/chambre_de_tirage_telecom.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466873/; classtype:trojan-activity;sid:84329973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/48283c5b-b198-4860-9bf9-7f30a2f8146b/downloads/10387443769.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466875/; classtype:trojan-activity;sid:84329975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/zasuporuxumuza.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466876/; classtype:trojan-activity;sid:84329976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3d0a6e54-c95b-4e67-871e-882f39f9c203/downloads/77235011630.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466861/; classtype:trojan-activity;sid:84329961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/luvuges.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466863/; classtype:trojan-activity;sid:84329963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/tovidesukowoxam.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466858/; classtype:trojan-activity;sid:84329958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a5a93100-d349-4291-8bce-18547efeb268/downloads/14773335318.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466859/; classtype:trojan-activity;sid:84329959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/62bebe3a-24c2-4a56-9b26-65d7a4a8233d/downloads/xijawef.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466845/; classtype:trojan-activity;sid:84329945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a6301bc9-fbf1-4861-936b-8ce401d46d09/downloads/non_renewal_of_contract_letter_sample.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466846/; classtype:trojan-activity;sid:84329946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98fd26ea-5c50-4ebf-945e-7ed158ebe1b6/downloads/75925905792.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466847/; classtype:trojan-activity;sid:84329947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/561eb1da-cbac-4811-84b8-e841d63e56cb/downloads/fomogivazugararux.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466848/; classtype:trojan-activity;sid:84329948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3ccd9234-721c-480b-91a1-84bae34c2069/downloads/votudomafuze.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466849/; classtype:trojan-activity;sid:84329949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ed3e7e73-6deb-4ec1-95e4-868a6659fe93/downloads/manning_guide_hotel_sample.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466851/; classtype:trojan-activity;sid:84329951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/45596981954.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466852/; classtype:trojan-activity;sid:84329952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/tilovapexof.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466853/; classtype:trojan-activity;sid:84329953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/najufijirubedejalu.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466838/; classtype:trojan-activity;sid:84329938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d89879dd-a0f6-4cd8-8b66-99c2d6e48b2c/downloads/ludejawirusoxodofe.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466839/; classtype:trojan-activity;sid:84329939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/4959938645.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466843/; classtype:trojan-activity;sid:84329943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/52e9408f-c536-4a35-bd81-6078a5dce549/downloads/98085965001.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466832/; classtype:trojan-activity;sid:84329932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/dasuxugolod.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466833/; classtype:trojan-activity;sid:84329933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/804274b4-5f10-4c26-9de6-df56f38aac7c/downloads/attestation_de_non_affiliation_cnas_algerie.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466827/; classtype:trojan-activity;sid:84329927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/72502959-bd3f-431c-9582-055fb0eb9e9d/downloads/vw_gehaltstabelle_2022.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466828/; classtype:trojan-activity;sid:84329928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/nidugapageru.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466830/; classtype:trojan-activity;sid:84329930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f6f33080-7dde-4e51-88ef-59c9fd931fca/downloads/latoletevuwogerovug.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466831/; classtype:trojan-activity;sid:84329931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/40119004199.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466818/; classtype:trojan-activity;sid:84329918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d128fcda-7fcc-4d89-85b3-e79c54d4414e/downloads/talivejo.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466822/; classtype:trojan-activity;sid:84329922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/ansul_piranha_system_installation_manual.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466824/; classtype:trojan-activity;sid:84329924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/scada_system_architecture.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466813/; classtype:trojan-activity;sid:84329913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/63541235931.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466814/; classtype:trojan-activity;sid:84329914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bd6582d9-c54a-4b0b-ad89-3fd92efb45aa/downloads/gaylord_texan_hotel_map.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466802/; classtype:trojan-activity;sid:84329902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/laxokuzigurebudisinatonu.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466803/; classtype:trojan-activity;sid:84329903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/09d72da9-ee58-43de-9ce0-8696fa874a10/downloads/kojutaz.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466805/; classtype:trojan-activity;sid:84329905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/civil_engineer_experience_certificate_word_format.pdf"; depth:111; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466808/; classtype:trojan-activity;sid:84329908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/55d28ff0-9d0b-42b4-8190-887f90038148/downloads/gimisomogaro.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466799/; classtype:trojan-activity;sid:84329899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/950f7924-fa6b-44be-bda3-22eaf526f43f/downloads/how_to_write_a_letter_to_society_for_car_parking.pdf"; depth:110; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466800/; classtype:trojan-activity;sid:84329900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/78dac1c1-e6f9-4066-ad39-7cbcdc39e651/downloads/93448099882.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466801/; classtype:trojan-activity;sid:84329901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/payment_under_protest_letter_sample.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466794/; classtype:trojan-activity;sid:84329894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/43447829480.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466797/; classtype:trojan-activity;sid:84329897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/97374790135.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466798/; classtype:trojan-activity;sid:84329898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/71423402684.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466788/; classtype:trojan-activity;sid:84329888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5c9ed0ab-abf7-4895-9a79-d81e87aed60a/downloads/nezumizegorazulamalit.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466790/; classtype:trojan-activity;sid:84329890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a4c519f1-5301-485e-9e9c-56d1397df289/downloads/79371210580.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466791/; classtype:trojan-activity;sid:84329891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kekososiwixokaz.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466792/; classtype:trojan-activity;sid:84329892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/14889765830.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466778/; classtype:trojan-activity;sid:84329878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/rikisiwudepelapopazi.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466779/; classtype:trojan-activity;sid:84329879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/boriwivamafegujiser.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466781/; classtype:trojan-activity;sid:84329881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/seaworld_donation_request_orlando.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466782/; classtype:trojan-activity;sid:84329882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/schumacher_battery_charger_parts_se-4022.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466786/; classtype:trojan-activity;sid:84329886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d83328cf-50de-409a-9bf6-de7a48f66ed6/downloads/40650293844.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466787/; classtype:trojan-activity;sid:84329887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/ap_cm_relief_fund_application_process.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466777/; classtype:trojan-activity;sid:84329877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/narigokukeminozitema.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466768/; classtype:trojan-activity;sid:84329868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/32231114245.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466770/; classtype:trojan-activity;sid:84329870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fa0b65d5-8cfc-4875-922a-b490488b42be/downloads/schmersal_de-_42279_datasheet.pdf"; depth:91; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466771/; classtype:trojan-activity;sid:84329871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/checklist_format_for_housekeeping_in_hospital.pdf"; depth:107; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466772/; classtype:trojan-activity;sid:84329872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/91812224211.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466773/; classtype:trojan-activity;sid:84329873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/rizepigarebovubugebo.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466774/; classtype:trojan-activity;sid:84329874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/kawopixar.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466775/; classtype:trojan-activity;sid:84329875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/58311665155.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466767/; classtype:trojan-activity;sid:84329867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c0325f5e-ab4f-48af-8631-8757a310624e/downloads/93503353547.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466763/; classtype:trojan-activity;sid:84329863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6974f1eb-71bf-4f90-8572-d8ac4e4f765d/downloads/wazakovefonetak.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466764/; classtype:trojan-activity;sid:84329864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9978fe41-dbcb-4b88-8a80-a839de3f86b5/downloads/42576721881.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466758/; classtype:trojan-activity;sid:84329858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466759)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/73769466656.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466759/; classtype:trojan-activity;sid:84329859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/suvuraxelikubok.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466761/; classtype:trojan-activity;sid:84329861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3e09336e-0817-489c-96db-d43d5fd51fc4/downloads/i9_birth_certificate_example.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466762/; classtype:trojan-activity;sid:84329862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/stromer_st1_owners_manual.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466750/; classtype:trojan-activity;sid:84329850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/7215421885.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466753/; classtype:trojan-activity;sid:84329853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/37979647215.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466754/; classtype:trojan-activity;sid:84329854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/af0be9d0-b995-4f2a-8f66-25f04f50db42/downloads/tejovejujepotobafoba.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466755/; classtype:trojan-activity;sid:84329855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/43947647531.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466756/; classtype:trojan-activity;sid:84329856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/97640682614.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466747/; classtype:trojan-activity;sid:84329847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466748)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2ec5b631-127b-4a5e-84ff-7de19674a208/downloads/daxukipavibipukoj.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466748/; classtype:trojan-activity;sid:84329848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/66a9f463-0ae0-4403-bef2-3061bb9e36ef/downloads/rate_list_of_test_in_dr.lal_pathlabs.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466740/; classtype:trojan-activity;sid:84329840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c8939508-8a93-4f90-8b11-ddca3342e83a/downloads/4803379677.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466742/; classtype:trojan-activity;sid:84329842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ddc49093-0792-428b-8073-6170b30113a2/downloads/taski_procarpet_45_manual.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466745/; classtype:trojan-activity;sid:84329845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/gomik.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466738/; classtype:trojan-activity;sid:84329838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ef27ce0e-c911-4d37-baad-bea065e796b8/downloads/kirekafusofo.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466736/; classtype:trojan-activity;sid:84329836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/wiremabodopigotaf.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466732/; classtype:trojan-activity;sid:84329832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/67856105857.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466733/; classtype:trojan-activity;sid:84329833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/af0be9d0-b995-4f2a-8f66-25f04f50db42/downloads/rubetugetafapojopodibom.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466734/; classtype:trojan-activity;sid:84329834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/3048437595.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466724/; classtype:trojan-activity;sid:84329824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cc370600-8080-4216-8e6c-52a7f34eeccf/downloads/iso_weld_symbols_chart.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466726/; classtype:trojan-activity;sid:84329826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/47b969d8-0664-43a5-a1cb-4ec8411e9eef/downloads/powerflex_755_user_manual_espanol.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466728/; classtype:trojan-activity;sid:84329828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7539d3e4-198a-4c91-addc-38e6066bfe55/downloads/2305786492.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466729/; classtype:trojan-activity;sid:84329829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/kangwon_land_inc_annual_report.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466730/; classtype:trojan-activity;sid:84329830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4c0bdcf4-6f9c-40c3-8219-8cbbbcfb4026/downloads/wanigukanewalew.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466731/; classtype:trojan-activity;sid:84329831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/watiwime.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466715/; classtype:trojan-activity;sid:84329815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/638993752.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466716/; classtype:trojan-activity;sid:84329816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/milagetuxinofu.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466717/; classtype:trojan-activity;sid:84329817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7eafcf9d-33bd-4fd4-8489-654d240ab2f3/downloads/51295545026.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466719/; classtype:trojan-activity;sid:84329819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/xezumiriruko.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466720/; classtype:trojan-activity;sid:84329820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/cleavage_front_row_amy_measurements.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466721/; classtype:trojan-activity;sid:84329821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/diamond_sieve_chart.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466708/; classtype:trojan-activity;sid:84329808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/09b152c4-bf66-44a7-8224-2992cea3ed0a/downloads/sample_indian_renunciation_form.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466710/; classtype:trojan-activity;sid:84329810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/pelebesepasirokirefukew.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466711/; classtype:trojan-activity;sid:84329811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/455fd801-8453-4cfe-b6ee-1af9e2a627f6/downloads/7558215776.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466712/; classtype:trojan-activity;sid:84329812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e262bb3c-3205-4bb6-954b-f565479d59e0/downloads/50787175728.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466713/; classtype:trojan-activity;sid:84329813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d89879dd-a0f6-4cd8-8b66-99c2d6e48b2c/downloads/rotem_sigma_user_manual.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466706/; classtype:trojan-activity;sid:84329806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/lista_de_verbos_em_italiano.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466705/; classtype:trojan-activity;sid:84329805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a580c741-29a0-435a-a011-6aa538a5edae/downloads/25870917787.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466702/; classtype:trojan-activity;sid:84329802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/siwetofulugo.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466694/; classtype:trojan-activity;sid:84329794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0739216d-b619-42bb-83b4-7432b4331862/downloads/26798739628.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466695/; classtype:trojan-activity;sid:84329795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f36019eb-f077-446f-b5b6-39b8eacedf97/downloads/23513409250.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466696/; classtype:trojan-activity;sid:84329796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/the_long_dark_crumbling_highway_map.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466697/; classtype:trojan-activity;sid:84329797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2eabcd0a-1fbf-48aa-8399-71392232a891/downloads/92332863676.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466698/; classtype:trojan-activity;sid:84329798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4c633c3b-7c73-43a9-a161-0e7459f617b4/downloads/popajuzokovuluboz.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466682/; classtype:trojan-activity;sid:84329782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4b7c63a1-8c4d-413e-83dc-2db6954011c6/downloads/6759358871.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466684/; classtype:trojan-activity;sid:84329784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/41809607-5bd4-4a52-8a62-530dfb6fcdd7/downloads/gelumoxosudasikaxo.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466686/; classtype:trojan-activity;sid:84329786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cb46680e-64d4-4308-8a44-9926381d0750/downloads/47722224691.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466687/; classtype:trojan-activity;sid:84329787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/57326063662.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466689/; classtype:trojan-activity;sid:84329789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8aa13dbf-c0c5-4fe7-ae15-62e5c33a20e4/downloads/hewlett-packard_18e7_motherboard_specs.pdf"; depth:100; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466690/; classtype:trojan-activity;sid:84329790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/porebejotenojudud.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466691/; classtype:trojan-activity;sid:84329791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/72502959-bd3f-431c-9582-055fb0eb9e9d/downloads/duff_and_phelps_size_premium_2022.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466681/; classtype:trojan-activity;sid:84329781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pass_the_pigs_scoring_sheet.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466674/; classtype:trojan-activity;sid:84329774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6ae40ccb-f0fa-4b6b-bfcc-06032a30498c/downloads/logical_thinking_worksheets_for_kindergarten.pdf"; depth:106; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466679/; classtype:trojan-activity;sid:84329779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cb46680e-64d4-4308-8a44-9926381d0750/downloads/151743582.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466670/; classtype:trojan-activity;sid:84329770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/13792310994.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466671/; classtype:trojan-activity;sid:84329771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/cessna_172_instrument_panel_layout.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466666/; classtype:trojan-activity;sid:84329766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/24459864622.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466667/; classtype:trojan-activity;sid:84329767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4c0bdcf4-6f9c-40c3-8219-8cbbbcfb4026/downloads/10451479360.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466658/; classtype:trojan-activity;sid:84329758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/sap_fico_cutover_activities.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466659/; classtype:trojan-activity;sid:84329759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/98444125074.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466662/; classtype:trojan-activity;sid:84329762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/686c0a2e-9a90-4936-9f96-7d72f3c65f03/downloads/54960661120.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466663/; classtype:trojan-activity;sid:84329763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9c30937d-c8da-4e7b-9f7a-432344b46400/downloads/3262231356.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466664/; classtype:trojan-activity;sid:84329764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d89879dd-a0f6-4cd8-8b66-99c2d6e48b2c/downloads/livro_pesquisa_bibliografica.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466648/; classtype:trojan-activity;sid:84329748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/37ff6e83-e399-4f09-b7f3-13b9438039c2/downloads/54456550535.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466650/; classtype:trojan-activity;sid:84329750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/41780010-2245-4f59-96ea-abe2bb04704f/downloads/request_letter_format_in_marathi_language.pdf"; depth:103; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466652/; classtype:trojan-activity;sid:84329752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466645)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5809a244-7d90-46f4-9de4-ee86dda3a2de/downloads/evaluation_emc_6eme_devenir_collegien.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466645/; classtype:trojan-activity;sid:84329745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/dd809168-aa55-4437-9a0e-42447fbc16fd/downloads/22731947285.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466640/; classtype:trojan-activity;sid:84329740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/41780010-2245-4f59-96ea-abe2bb04704f/downloads/hypothecation_cancellation_request_letter_format.pdf"; depth:110; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466641/; classtype:trojan-activity;sid:84329741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/182ae1b8-0b64-4790-be7b-698d5e8b3d57/downloads/gidatigexapufalumiwolagad.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466642/; classtype:trojan-activity;sid:84329742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bd6582d9-c54a-4b0b-ad89-3fd92efb45aa/downloads/aocs_official_method_ce_1b_89.pdf"; depth:91; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466634/; classtype:trojan-activity;sid:84329734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pigogini.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466635/; classtype:trojan-activity;sid:84329735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ab158387-fd14-4136-be83-18d2feafd209/downloads/regonadafufosofujerijasur.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466639/; classtype:trojan-activity;sid:84329739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/xewegemodigu.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466625/; classtype:trojan-activity;sid:84329725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f9b61407-e9a0-4bfb-ac42-6ba811f07eed/downloads/daycare_reference_letter_template.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466626/; classtype:trojan-activity;sid:84329726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/displayport_1.4_spec.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466629/; classtype:trojan-activity;sid:84329729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0a49e03e-1cf9-44ed-ac44-c378f90fa5f8/downloads/63521883486.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466632/; classtype:trojan-activity;sid:84329732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/262ea410-a887-458b-b5ec-65748ef01e57/downloads/75258476975.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466633/; classtype:trojan-activity;sid:84329733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9441f8ad-6e79-4d4a-9602-3585b1269b7e/downloads/dajagunowe.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466619/; classtype:trojan-activity;sid:84329719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/432a6cf0-f63b-4132-8b03-52615cd2c1c3/downloads/hypochondria_ielts_reading_answers.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466620/; classtype:trojan-activity;sid:84329720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/migolijidawononavez.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466622/; classtype:trojan-activity;sid:84329722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466623)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6286d8b4-6ffa-4d84-aeea-f2a9bc58a594/downloads/hotel_courtesy_call_template.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466623/; classtype:trojan-activity;sid:84329723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/48cf8ef6-fe89-47b6-9b8e-43119a3d3833/downloads/89759746182.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466617/; classtype:trojan-activity;sid:84329717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/poquito_mas_nutrition_facts.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466613/; classtype:trojan-activity;sid:84329713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9a32841c-0d54-4ad0-8acd-a5b15c41cae1/downloads/luxutevosevuke.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466610/; classtype:trojan-activity;sid:84329710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/vamiralu.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466611/; classtype:trojan-activity;sid:84329711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/bonunorovekofa.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466605/; classtype:trojan-activity;sid:84329705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/36407415595.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466606/; classtype:trojan-activity;sid:84329706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/82707682561.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466607/; classtype:trojan-activity;sid:84329707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a0620227-6f33-427f-8ac7-1fb80d24bd78/downloads/loxabafefomukewizirefa.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466608/; classtype:trojan-activity;sid:84329708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/metric_bolt_specification_chart.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466609/; classtype:trojan-activity;sid:84329709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b6875802-d83d-45fa-a01c-dd9f30c53739/downloads/22305465780.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466597/; classtype:trojan-activity;sid:84329697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/efeaa59e-2423-41d8-b482-9a37e80979c7/downloads/ge_disconnect_switch.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466598/; classtype:trojan-activity;sid:84329698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7518eff6-349e-4445-8380-e1c43aacea7b/downloads/gemudewefedevovep.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466600/; classtype:trojan-activity;sid:84329700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/41809607-5bd4-4a52-8a62-530dfb6fcdd7/downloads/tugojokuru.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466601/; classtype:trojan-activity;sid:84329701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/hadoop_notes_by_durgasoft_ramakrishna.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466602/; classtype:trojan-activity;sid:84329702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/compassionate_leave_letter_examples.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466603/; classtype:trojan-activity;sid:84329703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2294c0f6-d737-4b16-8fca-94076227dda5/downloads/garrison_carbon_monoxide_and_gas_detector_manual.pdf"; depth:110; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466604/; classtype:trojan-activity;sid:84329704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/kuradorug.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466593/; classtype:trojan-activity;sid:84329693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7eafcf9d-33bd-4fd4-8489-654d240ab2f3/downloads/38053692779.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466594/; classtype:trojan-activity;sid:84329694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c4240411-5b76-4ebe-95b9-c00242399cf6/downloads/26107131918.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466595/; classtype:trojan-activity;sid:84329695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/tozivagal.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466587/; classtype:trojan-activity;sid:84329687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1b026e03-5af6-461d-a832-b5e23f93b19f/downloads/rojumedevunez.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466591/; classtype:trojan-activity;sid:84329691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/nefusajoxepisajejod.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466585/; classtype:trojan-activity;sid:84329685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/tubewerapip.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466581/; classtype:trojan-activity;sid:84329681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/18645484853.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466583/; classtype:trojan-activity;sid:84329683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/50ab7773-f1d2-4be6-a8e2-1065b2477787/downloads/4850921377.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466584/; classtype:trojan-activity;sid:84329684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/basimonuje.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466567/; classtype:trojan-activity;sid:84329667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4490da21-0774-43c2-8f10-26fe1384ffab/downloads/convention_collective_ucanss_mutatio.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466568/; classtype:trojan-activity;sid:84329668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2f6bcf3c-4b23-42e7-95db-7e5e3070b630/downloads/29680644903.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466569/; classtype:trojan-activity;sid:84329669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e297ab99-26f3-4763-8aa9-4b5ba8336826/downloads/61556440139.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466571/; classtype:trojan-activity;sid:84329671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/93a7eb93-9eef-4244-8f20-7f48de1f8294/downloads/rikeleneliteta.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466572/; classtype:trojan-activity;sid:84329672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/dupibutemuxubezukexe.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466559/; classtype:trojan-activity;sid:84329659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/58f82e37-5723-4fc5-be87-1ca34da7fc9c/downloads/ladovarudugusujo.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466561/; classtype:trojan-activity;sid:84329661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/93623530863.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466562/; classtype:trojan-activity;sid:84329662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f4482b02-adbc-4511-a01d-8f5a32444a75/downloads/31982364803.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466563/; classtype:trojan-activity;sid:84329663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c29905cb-cab1-47d6-9263-d073f5bcab67/downloads/manually_update_officescan_server.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466564/; classtype:trojan-activity;sid:84329664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/meligofat.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466565/; classtype:trojan-activity;sid:84329665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pibajusapasadasizuvabo.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466566/; classtype:trojan-activity;sid:84329666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/vuguvukopipokimukunoju.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466552/; classtype:trojan-activity;sid:84329652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/vmware_horizon_not_loading.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466553/; classtype:trojan-activity;sid:84329653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/gekepozokenaxaketojakoj.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466556/; classtype:trojan-activity;sid:84329656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/xekinozu.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466557/; classtype:trojan-activity;sid:84329657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d258c0c8-b9d9-4d64-b965-01378617d9c6/downloads/tanaber.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466558/; classtype:trojan-activity;sid:84329658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466546)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/lokodemerukezabakexa.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466546/; classtype:trojan-activity;sid:84329646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/wijigezafububofelib.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466547/; classtype:trojan-activity;sid:84329647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1a64ed17-85a2-4cee-b266-878ed957a17a/downloads/wezixipusafa.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466548/; classtype:trojan-activity;sid:84329648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6ed9a7df-8325-4b88-b206-4975011bd8d3/downloads/73303046927.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466551/; classtype:trojan-activity;sid:84329651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/vafibezesixura.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466544/; classtype:trojan-activity;sid:84329644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cdf9b72e-240a-4a41-ac28-e187be75db3e/downloads/10008295817.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466542/; classtype:trojan-activity;sid:84329642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466539)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/35017680871.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466539/; classtype:trojan-activity;sid:84329639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b5346c1d-c474-4a92-9b4c-cbf0eee37189/downloads/jamupipenimewuroveg.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466534/; classtype:trojan-activity;sid:84329634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ddc49093-0792-428b-8073-6170b30113a2/downloads/ritiwuga.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466523/; classtype:trojan-activity;sid:84329623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/697088a1-6c9a-496e-9a4d-922308cd97be/downloads/98558988287.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466524/; classtype:trojan-activity;sid:84329624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3d8c405e-d09a-43e6-b2b9-f8bbfe0e4b05/downloads/japifitakudisudupuweb.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466525/; classtype:trojan-activity;sid:84329625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b7519557-5091-4de7-b104-8e86c3953c5d/downloads/66697702965.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466527/; classtype:trojan-activity;sid:84329627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466528)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c4d8863b-da23-437d-86ed-df2351a23265/downloads/sazodaxorega.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466528/; classtype:trojan-activity;sid:84329628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/36655168913.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466512/; classtype:trojan-activity;sid:84329612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/wevularaboxurewugawe.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466513/; classtype:trojan-activity;sid:84329613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/rubizegelolulagexarunup.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466514/; classtype:trojan-activity;sid:84329614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466515)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c29905cb-cab1-47d6-9263-d073f5bcab67/downloads/pipe_fittings_surface_area_chart.pdf"; depth:94; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466515/; classtype:trojan-activity;sid:84329615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/ludirov.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466517/; classtype:trojan-activity;sid:84329617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/jedibam.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466521/; classtype:trojan-activity;sid:84329621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c2f5ec0b-52d8-40cb-8fa6-a66f6f891fa9/downloads/64630520522.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466522/; classtype:trojan-activity;sid:84329622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/19f0e93a-8f01-4f21-8964-dcc990dea571/downloads/honeywell_dc3002_manual.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466506/; classtype:trojan-activity;sid:84329606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/30963207670.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466507/; classtype:trojan-activity;sid:84329607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/963d457e-5dea-4a7e-aae8-47aada2a7cc0/downloads/36202936872.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466508/; classtype:trojan-activity;sid:84329608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/738cd3ca-10f0-4f1e-865e-c0932904fbb2/downloads/28412734415.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466509/; classtype:trojan-activity;sid:84329609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/af067739-2dfe-40f3-ae00-a758e587d7d3/downloads/wepepuv.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466510/; classtype:trojan-activity;sid:84329610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/atpco_fare_filing_manual_s.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466503/; classtype:trojan-activity;sid:84329603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/gartner_magic_quadrant_ips.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466504/; classtype:trojan-activity;sid:84329604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f2215a6c-0436-4d82-8033-c5d079398259/downloads/xawegifurixikinixi.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466505/; classtype:trojan-activity;sid:84329605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/nolovafitavire.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466501/; classtype:trojan-activity;sid:84329601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9f11cc6f-a645-4f71-bee4-e3848f35abf2/downloads/mojijodexiv.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466495/; classtype:trojan-activity;sid:84329595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/64114a94-94a3-4f5d-866a-beee254b955f/downloads/xipefodefanotare.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466497/; classtype:trojan-activity;sid:84329597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/gekulafemidafalijuw.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466498/; classtype:trojan-activity;sid:84329598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/types_of_lines_in_construction_drawings.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466489/; classtype:trojan-activity;sid:84329589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/psa_birth_certificate_authorization_letter.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466490/; classtype:trojan-activity;sid:84329590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/53202951-38c7-4c35-8280-6cefaf47915f/downloads/libububodanusakamarad.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466492/; classtype:trojan-activity;sid:84329592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/41202776349.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466480/; classtype:trojan-activity;sid:84329580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/dc583f51-62de-45fb-b9c6-f152dd4c2594/downloads/combining_like_terms_pyramid_worksheet_answers.pdf"; depth:108; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466481/; classtype:trojan-activity;sid:84329581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1dc2c198-09f6-4966-96bb-2e160c7d78e2/downloads/55840145977.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466482/; classtype:trojan-activity;sid:84329582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/puzenesariwalez.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466484/; classtype:trojan-activity;sid:84329584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c0eb552d-3ccf-4b3e-a340-0e3717106147/downloads/kalozarisi.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466485/; classtype:trojan-activity;sid:84329585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bb45e14d-29c5-4287-b67f-843105f3b091/downloads/wilikof.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466486/; classtype:trojan-activity;sid:84329586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/geruzirejexexani.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466487/; classtype:trojan-activity;sid:84329587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/de9d9f96-a289-4877-85d4-e6d2d4cc419c/downloads/minerva_t2000_manual.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466476/; classtype:trojan-activity;sid:84329576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/siemens_pcs_7_full_training_manual.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466474/; classtype:trojan-activity;sid:84329574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/sojawamiluredowad.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466472/; classtype:trojan-activity;sid:84329572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/add57eeb-0480-4d3e-871c-79d9b8fe2772/downloads/lozataroziwukurejigax.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466462/; classtype:trojan-activity;sid:84329562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/capacitor_bank_preventive_maintenance_checklist.pdf"; depth:109; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466463/; classtype:trojan-activity;sid:84329563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/jesafi.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466464/; classtype:trojan-activity;sid:84329564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/wofewipawo.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466465/; classtype:trojan-activity;sid:84329565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/58423586845.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466468/; classtype:trojan-activity;sid:84329568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466469)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/89849145142.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466469/; classtype:trojan-activity;sid:84329569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4c26a93a-50bb-4104-895b-059e3fc9a02c/downloads/zoxinigexozojadidara.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466460/; classtype:trojan-activity;sid:84329560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/96b6a2f4-8317-413b-a7e3-44adb2eb81f5/downloads/demande_d_allocation_chomage_pole_emploi.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466454/; classtype:trojan-activity;sid:84329554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/tutorialspoint_sap_pp.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466459/; classtype:trojan-activity;sid:84329559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/lafebokoz.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466449/; classtype:trojan-activity;sid:84329549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/advance_payment_request_letter_format_word.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466450/; classtype:trojan-activity;sid:84329550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466452)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0a0c7596-8583-4967-abed-67d8d1ffd610/downloads/boilermaker_drawings_and_developments.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466452/; classtype:trojan-activity;sid:84329552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8532eb1d-13c2-4756-9d41-225750b056f4/downloads/litimuwabu.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466453/; classtype:trojan-activity;sid:84329553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/telcordia_sr_332_issue_4.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466444/; classtype:trojan-activity;sid:84329544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466445)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d89879dd-a0f6-4cd8-8b66-99c2d6e48b2c/downloads/stopaq_application_manual_2018.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466445/; classtype:trojan-activity;sid:84329545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3daad7b2-98c5-4dc1-b37a-5570afcba267/downloads/40472163846.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466447/; classtype:trojan-activity;sid:84329547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/89247847196.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466439/; classtype:trojan-activity;sid:84329539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d258c0c8-b9d9-4d64-b965-01378617d9c6/downloads/72993487295.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466440/; classtype:trojan-activity;sid:84329540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/de9155fa-7173-4766-94c3-9e400d4aed58/downloads/def_stan_91-91.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466441/; classtype:trojan-activity;sid:84329541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/42d6a3b4-bbc0-47ab-bf86-c3ddb806b2ed/downloads/rafadaduveputev.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466443/; classtype:trojan-activity;sid:84329543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3924d65b-e08d-4f21-8d71-a0b15eb654bb/downloads/63720952596.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466429/; classtype:trojan-activity;sid:84329529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/woleb.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466417/; classtype:trojan-activity;sid:84329517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/dururotilonid.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466418/; classtype:trojan-activity;sid:84329518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/150_dialogues_en_francais.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466419/; classtype:trojan-activity;sid:84329519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/88031585580.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466420/; classtype:trojan-activity;sid:84329520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466423)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/dollar_general_cbl_answers_robbery_prevention.pdf"; depth:107; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466423/; classtype:trojan-activity;sid:84329523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466424)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4e8158-a082-4b1f-960e-1d82a946a72b/downloads/76239393989.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466424/; classtype:trojan-activity;sid:84329524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466414)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/51c1105d-a687-468d-b1aa-293ca9578a34/downloads/giwuroganapedokozijave.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466414/; classtype:trojan-activity;sid:84329514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/50e5aae7-a15c-4d74-a4ed-a8edfca980c4/downloads/atividades_adaptadas_de_ingles_para_deficientes_intelectuais.pdf"; depth:122; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466406/; classtype:trojan-activity;sid:84329506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/697088a1-6c9a-496e-9a4d-922308cd97be/downloads/24465842333.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466407/; classtype:trojan-activity;sid:84329507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466409)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2d664301-7b5e-474d-97a1-1305c7ece601/downloads/35905190672.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466409/; classtype:trojan-activity;sid:84329509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/12922543008.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466410/; classtype:trojan-activity;sid:84329510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/804274b4-5f10-4c26-9de6-df56f38aac7c/downloads/20643132370.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466412/; classtype:trojan-activity;sid:84329512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/95435099570.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466413/; classtype:trojan-activity;sid:84329513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466401)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2bb4e8cb-ec7e-44c1-a645-d94d4534f3a4/downloads/far_from_you_tess_sharpe.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466401/; classtype:trojan-activity;sid:84329501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/87076889980.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466403/; classtype:trojan-activity;sid:84329503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/40331451843.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466396/; classtype:trojan-activity;sid:84329496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/71d9f42f-0bad-4406-8a48-95c698e57e68/downloads/sumitomo_f50_compressor_manual.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466397/; classtype:trojan-activity;sid:84329497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/tusosexukitut.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466398/; classtype:trojan-activity;sid:84329498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/chambre_de_tirage_telecom.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466387/; classtype:trojan-activity;sid:84329487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d45c0d9d-8581-471d-bee0-51d1b9891f05/downloads/nisisot.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466389/; classtype:trojan-activity;sid:84329489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/tojabuka.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466390/; classtype:trojan-activity;sid:84329490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bb45e14d-29c5-4287-b67f-843105f3b091/downloads/16219919996.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466391/; classtype:trojan-activity;sid:84329491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/famous_athletes_banned_for_drug_use.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466392/; classtype:trojan-activity;sid:84329492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/31075581028.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466393/; classtype:trojan-activity;sid:84329493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/table_trigonometrique_complet.pdf"; depth:91; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466394/; classtype:trojan-activity;sid:84329494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f20719e2-319c-4f10-aabc-5dffb4a98912/downloads/45233279752.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466385/; classtype:trojan-activity;sid:84329485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/10e01255-b324-4a54-ae63-f4e28a319147/downloads/how_to_make_authorization_letter_to_claim_money_in_palawan.pdf"; depth:120; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466376/; classtype:trojan-activity;sid:84329476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7a69ed85-566a-4d22-8bd3-47a8a314b3bf/downloads/baropuzijavalerivotenujop.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466378/; classtype:trojan-activity;sid:84329478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466379)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/15135097712.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466379/; classtype:trojan-activity;sid:84329479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4831e354-44dc-4759-9d14-0dd6cfda589f/downloads/demag_ac_350_dwg.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466366/; classtype:trojan-activity;sid:84329466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466370)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f6479094-5bf7-4b46-9ced-d0f3d0d49751/downloads/63982701040.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466370/; classtype:trojan-activity;sid:84329470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e35dded4-68df-49bc-a9b0-aad8c63628c2/downloads/polipuzikiwelines.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466371/; classtype:trojan-activity;sid:84329471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/jakirezimukixinirivuvizuw.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466372/; classtype:trojan-activity;sid:84329472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c4bf44b4-a39c-49f8-89f5-4b487ef61751/downloads/safety_precautions_during_rainy_season_ppt.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466373/; classtype:trojan-activity;sid:84329473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/gasanon.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466358/; classtype:trojan-activity;sid:84329458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/87218120165.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466359/; classtype:trojan-activity;sid:84329459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6c9fdcec-b167-4620-b064-54b8917c32b8/downloads/57211354597.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466364/; classtype:trojan-activity;sid:84329464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9927c1c5-c61c-4f5e-807e-67bd1833b3e4/downloads/2687436544.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466355/; classtype:trojan-activity;sid:84329455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/astonishment_report_example_template_free.pdf"; depth:103; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466356/; classtype:trojan-activity;sid:84329456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4454ad30-3f6f-488a-b5e6-19e7bcca2146/downloads/duzinijilufixikedaluw.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466353/; classtype:trojan-activity;sid:84329453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/47a03532-4838-4d3f-b185-a29c87fa882c/downloads/24511080679.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466340/; classtype:trojan-activity;sid:84329440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/35512569741.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466341/; classtype:trojan-activity;sid:84329441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/fiselarodinolapin.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466344/; classtype:trojan-activity;sid:84329444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/fonuferin.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466348/; classtype:trojan-activity;sid:84329448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/59681288373.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466349/; classtype:trojan-activity;sid:84329449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9db526fb-d62a-447a-9766-8665158ad47a/downloads/skf_linear_bearing_catalogue.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466350/; classtype:trojan-activity;sid:84329450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/45838770375.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466351/; classtype:trojan-activity;sid:84329451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466336)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98a1791f-f3a9-4ef2-ac34-41b3393c3d1d/downloads/original_documents_handover_letter_format.pdf"; depth:103; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466336/; classtype:trojan-activity;sid:84329436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466337)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/60272662631.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466337/; classtype:trojan-activity;sid:84329437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aa44ab49-4d64-4d64-8bfd-2dfce545052f/downloads/limitations_act_2004_nigeria.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466338/; classtype:trojan-activity;sid:84329438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466331)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/72cc53f9-3bf4-447c-963a-353f48ad8500/downloads/puwutokok.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466331/; classtype:trojan-activity;sid:84329431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2224247e-29ce-4f8d-b838-abfcbdf269c0/downloads/emdr_cognitive_interweaves.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466333/; classtype:trojan-activity;sid:84329433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/15715958975.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466325/; classtype:trojan-activity;sid:84329425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466326)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/sanugesijeviwo.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466326/; classtype:trojan-activity;sid:84329426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466327)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/167862b3-31e9-4984-90e5-30766e3a7fa8/downloads/20740408467.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466327/; classtype:trojan-activity;sid:84329427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f36019eb-f077-446f-b5b6-39b8eacedf97/downloads/22914289512.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466316/; classtype:trojan-activity;sid:84329416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f842cd9f-c67c-4749-ba01-22d7c1ea502c/downloads/93070455772.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466317/; classtype:trojan-activity;sid:84329417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/61240910211.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466319/; classtype:trojan-activity;sid:84329419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/33251318472.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466320/; classtype:trojan-activity;sid:84329420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/800cff82-04ba-4c47-9f8b-d21367acb04d/downloads/84098559127.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466321/; classtype:trojan-activity;sid:84329421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kaxajopisojurivo.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466322/; classtype:trojan-activity;sid:84329422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/vehicle_sale_agreement_format_in_word_kerala_online_applicat.pdf"; depth:122; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466324/; classtype:trojan-activity;sid:84329424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/everstart_750_amp_jump_starter_manual.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466312/; classtype:trojan-activity;sid:84329412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/424b0398-579a-4717-a17a-ffb972bf5819/downloads/manual_ppap_4_edicao.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466313/; classtype:trojan-activity;sid:84329413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466314)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b2a026b5-555a-437c-867f-3969f62b48d7/downloads/3703775959.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466314/; classtype:trojan-activity;sid:84329414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466305)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3f5ecf8d-ba74-430f-ac11-9eb6ace92d02/downloads/womirojepu.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466305/; classtype:trojan-activity;sid:84329405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466307)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/lord_of_the_flies_script.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466307/; classtype:trojan-activity;sid:84329407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3d0a6e54-c95b-4e67-871e-882f39f9c203/downloads/38102271043.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466309/; classtype:trojan-activity;sid:84329409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466304)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/depo_provera_osteoporosis_guidelines.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466304/; classtype:trojan-activity;sid:84329404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/397fbc33-145f-44ec-a774-e1fa1b866d82/downloads/fekesijurada.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466301/; classtype:trojan-activity;sid:84329401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1e222df8-d197-4254-b90b-be3d3b023ef4/downloads/78299826683.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466293/; classtype:trojan-activity;sid:84329393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466294)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bc2da57a-5cad-4b1e-b658-8efa7e30bee5/downloads/como_transferir_saldo_de_dados_unitel.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466294/; classtype:trojan-activity;sid:84329394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/billetes_didacticos_mexicanos_para_imprimir.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466283/; classtype:trojan-activity;sid:84329383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466284)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/xutodorimalibavexididoson.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466284/; classtype:trojan-activity;sid:84329384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/vatalikuxigepiwu.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466285/; classtype:trojan-activity;sid:84329385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466286)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2fda8269-9b7e-4008-b093-ed7dc0bde9d7/downloads/zinivegosejuriwevagowu.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466286/; classtype:trojan-activity;sid:84329386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466288)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/dotuxomolomorapitome.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466288/; classtype:trojan-activity;sid:84329388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466289)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/541a1d8b-7a21-4c1f-8013-03406bd1a8ad/downloads/mevuxurike.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466289/; classtype:trojan-activity;sid:84329389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9c30937d-c8da-4e7b-9f7a-432344b46400/downloads/jubomumifekomu.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466291/; classtype:trojan-activity;sid:84329391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aa25c895-a966-4265-aeb1-bc094284554e/downloads/jifig.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466279/; classtype:trojan-activity;sid:84329379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/90378982159.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466280/; classtype:trojan-activity;sid:84329380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/jodegemotekuseve.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466282/; classtype:trojan-activity;sid:84329382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466268)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/46578941429.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466268/; classtype:trojan-activity;sid:84329368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466269)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/elenco_corsi_vam_viterbo.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466269/; classtype:trojan-activity;sid:84329369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/17714436684.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466259/; classtype:trojan-activity;sid:84329359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466260)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/planet_fitness_membership_cancellation_letter.pdf"; depth:107; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466260/; classtype:trojan-activity;sid:84329360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466261)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/af067739-2dfe-40f3-ae00-a758e587d7d3/downloads/61105974714.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466261/; classtype:trojan-activity;sid:84329361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466266)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/933c3405-1572-4648-b39e-d98567eb5bee/downloads/for_your_kind_perusal_and_necessary_action_meaning.pdf"; depth:112; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466266/; classtype:trojan-activity;sid:84329366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/119d5b03-e78f-4725-87b7-ed496b267f6d/downloads/scrubber_design_calculation_excel.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466267/; classtype:trojan-activity;sid:84329367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6787db73-833d-4393-867e-1b786eb5e101/downloads/60859753638.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466249/; classtype:trojan-activity;sid:84329349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466252)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/62a7895e-5f81-4049-920b-e70e38d29e37/downloads/why_is_annexure_d_required_for_minor_passport.pdf"; depth:107; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466252/; classtype:trojan-activity;sid:84329352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466253)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/574284889.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466253/; classtype:trojan-activity;sid:84329353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466254)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9e5b6b40-f934-4273-a65f-cbaee9aa4b00/downloads/xikapataxofako.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466254/; classtype:trojan-activity;sid:84329354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466255)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/lobigexapi.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466255/; classtype:trojan-activity;sid:84329355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466256)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2470d53e-fef7-4646-9c8b-919894e66d18/downloads/72646482584.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466256/; classtype:trojan-activity;sid:84329356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8c16f145-4fc0-4af7-a4db-de4acd818fe4/downloads/46429707192.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466257/; classtype:trojan-activity;sid:84329357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7153ec40-cd7f-411a-a08b-66d173a33455/downloads/standards_australia_handbook_197.pdf"; depth:94; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466245/; classtype:trojan-activity;sid:84329345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/55745505506.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466247/; classtype:trojan-activity;sid:84329347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/43311556781.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466241/; classtype:trojan-activity;sid:84329341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/80691091889.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466244/; classtype:trojan-activity;sid:84329344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/sewuxazomuwara.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466238/; classtype:trojan-activity;sid:84329338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ce549e8-3051-428a-a71b-b48f204ac3cd/downloads/rapid_router_level_43_solution.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466231/; classtype:trojan-activity;sid:84329331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0620bed2-a9d8-4f06-ab8c-173ea1a60a70/downloads/jijegarazomimubusawogam.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466232/; classtype:trojan-activity;sid:84329332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/matunekuv.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466233/; classtype:trojan-activity;sid:84329333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/53202951-38c7-4c35-8280-6cefaf47915f/downloads/statsafe_3000_msds.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466230/; classtype:trojan-activity;sid:84329330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/82647770508.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466221/; classtype:trojan-activity;sid:84329321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ee3e2894-0337-41f6-9371-caecf7034a22/downloads/26991821255.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466222/; classtype:trojan-activity;sid:84329322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466226)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/gesuzodekutiz.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466226/; classtype:trojan-activity;sid:84329326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466227)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/62a7895e-5f81-4049-920b-e70e38d29e37/downloads/how_to_register_in_upstox.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466227/; classtype:trojan-activity;sid:84329327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/exercises_for_trigger_thumb.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466228/; classtype:trojan-activity;sid:84329328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/132d13c5-3f89-41bf-85b4-d1a24ddcf61c/downloads/nosiwevixina.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466229/; classtype:trojan-activity;sid:84329329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a56a106f-21b9-46c2-b5bc-12461919334c/downloads/vurarufa.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466215/; classtype:trojan-activity;sid:84329315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/how_to_get_a_wire_transfer_receipt_chase.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466217/; classtype:trojan-activity;sid:84329317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/3175972790.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466219/; classtype:trojan-activity;sid:84329319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/62128af0-82d0-4bae-b967-d393a4304003/downloads/apex_sl_vibration_controller_manual.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466213/; classtype:trojan-activity;sid:84329313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466214)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/nakozixuwelafi.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466214/; classtype:trojan-activity;sid:84329314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/mobesapovasag.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466205/; classtype:trojan-activity;sid:84329305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466206)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fae029f6-27b1-4578-94bc-ae0bbaeebde4/downloads/imperial_vernier_caliper_worksheet.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466206/; classtype:trojan-activity;sid:84329306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e2ab423c-1813-4cd0-becb-6a8adbf01641/downloads/ribafimimeriledok.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466207/; classtype:trojan-activity;sid:84329307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/62228929609.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466208/; classtype:trojan-activity;sid:84329308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/91a706e9-d066-47d7-89af-69535d865c3d/downloads/carteirinha_de_estudante_falsa_em.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466209/; classtype:trojan-activity;sid:84329309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/80e9e7c7-d97b-4b5a-96c4-9a83854a3065/downloads/35740879646.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466196/; classtype:trojan-activity;sid:84329296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f2d42ffe-779b-4107-ac42-7f36375aab37/downloads/zeneliginuboripiriza.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466201/; classtype:trojan-activity;sid:84329301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6bb5c8cf-e89d-49c0-aeeb-7278d39f6b32/downloads/fiche_grcf_bts_gpme.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466202/; classtype:trojan-activity;sid:84329302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/77724997403.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466193/; classtype:trojan-activity;sid:84329293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/xinunivigaxelifujukedo.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466181/; classtype:trojan-activity;sid:84329281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/pidipaxiworoguvosifap.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466182/; classtype:trojan-activity;sid:84329282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/rent_receipt_format_in_ms_word.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466183/; classtype:trojan-activity;sid:84329283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/nipipuk.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466184/; classtype:trojan-activity;sid:84329284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/081e0348-3bf0-4a3e-a723-749adc1aa630/downloads/67271829455.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466185/; classtype:trojan-activity;sid:84329285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c0325f5e-ab4f-48af-8631-8757a310624e/downloads/57390845107.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466186/; classtype:trojan-activity;sid:84329286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/45659404876.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466187/; classtype:trojan-activity;sid:84329287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/80200009732.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466189/; classtype:trojan-activity;sid:84329289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3a657e0c-a872-4028-94b8-811aea249c49/downloads/shl_general_ability_test_answers_reddit.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466190/; classtype:trojan-activity;sid:84329290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06823f9b-45c4-43cb-a44f-1f9f645cebcf/downloads/32406777299.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466175/; classtype:trojan-activity;sid:84329275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/7694747911.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466177/; classtype:trojan-activity;sid:84329277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/danokubiwen.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466178/; classtype:trojan-activity;sid:84329278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/62128af0-82d0-4bae-b967-d393a4304003/downloads/xibuvajuxaluvotom.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466179/; classtype:trojan-activity;sid:84329279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466180)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0a0c7596-8583-4967-abed-67d8d1ffd610/downloads/8393439781.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466180/; classtype:trojan-activity;sid:84329280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/redoripedigi.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466170/; classtype:trojan-activity;sid:84329270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/how_to_cancel_print_job_on_zebra_gk420d.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466172/; classtype:trojan-activity;sid:84329272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b83dcfc0-bbe6-4498-b356-e365ec2ed396/downloads/zofafiba.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466169/; classtype:trojan-activity;sid:84329269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a37e9011-77af-43eb-9e7b-dd6853450512/downloads/les_jours_de_la_semaine_exercices.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466161/; classtype:trojan-activity;sid:84329261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/90213521835.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466162/; classtype:trojan-activity;sid:84329262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/28725733968.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466154/; classtype:trojan-activity;sid:84329254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7aa15cc-b2d1-4fef-8a47-8d7810090a9c/downloads/jenuwegipujodunoj.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466149/; classtype:trojan-activity;sid:84329249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466151)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/dowuvibatekijutajuvavu.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466151/; classtype:trojan-activity;sid:84329251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466152)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/14196656823.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466152/; classtype:trojan-activity;sid:84329252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466153)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/44a9091e-2134-47ec-8037-250483142ad3/downloads/kenmore_elite_665.12783_k311_service_manual.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466153/; classtype:trojan-activity;sid:84329253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bd6582d9-c54a-4b0b-ad89-3fd92efb45aa/downloads/50362295282.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466144/; classtype:trojan-activity;sid:84329244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/navy_uic_code_list.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466145/; classtype:trojan-activity;sid:84329245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9f2acd38-413e-47a5-ac42-d6305581bfab/downloads/logerafanekox.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466147/; classtype:trojan-activity;sid:84329247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/zakojamoderuvovu.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466140/; classtype:trojan-activity;sid:84329240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b2a026b5-555a-437c-867f-3969f62b48d7/downloads/successfactors_recruiting_implementation_guide.pdf"; depth:108; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466133/; classtype:trojan-activity;sid:84329233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/97474238027.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466134/; classtype:trojan-activity;sid:84329234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ddcbbbab-f8a6-4067-a450-a2f971a66e79/downloads/daikin_ac_remote_control_guide.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466135/; classtype:trojan-activity;sid:84329235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/lebuk.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466138/; classtype:trojan-activity;sid:84329238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/71642361311.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466139/; classtype:trojan-activity;sid:84329239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466128)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kumujadirifokekikivexe.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466128/; classtype:trojan-activity;sid:84329228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/2818265442.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466130/; classtype:trojan-activity;sid:84329230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e262bb3c-3205-4bb6-954b-f565479d59e0/downloads/examenes_psicometricos_pruebas_psicometricas_gratis_para_imp.pdf"; depth:122; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466132/; classtype:trojan-activity;sid:84329232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466122)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4252a31f-7a57-4ac8-a31e-ee71b2361194/downloads/61162239689.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466122/; classtype:trojan-activity;sid:84329222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/43b3ecff-25d4-4371-99a8-6df485cf4fd5/downloads/amoeba_sisters_classification_worksheet.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466125/; classtype:trojan-activity;sid:84329225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/fundamentals_of_power_supply_design_book.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466115/; classtype:trojan-activity;sid:84329215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/her_yonuyle_modern_almanca_dursun_zengin.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466116/; classtype:trojan-activity;sid:84329216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/15938565950.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466117/; classtype:trojan-activity;sid:84329217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d5271715-d4c2-447f-bd8c-804dbc17722c/downloads/experience_certificate_format_for_quality_control_engineer.pdf"; depth:120; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466107/; classtype:trojan-activity;sid:84329207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1b7f80b5-fb34-497d-8072-447feb44da09/downloads/lewamagoromizesa.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466109/; classtype:trojan-activity;sid:84329209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466110)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/courier_declaration_format.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466110/; classtype:trojan-activity;sid:84329210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466104)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/ruripumefenezalizaf.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466104/; classtype:trojan-activity;sid:84329204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/32a18e69-8d9d-488c-b50f-45023ca24343/downloads/87353354077.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466101/; classtype:trojan-activity;sid:84329201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/20305303180.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466092/; classtype:trojan-activity;sid:84329192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466099)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/kutapodisub.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466099/; classtype:trojan-activity;sid:84329199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0919b7e4-2541-44dd-b945-9d5e6d22eaf1/downloads/xibegakibojonabawaz.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466100/; classtype:trojan-activity;sid:84329200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/doxuwiponubagexotabos.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466083/; classtype:trojan-activity;sid:84329183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/54308720858.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466084/; classtype:trojan-activity;sid:84329184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/gomanelakog.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466085/; classtype:trojan-activity;sid:84329185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/nx_nastran_element_library_reference_manual.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466089/; classtype:trojan-activity;sid:84329189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/collibra_expert_i_certification_answers_sheet_download_2017.pdf"; depth:121; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466074/; classtype:trojan-activity;sid:84329174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4ec11559-69c0-4903-84a6-3240babfcfe7/downloads/lapagikevipewijumodoru.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466075/; classtype:trojan-activity;sid:84329175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1bfc168f-d0df-43cb-a73e-d0c80e42fe5c/downloads/formulaire_virement_international_banque_postale.pdf"; depth:110; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466076/; classtype:trojan-activity;sid:84329176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/96273346643.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466078/; classtype:trojan-activity;sid:84329178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1feaf4a2-3a85-48bd-b975-ab8d5bcee640/downloads/30816276176.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466079/; classtype:trojan-activity;sid:84329179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d8f5bd9b-2c75-4c1f-8d4d-84a7de1d3443/downloads/rent_brokerage_receipt_format_word.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466070/; classtype:trojan-activity;sid:84329170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8439ca10-a5ac-4299-aa09-54ab615a2090/downloads/bozagororaxurivir.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466071/; classtype:trojan-activity;sid:84329171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/54016191818.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466072/; classtype:trojan-activity;sid:84329172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f0d27cad-ce96-47a4-a6b6-d00149677212/downloads/87562723190.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466073/; classtype:trojan-activity;sid:84329173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/swot_analysis_for_poultry_farming.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466066/; classtype:trojan-activity;sid:84329166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/bosokoxa.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466067/; classtype:trojan-activity;sid:84329167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/69034861186.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466063/; classtype:trojan-activity;sid:84329163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466065)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/14962502915.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466065/; classtype:trojan-activity;sid:84329165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/42589334771.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466060/; classtype:trojan-activity;sid:84329160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/banksman_hand_signals.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466054/; classtype:trojan-activity;sid:84329154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6cdacb6d-7fbf-4d09-a986-56cdfa4edeb2/downloads/5985868832.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466055/; classtype:trojan-activity;sid:84329155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d258c0c8-b9d9-4d64-b965-01378617d9c6/downloads/voter_list_delhi_2018.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466056/; classtype:trojan-activity;sid:84329156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/99737319160.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466058/; classtype:trojan-activity;sid:84329158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1bfc168f-d0df-43cb-a73e-d0c80e42fe5c/downloads/71653623394.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466045/; classtype:trojan-activity;sid:84329145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/testing_and_commissioning_of_electrical_equipment.pdf"; depth:111; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466047/; classtype:trojan-activity;sid:84329147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/1ffc09a0-c9a4-4762-8145-43798f2fda71/downloads/back_to_work_from_maternity_leave_email.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466048/; classtype:trojan-activity;sid:84329148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/xepaxijaniwitofoxipoja.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466049/; classtype:trojan-activity;sid:84329149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/de43da9e-bc77-4e56-a909-0e72ba746cf9/downloads/electricity_bill_name_change_noc_format.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466051/; classtype:trojan-activity;sid:84329151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2ad58263-1b5c-4da7-bc4a-7b8f99e22218/downloads/formulaire_ordre_de_virement_banque_postale.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466052/; classtype:trojan-activity;sid:84329152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/76135669664.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466053/; classtype:trojan-activity;sid:84329153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/23ec0b56-0ae7-4e41-8565-08e517b0b386/downloads/gatamalepuberik.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466039/; classtype:trojan-activity;sid:84329139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466040)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/97106569323.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466040/; classtype:trojan-activity;sid:84329140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466041)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3e3d230e-4918-4f4b-8a10-8ee933aabcaf/downloads/99772344048.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466041/; classtype:trojan-activity;sid:84329141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/wapurexep.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466037/; classtype:trojan-activity;sid:84329137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/19668bf7-0111-4cbb-8050-06562ac08bba/downloads/steps_to_create_template_instance_in_tosca.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466032/; classtype:trojan-activity;sid:84329132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/bidoxefemoduxunirez.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466033/; classtype:trojan-activity;sid:84329133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/88817028453.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466034/; classtype:trojan-activity;sid:84329134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/job_work_challan_format_in_excel.pdf"; depth:94; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466027/; classtype:trojan-activity;sid:84329127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466028)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/34794329-fa5b-49f8-8f60-fb0720b1e556/downloads/14476765670.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466028/; classtype:trojan-activity;sid:84329128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/resignation_letter_template_family_reasons.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466015/; classtype:trojan-activity;sid:84329115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8c16f145-4fc0-4af7-a4db-de4acd818fe4/downloads/14431999044.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466016/; classtype:trojan-activity;sid:84329116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/21303726077.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466017/; classtype:trojan-activity;sid:84329117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/minupawuferogu.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466018/; classtype:trojan-activity;sid:84329118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b071d266-376f-40c9-bb70-11ca77d8051b/downloads/36008974689.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466020/; classtype:trojan-activity;sid:84329120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466021)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/60919645191.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466021/; classtype:trojan-activity;sid:84329121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/424b0398-579a-4717-a17a-ffb972bf5819/downloads/audit_professional_clearance_letter_template.pdf"; depth:106; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466022/; classtype:trojan-activity;sid:84329122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466023)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/30072850819.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466023/; classtype:trojan-activity;sid:84329123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/75213021290.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466024/; classtype:trojan-activity;sid:84329124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/law-making_process_in_zimbabwe.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466025/; classtype:trojan-activity;sid:84329125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/363b8b8c-bdd6-4ad7-ac6c-ba65cd60171b/downloads/abaqus_user_subroutine_reference_guide.pdf"; depth:100; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466011/; classtype:trojan-activity;sid:84329111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/85845004614.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466014/; classtype:trojan-activity;sid:84329114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466005)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/genuwafazapibiwinowafal.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466005/; classtype:trojan-activity;sid:84329105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/20322886839.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466006/; classtype:trojan-activity;sid:84329106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/gagibipawuzepakan.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466008/; classtype:trojan-activity;sid:84329108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/sample_authorization_letter_to_get_psa_marriage_certificate.pdf"; depth:121; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466002/; classtype:trojan-activity;sid:84329102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/8517821794.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465993/; classtype:trojan-activity;sid:84329093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/padanad.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465994/; classtype:trojan-activity;sid:84329094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465995)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9971747c-d991-46ae-b932-5ba73958e604/downloads/fojajexuretimototatoles.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465995/; classtype:trojan-activity;sid:84329095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/mosodekasaxozebopajebibe.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465996/; classtype:trojan-activity;sid:84329096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6be9a470-c465-4776-ab76-53713c51537a/downloads/30164245456.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465997/; classtype:trojan-activity;sid:84329097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f264223f-22e7-47f1-947d-9e365a75e217/downloads/96358679127.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465999/; classtype:trojan-activity;sid:84329099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f65856df-6ee2-426f-901a-fbcb5106e767/downloads/22057173676.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466000/; classtype:trojan-activity;sid:84329100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465984)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/butterfly_roof_construction_detail.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465984/; classtype:trojan-activity;sid:84329084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/baxejatoxenidomixidedax.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465985/; classtype:trojan-activity;sid:84329085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/17465496427.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465986/; classtype:trojan-activity;sid:84329086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465989)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/zabefenakozevopesomewazi.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465989/; classtype:trojan-activity;sid:84329089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/48283c5b-b198-4860-9bf9-7f30a2f8146b/downloads/zoromipubadijivonexon.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465990/; classtype:trojan-activity;sid:84329090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8df58291-e0db-425a-9cda-a9882386ada6/downloads/jaladimurefasetuzukiwaxit.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465991/; classtype:trojan-activity;sid:84329091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/wofalobomosotanavuze.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465992/; classtype:trojan-activity;sid:84329092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465980)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0d21a9d5-01df-4a9e-9327-883996b2f71d/downloads/ansi_electrical_symbols_standards.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465980/; classtype:trojan-activity;sid:84329080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a435afa7-bc93-481f-8a35-ce503cc8a972/downloads/sri_rudram_namakam_chamakam_tamil.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465974/; classtype:trojan-activity;sid:84329074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/tumiwujuluxuwaxi.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465975/; classtype:trojan-activity;sid:84329075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/denutetoraditut.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465977/; classtype:trojan-activity;sid:84329077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9569c183-65dc-4f14-a45e-e7944584cb65/downloads/bifidetogatovotuwideki.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465961/; classtype:trojan-activity;sid:84329061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465962)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/baroque_guitar_tab.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465962/; classtype:trojan-activity;sid:84329062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7f34267e-2563-449a-82e3-60f19988c45d/downloads/lic_jeevan_saral_plan_165_chart.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465963/; classtype:trojan-activity;sid:84329063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f36019eb-f077-446f-b5b6-39b8eacedf97/downloads/69187265192.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465965/; classtype:trojan-activity;sid:84329065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d551812a-3c47-48f1-bc1d-3ac42c3f246c/downloads/rigumudusogepivana.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465968/; classtype:trojan-activity;sid:84329068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/5528845131.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465969/; classtype:trojan-activity;sid:84329069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/74129229699.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465971/; classtype:trojan-activity;sid:84329071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/cancionero_catolico_jesed.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465972/; classtype:trojan-activity;sid:84329072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7a3b63b5-3e6a-48ac-8e49-14ed0037cbc4/downloads/historietas_del_medio_ambiente_largas.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465957/; classtype:trojan-activity;sid:84329057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/62049175170.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465955/; classtype:trojan-activity;sid:84329055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/10908647555.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465949/; classtype:trojan-activity;sid:84329049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465951)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/maxabamuxixotabevifutiw.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465951/; classtype:trojan-activity;sid:84329051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/downgrade_oracle_database_from_19c_to_11g.pdf"; depth:103; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465953/; classtype:trojan-activity;sid:84329053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ba9b549d-a804-4d13-a818-3c55b3524acd/downloads/75189909272.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465942/; classtype:trojan-activity;sid:84329042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465945)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/individual_development_plan_powerpoint_template.pdf"; depth:109; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465945/; classtype:trojan-activity;sid:84329045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465946)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/64954946228.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465946/; classtype:trojan-activity;sid:84329046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/bapozujipo.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465939/; classtype:trojan-activity;sid:84329039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4872c6d8-aa46-4e32-b809-43d741337793/downloads/74841624584.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465931/; classtype:trojan-activity;sid:84329031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3a90d4c9-f215-49ec-8178-8e50febf5250/downloads/tedutogonisijetinikiw.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465932/; classtype:trojan-activity;sid:84329032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/wipofuta.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465933/; classtype:trojan-activity;sid:84329033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4cb1e8a7-0f1a-4c3a-ae4d-65ac09f78b80/downloads/fenekipejivatoxeni.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465935/; classtype:trojan-activity;sid:84329035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/wolarodipuxusisug.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465937/; classtype:trojan-activity;sid:84329037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465938)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c3be0091-4534-4191-a72e-570acc745d3e/downloads/attestation_de_prise_en_charge_tlscontact.pdf"; depth:103; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465938/; classtype:trojan-activity;sid:84329038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fa4295b9-8c98-4187-bbf8-91c9d7ce5f9e/downloads/89606848887.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465924/; classtype:trojan-activity;sid:84329024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465926)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/44d0963d-ba71-4620-abdb-e3c6631b392b/downloads/balance_confirmation_letter_format_in_word.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465926/; classtype:trojan-activity;sid:84329026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/rollo_tomassi_the_rational_male_turkce.pdf"; depth:100; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465912/; classtype:trojan-activity;sid:84329012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465914)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/800bda9c-ed1b-45a1-a7d5-702e4e14f980/downloads/pmp_42_processes_chart.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465914/; classtype:trojan-activity;sid:84329014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465915)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/86917927693.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465915/; classtype:trojan-activity;sid:84329015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465916)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/methodologie_du_commentaire_compose_francais.pdf"; depth:106; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465916/; classtype:trojan-activity;sid:84329016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/gauss_elimination_method_example_with_solution.pdf"; depth:108; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465919/; classtype:trojan-activity;sid:84329019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5f03ee03-a319-4a1e-a052-a99710c59365/downloads/bujulodipesotixugakujup.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465910/; classtype:trojan-activity;sid:84329010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/hsbc_bank_statement.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465906/; classtype:trojan-activity;sid:84329006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/94e1955e-c7d2-4e11-a6ac-7a5ec652d6cd/downloads/suzuki_dt4_owners_manual.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465909/; classtype:trojan-activity;sid:84329009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8f5eeb54-04ec-4a30-bb55-41e413d1f3ed/downloads/open_pit_mine_planning_and_design.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465903/; classtype:trojan-activity;sid:84329003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465904)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ceb9a026-f6c4-4e26-a968-d8e0e8d06aaa/downloads/tevedowopalugafaxoro.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465904/; classtype:trojan-activity;sid:84329004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/adb32098-1c7a-4519-9e53-ced990fc5d88/downloads/kuniwuzujujurejovewo.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465905/; classtype:trojan-activity;sid:84329005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/76236294804.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465896/; classtype:trojan-activity;sid:84328996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6ab86f22-a419-4e4f-91d4-5a654823f744/downloads/pamolitix.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465897/; classtype:trojan-activity;sid:84328997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/697088a1-6c9a-496e-9a4d-922308cd97be/downloads/42508658220.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465898/; classtype:trojan-activity;sid:84328998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/sotax_at_xtend_user_manual.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465885/; classtype:trojan-activity;sid:84328985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5d8bfe2e-b91e-431f-9bdc-3f0ea97e388e/downloads/wovivesapo.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465886/; classtype:trojan-activity;sid:84328986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/sample_consent_letter_from_husband_for_wife_to_travel.pdf"; depth:115; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465888/; classtype:trojan-activity;sid:84328988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/formulaire_renouvellement_titre_de_sejour_yvelines.pdf"; depth:112; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465889/; classtype:trojan-activity;sid:84328989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/71d9f42f-0bad-4406-8a48-95c698e57e68/downloads/98599689697.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465891/; classtype:trojan-activity;sid:84328991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/92007305293.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465892/; classtype:trojan-activity;sid:84328992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d07e2353-3643-42fe-ba11-ffa772b1a28d/downloads/duff_phelps_size_premium.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465893/; classtype:trojan-activity;sid:84328993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9213334f-b8c6-41b2-903d-dc8cc5791a0a/downloads/49429599069.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465881/; classtype:trojan-activity;sid:84328981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/22187922858.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465882/; classtype:trojan-activity;sid:84328982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d5e97205-d745-471d-94c2-4bc94f943a29/downloads/nafexasu.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465876/; classtype:trojan-activity;sid:84328976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/99401481523.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465878/; classtype:trojan-activity;sid:84328978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/harry_potter_ea_camara_secreta_ilustrado.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465879/; classtype:trojan-activity;sid:84328979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465870)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/800cff82-04ba-4c47-9f8b-d21367acb04d/downloads/all_gujarati_magazine.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465870/; classtype:trojan-activity;sid:84328970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465871)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/34103705134.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465871/; classtype:trojan-activity;sid:84328971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9a32841c-0d54-4ad0-8acd-a5b15c41cae1/downloads/nagpur_metro_phase_2_dpr.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465872/; classtype:trojan-activity;sid:84328972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/99406712648.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465873/; classtype:trojan-activity;sid:84328973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/96d7062c-715f-4c9e-82c2-ac322bf04d1a/downloads/fawafep.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465874/; classtype:trojan-activity;sid:84328974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/51e053ea-8122-46e3-bee6-6c00a935619c/downloads/28185631859.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465875/; classtype:trojan-activity;sid:84328975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/renamotoxuxesike.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465865/; classtype:trojan-activity;sid:84328965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/wixutazavadupiruzani.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465866/; classtype:trojan-activity;sid:84328966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/vixodamev.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465864/; classtype:trojan-activity;sid:84328964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pulse_secure_network_error_1329.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465852/; classtype:trojan-activity;sid:84328952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465853)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8fc62093-f93e-447d-8e21-b1e235f4d9cc/downloads/cibse_psychrometric_chart.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465853/; classtype:trojan-activity;sid:84328953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/citrix_adc_vpx_datasheet.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465857/; classtype:trojan-activity;sid:84328957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cac64821-2205-4248-abd9-55e775312c94/downloads/rosigamosusen.pdf"; depth:75; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465847/; classtype:trojan-activity;sid:84328947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465848)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/fosofiboma.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465848/; classtype:trojan-activity;sid:84328948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/600b6853-9b14-40c4-b9d1-c0a10f9ad1eb/downloads/mathematics_core_topics_sl.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465850/; classtype:trojan-activity;sid:84328950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/6e0acf5f-e652-447e-8a3a-90dcb81c48ee/downloads/loan_cancellation_letter.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465843/; classtype:trojan-activity;sid:84328943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98fd26ea-5c50-4ebf-945e-7ed158ebe1b6/downloads/workplace_printable_hurt_feelings_report.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465844/; classtype:trojan-activity;sid:84328944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465845)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/zalekebi.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465845/; classtype:trojan-activity;sid:84328945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/58616986475.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465833/; classtype:trojan-activity;sid:84328933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465835)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/one_of_us_is_lying_character_quotes.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465835/; classtype:trojan-activity;sid:84328935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465839)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0e65d320-97ed-47cb-9ca0-bcd7400824c9/downloads/jewuzikilodejosowar.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465839/; classtype:trojan-activity;sid:84328939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/72fc6eb8-20de-4439-bced-6bfc7eecaa8e/downloads/bogev.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465825/; classtype:trojan-activity;sid:84328925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/58b13a51-176b-4b7e-ab1e-a0c84e7a5487/downloads/currency_market_mechanics_bmc_answers.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465826/; classtype:trojan-activity;sid:84328926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/018aefd4-3541-4598-a5c3-d0911ca60a82/downloads/asce_7-05_espanol_gratis.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465827/; classtype:trojan-activity;sid:84328927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/tifunakarexefeguwitoda.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465828/; classtype:trojan-activity;sid:84328928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/06a2cc2e-f4bb-4ca4-a0d9-71e2fc8b7812/downloads/molaxoxekex.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465829/; classtype:trojan-activity;sid:84328929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/iata_airport_handling_manual_2019_full.pdf"; depth:100; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465830/; classtype:trojan-activity;sid:84328930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c1bf3ae2-f6cc-4078-b639-2ff1ca0b62be/downloads/1172286111.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465831/; classtype:trojan-activity;sid:84328931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465832)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/euchre_score_sheets_for_16_players.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465832/; classtype:trojan-activity;sid:84328932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/dungeon_crawl_classics.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465820/; classtype:trojan-activity;sid:84328920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465804)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bb45e14d-29c5-4287-b67f-843105f3b091/downloads/69904656893.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465804/; classtype:trojan-activity;sid:84328904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/emmaus_walk_letters_of_encouragement.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465806/; classtype:trojan-activity;sid:84328906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fc635392-61de-40bc-86f0-c9844fcf30fd/downloads/gramatica_portugues_brasil.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465809/; classtype:trojan-activity;sid:84328909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/647bfca3-c5f6-48a0-9ec3-35afde17c6e3/downloads/gamokul.pdf"; depth:69; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465814/; classtype:trojan-activity;sid:84328914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fa284320-69aa-45db-92e2-86468d4beaf0/downloads/53174458267.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465815/; classtype:trojan-activity;sid:84328915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/72502959-bd3f-431c-9582-055fb0eb9e9d/downloads/nike_employee_benefits.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465795/; classtype:trojan-activity;sid:84328895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/97767745983.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465798/; classtype:trojan-activity;sid:84328898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/country_of_origin_letter_template.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465799/; classtype:trojan-activity;sid:84328899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/39834772333.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465802/; classtype:trojan-activity;sid:84328902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/rofaruzev.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465790/; classtype:trojan-activity;sid:84328890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/verismo_701_service_manual.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465791/; classtype:trojan-activity;sid:84328891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/rodudiniruzawame.pdf"; depth:78; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465792/; classtype:trojan-activity;sid:84328892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3c8f7a45-f68c-4369-8f63-be6429599400/downloads/butulanimirovubeve.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465785/; classtype:trojan-activity;sid:84328885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c725aa89-ce3b-4b0b-861e-e7c40702153d/downloads/gisewonivikamadoliwozuv.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465786/; classtype:trojan-activity;sid:84328886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d1335ae9-6401-4997-a89d-ffce5d766eb7/downloads/44332900662.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465787/; classtype:trojan-activity;sid:84328887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b6f72d87-e560-495a-a5bd-684e976b53e4/downloads/nagano_keiki_km10.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465779/; classtype:trojan-activity;sid:84328879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/76488986948.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465781/; classtype:trojan-activity;sid:84328881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465782)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ac62f849-5623-435a-93ad-86e4d8edc83e/downloads/90625111849.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465782/; classtype:trojan-activity;sid:84328882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/72445144906.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465772/; classtype:trojan-activity;sid:84328872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0e65d320-97ed-47cb-9ca0-bcd7400824c9/downloads/wrightbus_streetlite_manual.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465773/; classtype:trojan-activity;sid:84328873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/waste_management_in_dubai.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465776/; classtype:trojan-activity;sid:84328876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/chevening_scholarship_reference_letter_sample.pdf"; depth:107; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465777/; classtype:trojan-activity;sid:84328877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/14409296375.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465778/; classtype:trojan-activity;sid:84328878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d128fcda-7fcc-4d89-85b3-e79c54d4414e/downloads/unit_conversion_practice_problems.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465766/; classtype:trojan-activity;sid:84328866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/11197801286.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465768/; classtype:trojan-activity;sid:84328868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/50ab7773-f1d2-4be6-a8e2-1065b2477787/downloads/41229957036.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465769/; classtype:trojan-activity;sid:84328869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/950f7924-fa6b-44be-bda3-22eaf526f43f/downloads/konujidav.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465771/; classtype:trojan-activity;sid:84328871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/burijuterapudupelirebi.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465760/; classtype:trojan-activity;sid:84328860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a85f54ee-11f7-4ab3-9970-dabd8f52d583/downloads/vowivovabafases.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465761/; classtype:trojan-activity;sid:84328861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465762)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/acb19439-02ad-48ae-a6e4-8c3bfce04694/downloads/32470708569.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465762/; classtype:trojan-activity;sid:84328862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/xikesoxabafubuwepof.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465763/; classtype:trojan-activity;sid:84328863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/2251478862.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465764/; classtype:trojan-activity;sid:84328864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9d0d7648-4006-4e9a-bf4e-cd4f5c534844/downloads/socomec_ups_service_manual.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465765/; classtype:trojan-activity;sid:84328865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/6098867423.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465757/; classtype:trojan-activity;sid:84328857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2b383d2d-2b5a-4b4f-949f-124c21f71183/downloads/how_to_write_an_introduction_letter_to_an_embassy.pdf"; depth:111; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465758/; classtype:trojan-activity;sid:84328858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/41780010-2245-4f59-96ea-abe2bb04704f/downloads/38265042738.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465755/; classtype:trojan-activity;sid:84328855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/183feb73-c001-4172-a9c4-8aedcbb9c085/downloads/nosasasoxanuxoxazefuz.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465747/; classtype:trojan-activity;sid:84328847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/gibekewelodi.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465749/; classtype:trojan-activity;sid:84328849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465752)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/16395777837.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465752/; classtype:trojan-activity;sid:84328852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/jspdf_autotable_x_position.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465753/; classtype:trojan-activity;sid:84328853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a0b0ee5f-47ab-407d-8f2e-b86a71eb1b80/downloads/cerere_demisie_fara_preaviz.pdf"; depth:89; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465739/; classtype:trojan-activity;sid:84328839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/0fde6049-38a2-402e-8604-5a56fc977486/downloads/request_letter_for_construction_bond_refund.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465740/; classtype:trojan-activity;sid:84328840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cdd5ea6e-1f6b-4417-9fad-928f6d1c8a68/downloads/50_verbes_irreguliers_en_anglais.pdf"; depth:94; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465741/; classtype:trojan-activity;sid:84328841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7a69ed85-566a-4d22-8bd3-47a8a314b3bf/downloads/molecular_mass_of_elements_list.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465742/; classtype:trojan-activity;sid:84328842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465744)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/69278806631.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465744/; classtype:trojan-activity;sid:84328844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/nonisenokedevesuxumuk.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465735/; classtype:trojan-activity;sid:84328835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/mesoduwegotujowokikurixo.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465729/; classtype:trojan-activity;sid:84328829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2b383d2d-2b5a-4b4f-949f-124c21f71183/downloads/how_to_fill_up_deed_of_sale_of_motor_vehicle.pdf"; depth:106; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465731/; classtype:trojan-activity;sid:84328831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/33d2c907-2bf6-4426-875f-30dcfdd2ea6c/downloads/takeshi_amemiya_advanced_econometrics.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465724/; classtype:trojan-activity;sid:84328824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/paxakuvenu.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465725/; classtype:trojan-activity;sid:84328825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/51d0d552-51a2-4187-835e-597cbad426c9/downloads/astm_e2500.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465715/; classtype:trojan-activity;sid:84328815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/16407212514.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465716/; classtype:trojan-activity;sid:84328816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f2215a6c-0436-4d82-8033-c5d079398259/downloads/mewivisonixapolivifit.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465717/; classtype:trojan-activity;sid:84328817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5778216d-14df-4dd7-ac4c-aefbb7c07c24/downloads/kugaduvekujewotaz.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465718/; classtype:trojan-activity;sid:84328818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/tafanavevimewom.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465719/; classtype:trojan-activity;sid:84328819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/lemowegigusazisalelupo.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465721/; classtype:trojan-activity;sid:84328821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5add4dbc-ec7d-4010-9077-0d95eef82ba1/downloads/64293794102.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465722/; classtype:trojan-activity;sid:84328822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a7c970be-6487-407b-ae67-0318aa6bed96/downloads/19932307165.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465723/; classtype:trojan-activity;sid:84328823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/lowasa.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465709/; classtype:trojan-activity;sid:84328809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/8014aeaa-17b8-4bcd-a9d7-094ad1ff7644/downloads/19999334835.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465710/; classtype:trojan-activity;sid:84328810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/921a43a6-1495-4d95-bdb1-69b79162b826/downloads/13397059696.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465711/; classtype:trojan-activity;sid:84328811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b3cb2fd2-80cf-4497-9966-46f7699e136d/downloads/kovajive.pdf"; depth:70; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465714/; classtype:trojan-activity;sid:84328814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/49bbfdeb-576f-4f20-b756-96ff9c705013/downloads/96422280236.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465707/; classtype:trojan-activity;sid:84328807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/imo_dangerous_goods_declaration_example.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465708/; classtype:trojan-activity;sid:84328808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/bd6582d9-c54a-4b0b-ad89-3fd92efb45aa/downloads/88847399269.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465703/; classtype:trojan-activity;sid:84328803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cdb9e382-acbe-48dd-9722-c531572d81a1/downloads/pugalisamelifakebage.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465704/; classtype:trojan-activity;sid:84328804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/89463890604.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465697/; classtype:trojan-activity;sid:84328797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/lotumajufinunixine.pdf"; depth:80; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465699/; classtype:trojan-activity;sid:84328799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d9951c46-77aa-4ac5-b843-be02d4be2067/downloads/50826134191.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465701/; classtype:trojan-activity;sid:84328801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kasupobuwomubafujos.pdf"; depth:81; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465702/; classtype:trojan-activity;sid:84328802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/jotepebuzixulelomizo.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465691/; classtype:trojan-activity;sid:84328791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e51c42a2-48a1-43ea-b124-a034de3679a6/downloads/83320615193.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465692/; classtype:trojan-activity;sid:84328792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/78c14b69-39ed-4d94-8d63-a7b29776e43c/downloads/radix_temperature_controller_x_48_manual.pdf"; depth:102; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465693/; classtype:trojan-activity;sid:84328793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/24a9af23-a9c8-45b6-80f8-335651f17510/downloads/96094090900.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465694/; classtype:trojan-activity;sid:84328794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/22a15b49-22b8-4edf-a855-4e76194b4aaf/downloads/97812412729.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465695/; classtype:trojan-activity;sid:84328795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/lizaputasu.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465685/; classtype:trojan-activity;sid:84328785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465679)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/boxikijefedajexufesibul.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465679/; classtype:trojan-activity;sid:84328779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/11012613986.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465680/; classtype:trojan-activity;sid:84328780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/bucharest_grill_nutrition_information.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465682/; classtype:trojan-activity;sid:84328782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465683)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3844a76d-a274-4a3a-ad7f-2943a29e37b3/downloads/lezopidigusaraten.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465683/; classtype:trojan-activity;sid:84328783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e9dc005a-39e6-474d-bf2f-ef67b812a261/downloads/guia_para_ingresar_al_bachillerato_conamat.pdf"; depth:104; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465675/; classtype:trojan-activity;sid:84328775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465678)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/robaziromumeborumapix.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465678/; classtype:trojan-activity;sid:84328778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465671)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/52e9408f-c536-4a35-bd81-6078a5dce549/downloads/5252998215.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465671/; classtype:trojan-activity;sid:84328771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/36758652154.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465672/; classtype:trojan-activity;sid:84328772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465673)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/73577237968.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465673/; classtype:trojan-activity;sid:84328773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/louison_et_monsieur_moliere_resume.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465657/; classtype:trojan-activity;sid:84328757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a03fd264-622c-49da-819e-92c49cdd5e2b/downloads/xovifubakuforij.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465660/; classtype:trojan-activity;sid:84328760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/rupesiduvunimekesozo.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465663/; classtype:trojan-activity;sid:84328763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/special_forces_knife_techniques.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465664/; classtype:trojan-activity;sid:84328764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/90645579432.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465665/; classtype:trojan-activity;sid:84328765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7eafcf9d-33bd-4fd4-8489-654d240ab2f3/downloads/6130931006.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465666/; classtype:trojan-activity;sid:84328766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/e0319bbe-78e1-4446-90fc-2b4b4cc85a3e/downloads/camp_green_lake.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465667/; classtype:trojan-activity;sid:84328767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/478a916a-56a8-445d-9eb0-b1a280ba537b/downloads/27628335796.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465668/; classtype:trojan-activity;sid:84328768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/eating_questionnaire-_a_ede-a_scoring.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465655/; classtype:trojan-activity;sid:84328755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/myer_victor_sewing_machine_manual.pdf"; depth:95; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465652/; classtype:trojan-activity;sid:84328752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/jorejujavupu.pdf"; depth:74; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465647/; classtype:trojan-activity;sid:84328747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/41fa09f3-79bd-43c0-909a-d1a20c3cb7f6/downloads/attestation_sur_l_honneur_de_non_ressources.pdf"; depth:105; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465648/; classtype:trojan-activity;sid:84328748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/eb7f2f0c-e896-4e47-abeb-a05a47b6dcff/downloads/37569138292.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465649/; classtype:trojan-activity;sid:84328749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f36019eb-f077-446f-b5b6-39b8eacedf97/downloads/98482064700.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465630/; classtype:trojan-activity;sid:84328730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/83364999300.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465631/; classtype:trojan-activity;sid:84328731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465632)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/records_of_declaration_disbursements_division.pdf"; depth:107; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465632/; classtype:trojan-activity;sid:84328732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f6084bd9-50ce-4d5f-82c5-bb685cd57a0d/downloads/mdsap_audit_checklist.pdf"; depth:83; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465633/; classtype:trojan-activity;sid:84328733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/jaziz.pdf"; depth:67; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465635/; classtype:trojan-activity;sid:84328735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a74441e7-424c-4454-9bc5-28c3682f6c16/downloads/jupifevaperoziput.pdf"; depth:79; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465636/; classtype:trojan-activity;sid:84328736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f778edfd-e481-47d7-9553-9364d433dcaf/downloads/morningstar_andex_chart_2022.pdf"; depth:90; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465637/; classtype:trojan-activity;sid:84328737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/cabcb3ce-a861-487f-a172-56f4b47cbc63/downloads/nilefovidigutozezosanuz.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465638/; classtype:trojan-activity;sid:84328738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/39892598323.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465640/; classtype:trojan-activity;sid:84328740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/00810c7d-a901-42bd-b2e3-20945a4ad8cb/downloads/wimorawezabizu.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465641/; classtype:trojan-activity;sid:84328741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/viduwe.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465642/; classtype:trojan-activity;sid:84328742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a1b48068-f219-4487-b633-0ea4f25dfa5f/downloads/57025089155.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465643/; classtype:trojan-activity;sid:84328743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/00490ec0-0f24-4e25-91e3-8e5bedec5e60/downloads/woxudinawonetunogidubi.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465625/; classtype:trojan-activity;sid:84328725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2224247e-29ce-4f8d-b838-abfcbdf269c0/downloads/16984198490.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465626/; classtype:trojan-activity;sid:84328726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/33bb6cfc-294d-4317-8afb-5d34ed60ffe6/downloads/20222176664.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465622/; classtype:trojan-activity;sid:84328722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/72454635563.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465618/; classtype:trojan-activity;sid:84328718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pisaxafubavofi.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465621/; classtype:trojan-activity;sid:84328721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/catastrophic_disaster_area_property_inspection_report.pdf"; depth:115; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465613/; classtype:trojan-activity;sid:84328713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/citadel_document_solutions_lawsuit.pdf"; depth:96; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465615/; classtype:trojan-activity;sid:84328715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465607)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/fumaxogufav.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465607/; classtype:trojan-activity;sid:84328707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/kigepobesewizijipakusafal.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465610/; classtype:trojan-activity;sid:84328710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/tabuas_sumerias_traduzidas.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465600/; classtype:trojan-activity;sid:84328700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/17054728623.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465603/; classtype:trojan-activity;sid:84328703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465604)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/678cd2ef-32fa-4621-9c35-e4f34096b4ea/downloads/airbus_cml.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465604/; classtype:trojan-activity;sid:84328704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/3730146334.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465605/; classtype:trojan-activity;sid:84328705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/36770579775.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465606/; classtype:trojan-activity;sid:84328706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a0b0ee5f-47ab-407d-8f2e-b86a71eb1b80/downloads/luxodebapiruwuneragomugef.pdf"; depth:87; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465594/; classtype:trojan-activity;sid:84328694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/87554570559.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465598/; classtype:trojan-activity;sid:84328698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/fff11fc4-91ee-4c26-ab94-6b71630d2bb1/downloads/resignation_letter_sample_for_bpo_company.pdf"; depth:103; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465599/; classtype:trojan-activity;sid:84328699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/84675915071.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465586/; classtype:trojan-activity;sid:84328686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/17a8127f-1a20-4f1c-a234-ba1b1a8873f5/downloads/90572854820.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465588/; classtype:trojan-activity;sid:84328688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465589)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/78534035283.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465589/; classtype:trojan-activity;sid:84328689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/wudofe.pdf"; depth:68; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465590/; classtype:trojan-activity;sid:84328690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/glassman_high_voltage_series_eq_manual.pdf"; depth:100; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465592/; classtype:trojan-activity;sid:84328692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465593)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/57653563602.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465593/; classtype:trojan-activity;sid:84328693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465585)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/343166b6-b38d-45a3-a768-806295759a1d/downloads/vatemunubiserotogurozem.pdf"; depth:85; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465585/; classtype:trojan-activity;sid:84328685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/simamutozudolejezeze.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465582/; classtype:trojan-activity;sid:84328682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/a8a7b266-73df-492a-af50-f7d9f90e0e6d/downloads/salesforce_community_developer_guide.pdf"; depth:98; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465583/; classtype:trojan-activity;sid:84328683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465572)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/zepojekowokevi.pdf"; depth:76; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465572/; classtype:trojan-activity;sid:84328672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/2cd8ef37-3f02-4d83-b132-5400b0b21173/downloads/can_sins_be_forgiven_in_hinduism.pdf"; depth:94; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465573/; classtype:trojan-activity;sid:84328673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/9390f2de-e8f5-48e5-8f1b-3aa5affb2913/downloads/ra_to_surface_finish.pdf"; depth:82; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465574/; classtype:trojan-activity;sid:84328674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/holman_enterprises_annual_report.pdf"; depth:94; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465577/; classtype:trojan-activity;sid:84328677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/chiller_factory_acceptance_test_checklist_template.pdf"; depth:112; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465551/; classtype:trojan-activity;sid:84328651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465552)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7913e2d4-0776-44f0-af91-53eb35e22f50/downloads/broken_sous_ta_peau_2_ekladata.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465552/; classtype:trojan-activity;sid:84328652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/lujipipatemajipurozurile.pdf"; depth:86; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465553/; classtype:trojan-activity;sid:84328653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/20a6346a-1701-43f8-be7d-6426912a09c2/downloads/sottoindicato_o_sotto_indicato_treccani.pdf"; depth:101; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465554/; classtype:trojan-activity;sid:84328654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/62fde782-5483-4905-a6da-12e04ab1250b/downloads/38559734752.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465555/; classtype:trojan-activity;sid:84328655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/dfa50dfd-b675-4866-b542-d79684ac1045/downloads/28769720040.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465556/; classtype:trojan-activity;sid:84328656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/formato_st-4_imss_para_imprimir.pdf"; depth:93; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465557/; classtype:trojan-activity;sid:84328657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/adfd48e6-08dc-41dd-a2a1-45489e329c75/downloads/attestation_de_non_affiliation_cnas.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465558/; classtype:trojan-activity;sid:84328658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/tosca_automation_specialist_level_2_certification_questions_.pdf"; depth:122; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465559/; classtype:trojan-activity;sid:84328659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/how_to_factory_reset_verifone_mx915.pdf"; depth:97; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465560/; classtype:trojan-activity;sid:84328660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/5e489076-b026-43ca-95da-8c6fe49f6d00/downloads/frm_part_2_schweser_quicksheet.pdf"; depth:92; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465561/; classtype:trojan-activity;sid:84328661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/incucyte_s3_user_guide.pdf"; depth:84; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465562/; classtype:trojan-activity;sid:84328662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/lean_visual_management_board_examples.pdf"; depth:99; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465563/; classtype:trojan-activity;sid:84328663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/1567746722.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465564/; classtype:trojan-activity;sid:84328664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465565)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/b6875802-d83d-45fa-a01c-dd9f30c53739/downloads/xujudodavudejeb.pdf"; depth:77; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465565/; classtype:trojan-activity;sid:84328665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465566)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/situation_denonciation_coupe_ou_ancre_exercices_corriges.pdf"; depth:118; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465566/; classtype:trojan-activity;sid:84328666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/wikuzidip.pdf"; depth:71; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465567/; classtype:trojan-activity;sid:84328667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/d5e97205-d745-471d-94c2-4bc94f943a29/downloads/87185669225.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465568/; classtype:trojan-activity;sid:84328668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/likibixeve.pdf"; depth:72; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465569/; classtype:trojan-activity;sid:84328669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/exsilentia_4._0_user_guide.pdf"; depth:88; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465570/; classtype:trojan-activity;sid:84328670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465571)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blobby/go/586b3ef6-c9db-4d1a-a9eb-303f942e21fa/downloads/55359157176.pdf"; depth:73; endswith; nocase; http.host; content:"img1.wsimg.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465571/; classtype:trojan-activity;sid:84328671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465210)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1kjjvh1muhjrkrzbajjlzjfawyi0zvxc1"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_04; reference:url, urlhaus.abuse.ch/url/3465210/; classtype:trojan-activity;sid:84328310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3464706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/wupiao.3987.com.rar"; depth:25; endswith; nocase; http.host; content:"forspeed.onlinedown.net"; depth:23; isdataat:!1,relative; metadata:created_at 2025_03_03; reference:url, urlhaus.abuse.ch/url/3464706/; classtype:trojan-activity;sid:84327806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/up/"; depth:4; endswith; nocase; http.host; content:"blessdayservices.org"; depth:20; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463509/; classtype:trojan-activity;sid:84326609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v/"; depth:3; endswith; nocase; http.host; content:"jessespridecharters.com"; depth:23; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463513/; classtype:trojan-activity;sid:84326613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"cambodiatouristservice.com"; depth:26; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463490/; classtype:trojan-activity;sid:84326590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"admin.gestroom.it"; depth:17; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463480/; classtype:trojan-activity;sid:84326580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"test.peperoncinochepassione.it"; depth:30; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463481/; classtype:trojan-activity;sid:84326581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"first-security-verden.de"; depth:24; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463482/; classtype:trojan-activity;sid:84326582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"www.first-security-verden.de"; depth:28; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463470/; classtype:trojan-activity;sid:84326570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463472)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"zamilgroups.com"; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463472/; classtype:trojan-activity;sid:84326572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"www.website.mypetapp.co.za"; depth:26; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463459/; classtype:trojan-activity;sid:84326559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"www.bratusferramentas.grupomoltz.com.br"; depth:39; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463446/; classtype:trojan-activity;sid:84326546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"website.mypetapp.co.za"; depth:22; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463437/; classtype:trojan-activity;sid:84326537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"bmdcompany.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463426/; classtype:trojan-activity;sid:84326526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"www.zamilgroups.com"; depth:19; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463430/; classtype:trojan-activity;sid:84326530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"www.test.peperoncinochepassione.it"; depth:34; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463422/; classtype:trojan-activity;sid:84326522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463367)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"82.146.62.232"; depth:13; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463367/; classtype:trojan-activity;sid:84326467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"82.146.62.232"; depth:13; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463364/; classtype:trojan-activity;sid:84326464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/plugin2.plg"; depth:16; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461771/; classtype:trojan-activity;sid:84324871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/plugin1.plg"; depth:16; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461769/; classtype:trojan-activity;sid:84324869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/plugin2.dll"; depth:16; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461770/; classtype:trojan-activity;sid:84324870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/plugin3.plg"; depth:16; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461768/; classtype:trojan-activity;sid:84324868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/plugin1.dll"; depth:16; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461767/; classtype:trojan-activity;sid:84324867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/plugin3.dll"; depth:16; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461763/; classtype:trojan-activity;sid:84324863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/robertdavidgraham/masscan/zip/refs/heads/master"; depth:48; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461663/; classtype:trojan-activity;sid:84324763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/robertdavidgraham/masscan/archive/refs/heads/master.zip"; depth:56; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461661/; classtype:trojan-activity;sid:84324761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3460167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"112.4.110.28"; depth:12; isdataat:!1,relative; metadata:created_at 2025_02_27; reference:url, urlhaus.abuse.ch/url/3460167/; classtype:trojan-activity;sid:84323267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3460000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1uxmu02r04iaslsrsh9quahzfsvq3tozm"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_02_27; reference:url, urlhaus.abuse.ch/url/3460000/; classtype:trojan-activity;sid:84323100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3452200)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"95.62.202.150"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_25; reference:url, urlhaus.abuse.ch/url/3452200/; classtype:trojan-activity;sid:84315300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3450176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/temp/putty.exe"; depth:15; endswith; nocase; http.host; content:"book.rollingvideogames.com"; depth:26; isdataat:!1,relative; metadata:created_at 2025_02_23; reference:url, urlhaus.abuse.ch/url/3450176/; classtype:trojan-activity;sid:84313276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3450147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loveryajenja/lwafmwoafmw11/raw/refs/heads/main/install.exe"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_23; reference:url, urlhaus.abuse.ch/url/3450147/; classtype:trojan-activity;sid:84313247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3450048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/continue/45.ps1"; depth:16; endswith; nocase; http.host; content:"www.benshamcentre.co.uk"; depth:23; isdataat:!1,relative; metadata:created_at 2025_02_23; reference:url, urlhaus.abuse.ch/url/3450048/; classtype:trojan-activity;sid:84313148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"93.87.42.154"; depth:12; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447681/; classtype:trojan-activity;sid:84310781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/laurenxss/36b18f37163aaa04654bd21e98d1b842/raw/dca82ba88fae8788a48ffb529f9610a0cc209781/x"; depth:90; endswith; nocase; http.host; content:"gist.githubusercontent.com"; depth:26; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447466/; classtype:trojan-activity;sid:84310566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sena1.png"; depth:10; endswith; nocase; http.host; content:"leindisncieamrocea-1341831283.cos.sa-saopaulo.myqcloud.com"; depth:58; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447458/; classtype:trojan-activity;sid:84310558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manga1.png"; depth:11; endswith; nocase; http.host; content:"leindisncieamrocea-1341831283.cos.sa-saopaulo.myqcloud.com"; depth:58; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447456/; classtype:trojan-activity;sid:84310556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/colheita1.png"; depth:14; endswith; nocase; http.host; content:"leindisncieamrocea-1341831283.cos.sa-saopaulo.myqcloud.com"; depth:58; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447457/; classtype:trojan-activity;sid:84310557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3446661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img001.exe"; depth:11; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_20; reference:url, urlhaus.abuse.ch/url/3446661/; classtype:trojan-activity;sid:84309761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3446653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"116.171.106.3"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_20; reference:url, urlhaus.abuse.ch/url/3446653/; classtype:trojan-activity;sid:84309753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3446649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/info.zip"; depth:9; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_20; reference:url, urlhaus.abuse.ch/url/3446649/; classtype:trojan-activity;sid:84309749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3445854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coracion1.png"; depth:14; endswith; nocase; http.host; content:"vaamsmgfreocmroe-1342087530.cos.sa-saopaulo.myqcloud.com"; depth:56; isdataat:!1,relative; metadata:created_at 2025_02_20; reference:url, urlhaus.abuse.ch/url/3445854/; classtype:trojan-activity;sid:84308954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3445431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data/df4a3196-accc-423a-a43b-6768f1aafd3e.pdf"; depth:46; endswith; nocase; http.host; content:"hotelembuguacu.blob.core.windows.net"; depth:36; isdataat:!1,relative; metadata:created_at 2025_02_19; reference:url, urlhaus.abuse.ch/url/3445431/; classtype:trojan-activity;sid:84308531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3445438)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/data/f6416fd0-71f3-45de-8c79-3d0e7281f124.pdf"; depth:46; endswith; nocase; http.host; content:"hotelembuguacu.blob.core.windows.net"; depth:36; isdataat:!1,relative; metadata:created_at 2025_02_19; reference:url, urlhaus.abuse.ch/url/3445438/; classtype:trojan-activity;sid:84308538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3444507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leinchchanceleinch/jik/refs/heads/main/d.msi"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_02_18; reference:url, urlhaus.abuse.ch/url/3444507/; classtype:trojan-activity;sid:84307607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3444267)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leinchchanceleinch/jik/raw/refs/heads/main/d.msi"; depth:49; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_18; reference:url, urlhaus.abuse.ch/url/3444267/; classtype:trojan-activity;sid:84307367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3443355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"179.248.3.202.ll.sta.mana.pf"; depth:28; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3443355/; classtype:trojan-activity;sid:84306455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3443354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.248.3.202.ll.sta.mana.pf"; depth:28; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3443354/; classtype:trojan-activity;sid:84306454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3443353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"99-118-215-24.lightspeed.irvnca.sbcglobal.net"; depth:45; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3443353/; classtype:trojan-activity;sid:84306453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3443350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"host-95-230-215-65.business.telecomitalia.it"; depth:44; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3443350/; classtype:trojan-activity;sid:84306450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output0/client/cabalmain.exe"; depth:29; endswith; nocase; http.host; content:"168.138.162.78"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3442712/; classtype:trojan-activity;sid:84305812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442701)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output0/client/cabal.exe"; depth:25; endswith; nocase; http.host; content:"168.138.162.78"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3442701/; classtype:trojan-activity;sid:84305801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/client/cabalmain.exe"; depth:28; endswith; nocase; http.host; content:"168.138.162.78"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3442616/; classtype:trojan-activity;sid:84305716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442198)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xxxx"; depth:5; endswith; nocase; http.host; content:"47.89.173.214"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3442198/; classtype:trojan-activity;sid:84305298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ffff"; depth:5; endswith; nocase; http.host; content:"47.89.173.214"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3442196/; classtype:trojan-activity;sid:84305296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asdf"; depth:5; endswith; nocase; http.host; content:"47.89.173.214"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3442197/; classtype:trojan-activity;sid:84305297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/libmod_hellocpp_42.so"; depth:22; endswith; nocase; http.host; content:"47.89.173.214"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3442195/; classtype:trojan-activity;sid:84305295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3441724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/output/client/cabal.exe"; depth:24; endswith; nocase; http.host; content:"168.138.162.78"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3441724/; classtype:trojan-activity;sid:84304824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l/rls"; depth:11; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440974/; classtype:trojan-activity;sid:84304074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64/rls"; depth:11; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440971/; classtype:trojan-activity;sid:84304071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64/rld"; depth:11; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440972/; classtype:trojan-activity;sid:84304072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l/kthreadrm"; depth:17; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440969/; classtype:trojan-activity;sid:84304069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440970)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64/kthreadrm"; depth:17; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440970/; classtype:trojan-activity;sid:84304070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aarch64"; depth:8; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440930/; classtype:trojan-activity;sid:84304030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arm7"; depth:5; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440931/; classtype:trojan-activity;sid:84304031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x86_64"; depth:7; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440932/; classtype:trojan-activity;sid:84304032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440934)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"198.166.72.242"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440934/; classtype:trojan-activity;sid:84304034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3439829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/umbrella/"; depth:10; endswith; nocase; http.host; content:"acusense.ae"; depth:11; isdataat:!1,relative; metadata:created_at 2025_02_14; reference:url, urlhaus.abuse.ch/url/3439829/; classtype:trojan-activity;sid:84302929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3438591)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"80.11.36.4"; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_13; reference:url, urlhaus.abuse.ch/url/3438591/; classtype:trojan-activity;sid:84301691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3438594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"80.11.36.4"; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_13; reference:url, urlhaus.abuse.ch/url/3438594/; classtype:trojan-activity;sid:84301694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3437118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/cgi-bin/adonis/pure_adonis"; depth:32; endswith; nocase; http.host; content:"upchemicals.co.in"; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_12; reference:url, urlhaus.abuse.ch/url/3437118/; classtype:trojan-activity;sid:84300218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3437119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/cgi-bin/jnd/pure_jnd"; depth:26; endswith; nocase; http.host; content:"upchemicals.co.in"; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_12; reference:url, urlhaus.abuse.ch/url/3437119/; classtype:trojan-activity;sid:84300219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3437116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/cgi-bin/adonis/all_adonis"; depth:31; endswith; nocase; http.host; content:"upchemicals.co.in"; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_12; reference:url, urlhaus.abuse.ch/url/3437116/; classtype:trojan-activity;sid:84300216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3437117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/cgi-bin/mr_bean/pure_bean"; depth:31; endswith; nocase; http.host; content:"upchemicals.co.in"; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_12; reference:url, urlhaus.abuse.ch/url/3437117/; classtype:trojan-activity;sid:84300217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3437115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/cgi-bin/mr_bean/all_bean"; depth:30; endswith; nocase; http.host; content:"upchemicals.co.in"; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_12; reference:url, urlhaus.abuse.ch/url/3437115/; classtype:trojan-activity;sid:84300215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3437114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/cgi-bin/jnd/jnd_all"; depth:25; endswith; nocase; http.host; content:"upchemicals.co.in"; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_12; reference:url, urlhaus.abuse.ch/url/3437114/; classtype:trojan-activity;sid:84300214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3435170)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neo23x0/signature-base/archive/master.zip"; depth:42; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_10; reference:url, urlhaus.abuse.ch/url/3435170/; classtype:trojan-activity;sid:84298270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3433357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"114.31.8.22"; depth:11; isdataat:!1,relative; metadata:created_at 2025_02_09; reference:url, urlhaus.abuse.ch/url/3433357/; classtype:trojan-activity;sid:84296457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3431851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/cgi-bin/mr_bean/all_bean"; depth:30; endswith; nocase; http.host; content:"upchemicals.co.in"; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_08; reference:url, urlhaus.abuse.ch/url/3431851/; classtype:trojan-activity;sid:84294951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3431850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/test/cgi-bin/mr_bean/pure_bean"; depth:31; endswith; nocase; http.host; content:"upchemicals.co.in"; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_08; reference:url, urlhaus.abuse.ch/url/3431850/; classtype:trojan-activity;sid:84294950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3431687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bljysvhw/info.zip"; depth:18; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_08; reference:url, urlhaus.abuse.ch/url/3431687/; classtype:trojan-activity;sid:84294787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3431686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bljysvhw/img001.exe"; depth:20; endswith; nocase; http.host; content:"200.14.250.72"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_08; reference:url, urlhaus.abuse.ch/url/3431686/; classtype:trojan-activity;sid:84294786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3429885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1/test.jpg"; depth:11; endswith; nocase; http.host; content:"ofice365.github.io"; depth:18; isdataat:!1,relative; metadata:created_at 2025_02_06; reference:url, urlhaus.abuse.ch/url/3429885/; classtype:trojan-activity;sid:84292985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3429793)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/static/files/bootstrappernew.exe"; depth:42; endswith; nocase; http.host; content:"d2314eac.solaraweb-alj.pages.dev"; depth:32; isdataat:!1,relative; metadata:created_at 2025_02_06; reference:url, urlhaus.abuse.ch/url/3429793/; classtype:trojan-activity;sid:84292893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3429311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.159.221.33"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_05; reference:url, urlhaus.abuse.ch/url/3429311/; classtype:trojan-activity;sid:84292411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3424485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.147.196.138"; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_02; reference:url, urlhaus.abuse.ch/url/3424485/; classtype:trojan-activity;sid:84287585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3423045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.70.63"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_01; reference:url, urlhaus.abuse.ch/url/3423045/; classtype:trojan-activity;sid:84286145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3423046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.70.63"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_01; reference:url, urlhaus.abuse.ch/url/3423046/; classtype:trojan-activity;sid:84286146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3423047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.70.63"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_01; reference:url, urlhaus.abuse.ch/url/3423047/; classtype:trojan-activity;sid:84286147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3423050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.70.63"; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_01; reference:url, urlhaus.abuse.ch/url/3423050/; classtype:trojan-activity;sid:84286150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3421183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xsh/xsh.exe"; depth:12; endswith; nocase; http.host; content:"101.126.11.168"; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_31; reference:url, urlhaus.abuse.ch/url/3421183/; classtype:trojan-activity;sid:84284283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3421027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sigmaplus/4.exe"; depth:16; endswith; nocase; http.host; content:"ny.lshdw.cc"; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_31; reference:url, urlhaus.abuse.ch/url/3421027/; classtype:trojan-activity;sid:84284127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3421020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ftp/emmetprod.exe"; depth:18; endswith; nocase; http.host; content:"141.147.43.219"; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_31; reference:url, urlhaus.abuse.ch/url/3421020/; classtype:trojan-activity;sid:84284120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3420564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.70.63"; depth:13; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3420564/; classtype:trojan-activity;sid:84283664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3419560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ff245185/payload/raw/refs/heads/main/fast%20download.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3419560/; classtype:trojan-activity;sid:84282660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3419570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grozniy1/folder/raw/refs/heads/main/444.exe"; depth:44; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3419570/; classtype:trojan-activity;sid:84282670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3419477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xevioo/xeviohub/raw/refs/heads/main/critscript.exe"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3419477/; classtype:trojan-activity;sid:84282577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3419368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/17793058/lg246dre.txt"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3419368/; classtype:trojan-activity;sid:84282468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3418042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cab/launcherloader.exe"; depth:23; endswith; nocase; http.host; content:"www.newkey.co.kr"; depth:16; isdataat:!1,relative; metadata:created_at 2025_01_29; reference:url, urlhaus.abuse.ch/url/3418042/; classtype:trojan-activity;sid:84281142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3417826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.250.173.158"; depth:15; isdataat:!1,relative; metadata:created_at 2025_01_28; reference:url, urlhaus.abuse.ch/url/3417826/; classtype:trojan-activity;sid:84280926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3417095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1t9mwfr1azhmksosp19tomch5dyi3hb2n"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2025_01_28; reference:url, urlhaus.abuse.ch/url/3417095/; classtype:trojan-activity;sid:84280195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3416674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.165.237.60"; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_27; reference:url, urlhaus.abuse.ch/url/3416674/; classtype:trojan-activity;sid:84279774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3415308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"222.165.237.59"; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_26; reference:url, urlhaus.abuse.ch/url/3415308/; classtype:trojan-activity;sid:84278408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3415209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loginanticheat.dll"; depth:19; endswith; nocase; http.host; content:"43.226.39.44"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_26; reference:url, urlhaus.abuse.ch/url/3415209/; classtype:trojan-activity;sid:84278309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3415207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loginanticheat4.dll"; depth:20; endswith; nocase; http.host; content:"43.226.39.44"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_26; reference:url, urlhaus.abuse.ch/url/3415207/; classtype:trojan-activity;sid:84278307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3414036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"216.155.92.203"; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_25; reference:url, urlhaus.abuse.ch/url/3414036/; classtype:trojan-activity;sid:84277136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3410864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackhatethicalhacking/fud/blob/master/access.exe|3f|raw=true"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_23; reference:url, urlhaus.abuse.ch/url/3410864/; classtype:trojan-activity;sid:84273964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3410865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackhatethicalhacking/fud/raw/refs/heads/master/access.exe"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_23; reference:url, urlhaus.abuse.ch/url/3410865/; classtype:trojan-activity;sid:84273965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3410375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"80.11.36.4"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_22; reference:url, urlhaus.abuse.ch/url/3410375/; classtype:trojan-activity;sid:84273475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3409838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blackhatethicalhacking/fud/refs/heads/master/access.exe"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_22; reference:url, urlhaus.abuse.ch/url/3409838/; classtype:trojan-activity;sid:84272938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3406818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/%eb%a7%ac%ec%9b%a8%ec%96%b4.hta"; depth:32; endswith; nocase; http.host; content:"hobobot.net"; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_20; reference:url, urlhaus.abuse.ch/url/3406818/; classtype:trojan-activity;sid:84269918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3406822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/%eb%b9%8c%ec%96%b4%20%eb%a8%b9%ec%9d%84.hta"; depth:44; endswith; nocase; http.host; content:"hobobot.net"; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_20; reference:url, urlhaus.abuse.ch/url/3406822/; classtype:trojan-activity;sid:84269922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"182.109.0.22"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405330/; classtype:trojan-activity;sid:84268430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"92.66.30.68"; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405320/; classtype:trojan-activity;sid:84268420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"92.66.30.68"; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405323/; classtype:trojan-activity;sid:84268423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"92.66.30.68"; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405324/; classtype:trojan-activity;sid:84268424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405319)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"92.66.30.68"; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405319/; classtype:trojan-activity;sid:84268419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.247.101.185"; depth:15; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405187/; classtype:trojan-activity;sid:84268287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.215.129.223"; depth:15; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405140/; classtype:trojan-activity;sid:84268240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.20.19.72"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405120/; classtype:trojan-activity;sid:84268220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3403380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lehila05/pdc/refs/heads/main/payload.bin"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_17; reference:url, urlhaus.abuse.ch/url/3403380/; classtype:trojan-activity;sid:84266480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3402741)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adobepdf-reader/pdf-reader/raw/refs/heads/main/pdf%20reader.exe"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_16; reference:url, urlhaus.abuse.ch/url/3402741/; classtype:trojan-activity;sid:84265841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3402154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.88.6.203"; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_16; reference:url, urlhaus.abuse.ch/url/3402154/; classtype:trojan-activity;sid:84265254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3401644)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/wpr-addons/forms/code1.png"; depth:46; endswith; nocase; http.host; content:"107.180.89.159"; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_15; reference:url, urlhaus.abuse.ch/url/3401644/; classtype:trojan-activity;sid:84264744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3399396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"115.178.100.190"; depth:15; isdataat:!1,relative; metadata:created_at 2025_01_13; reference:url, urlhaus.abuse.ch/url/3399396/; classtype:trojan-activity;sid:84262496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3398629)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ox2fa/justnow/refs/heads/main/1.sh"; depth:35; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_13; reference:url, urlhaus.abuse.ch/url/3398629/; classtype:trojan-activity;sid:84261729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3397531)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.168.227.130"; depth:15; isdataat:!1,relative; metadata:created_at 2025_01_11; reference:url, urlhaus.abuse.ch/url/3397531/; classtype:trojan-activity;sid:84260631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3395055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arvendrachhonkar/todo/releases/download/macosandwindows/install_setup_v1.2.0.dmg"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_09; reference:url, urlhaus.abuse.ch/url/3395055/; classtype:trojan-activity;sid:84258155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3394507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trismagi/daemon/raw/main/watchdog"; depth:34; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_09; reference:url, urlhaus.abuse.ch/url/3394507/; classtype:trojan-activity;sid:84257607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3394121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"62.56.225.99"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_08; reference:url, urlhaus.abuse.ch/url/3394121/; classtype:trojan-activity;sid:84257221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3394115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"62.56.225.99"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_08; reference:url, urlhaus.abuse.ch/url/3394115/; classtype:trojan-activity;sid:84257215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3393662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roukistl/ud/refs/heads/main/ud.bat"; depth:35; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_08; reference:url, urlhaus.abuse.ch/url/3393662/; classtype:trojan-activity;sid:84256762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3393596)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thomson101/xhp/releases/download/release/steanings.exe"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_08; reference:url, urlhaus.abuse.ch/url/3393596/; classtype:trojan-activity;sid:84256696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3393047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thomson101/xhp/releases/download/release/steanings.exe"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_07; reference:url, urlhaus.abuse.ch/url/3393047/; classtype:trojan-activity;sid:84256147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3390789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kusaka.php|3f|call=av"; depth:22; endswith; nocase; http.host; content:"cpofficial.com"; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_05; reference:url, urlhaus.abuse.ch/url/3390789/; classtype:trojan-activity;sid:84253889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3390749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kusaka.php|3f|call=smp"; depth:23; endswith; nocase; http.host; content:"mx9x.com"; depth:8; isdataat:!1,relative; metadata:created_at 2025_01_05; reference:url, urlhaus.abuse.ch/url/3390749/; classtype:trojan-activity;sid:84253849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3389403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ngrokc/ctc/raw/main/ctc64.dll"; depth:30; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_04; reference:url, urlhaus.abuse.ch/url/3389403/; classtype:trojan-activity;sid:84252503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3389404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ngrokc/ctc/main/ctc64.dll"; depth:26; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_04; reference:url, urlhaus.abuse.ch/url/3389404/; classtype:trojan-activity;sid:84252504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3388907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.83.78"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_04; reference:url, urlhaus.abuse.ch/url/3388907/; classtype:trojan-activity;sid:84252007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3388858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/static/files/solara.dir.zip"; depth:37; endswith; nocase; http.host; content:"c0e5b87c.solaraweb-alj.pages.dev"; depth:32; isdataat:!1,relative; metadata:created_at 2025_01_04; reference:url, urlhaus.abuse.ch/url/3388858/; classtype:trojan-activity;sid:84251958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3388859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/static/files/bootstrappernew.exe"; depth:42; endswith; nocase; http.host; content:"c0e5b87c.solaraweb-alj.pages.dev"; depth:32; isdataat:!1,relative; metadata:created_at 2025_01_04; reference:url, urlhaus.abuse.ch/url/3388859/; classtype:trojan-activity;sid:84251959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3387720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fericarr/newky/raw/refs/heads/main/prueba.exe"; depth:46; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_03; reference:url, urlhaus.abuse.ch/url/3387720/; classtype:trojan-activity;sid:84250820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3386507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file-32bit.elf"; depth:15; endswith; nocase; http.host; content:"34.45.47.180"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_02; reference:url, urlhaus.abuse.ch/url/3386507/; classtype:trojan-activity;sid:84249607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3386508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file.elf"; depth:9; endswith; nocase; http.host; content:"34.45.47.180"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_02; reference:url, urlhaus.abuse.ch/url/3386508/; classtype:trojan-activity;sid:84249608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3386509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file-arm.elf"; depth:13; endswith; nocase; http.host; content:"34.45.47.180"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_02; reference:url, urlhaus.abuse.ch/url/3386509/; classtype:trojan-activity;sid:84249609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3386510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file-64bit.elf"; depth:15; endswith; nocase; http.host; content:"34.45.47.180"; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_02; reference:url, urlhaus.abuse.ch/url/3386510/; classtype:trojan-activity;sid:84249610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3385167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soft_hair/ultravnc.ini"; depth:23; endswith; nocase; http.host; content:"support.clz.kr"; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_01; reference:url, urlhaus.abuse.ch/url/3385167/; classtype:trojan-activity;sid:84248267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3373067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"94.244.113.217"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3373067/; classtype:trojan-activity;sid:84236167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3373050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"89.216.107.99"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3373050/; classtype:trojan-activity;sid:84236150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3373017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"186.138.107.5"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3373017/; classtype:trojan-activity;sid:84236117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.93.83.124"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372979/; classtype:trojan-activity;sid:84236079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372968)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.85.166.12"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372968/; classtype:trojan-activity;sid:84236068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372964)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"139.255.97.116"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372964/; classtype:trojan-activity;sid:84236064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372953)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"47.49.114.179"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372953/; classtype:trojan-activity;sid:84236053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.129.177.162"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372956/; classtype:trojan-activity;sid:84236056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"111.74.21.155"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372903/; classtype:trojan-activity;sid:84236003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372902/; classtype:trojan-activity;sid:84236002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372900/; classtype:trojan-activity;sid:84236000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372891/; classtype:trojan-activity;sid:84235991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372892/; classtype:trojan-activity;sid:84235992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372893/; classtype:trojan-activity;sid:84235993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372896/; classtype:trojan-activity;sid:84235996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372898/; classtype:trojan-activity;sid:84235998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372883/; classtype:trojan-activity;sid:84235983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372884)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372884/; classtype:trojan-activity;sid:84235984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372885)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372885/; classtype:trojan-activity;sid:84235985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372886)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372886/; classtype:trojan-activity;sid:84235986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"46.141.62.238"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372887/; classtype:trojan-activity;sid:84235987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372890/; classtype:trojan-activity;sid:84235990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.247.101.63"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372876/; classtype:trojan-activity;sid:84235976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372878/; classtype:trojan-activity;sid:84235978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372879/; classtype:trojan-activity;sid:84235979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372880)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.240.155.245"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372880/; classtype:trojan-activity;sid:84235980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.34.102.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372704/; classtype:trojan-activity;sid:84235804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.34.102.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372705/; classtype:trojan-activity;sid:84235805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.34.102.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372684/; classtype:trojan-activity;sid:84235784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.88.190"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372657/; classtype:trojan-activity;sid:84235757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.34.102.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372654/; classtype:trojan-activity;sid:84235754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.34.102.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372651/; classtype:trojan-activity;sid:84235751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"2.54.88.189"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372625/; classtype:trojan-activity;sid:84235725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.34.102.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372639/; classtype:trojan-activity;sid:84235739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372615)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"195.34.102.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372615/; classtype:trojan-activity;sid:84235715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3366262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.73.75.82"; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_19; reference:url, urlhaus.abuse.ch/url/3366262/; classtype:trojan-activity;sid:84229362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3366230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.220.123.125"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_19; reference:url, urlhaus.abuse.ch/url/3366230/; classtype:trojan-activity;sid:84229330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356912)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ef/ef.bin"; depth:10; endswith; nocase; http.host; content:"www.tdejb.com"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356912/; classtype:trojan-activity;sid:84220012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ef/skifterne.sea"; depth:17; endswith; nocase; http.host; content:"www.tdejb.com"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356911/; classtype:trojan-activity;sid:84220011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ef/ef.vbs"; depth:10; endswith; nocase; http.host; content:"www.astenterprises.com.pk"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356909/; classtype:trojan-activity;sid:84220009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yn5og-40i6-9gu-9hjf.html"; depth:25; endswith; nocase; http.host; content:"bj5y6-0f-9h4-9fgg4-1324992141.cos.ap-bangkok.myqcloud.com"; depth:57; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356803/; classtype:trojan-activity;sid:84219903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/futon"; depth:6; endswith; nocase; http.host; content:"weco2.oss-me-east-1.aliyuncs.com"; depth:32; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356768/; classtype:trojan-activity;sid:84219868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/smiple_4yue"; depth:12; endswith; nocase; http.host; content:"weco2.oss-me-east-1.aliyuncs.com"; depth:32; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356761/; classtype:trojan-activity;sid:84219861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/36hg-04ik6-9j4-9h5.html"; depth:24; endswith; nocase; http.host; content:"f3i5-0g49bgn-3h95-1324992141.cos.ap-jakarta.myqcloud.com"; depth:56; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356758/; classtype:trojan-activity;sid:84219858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/35-0350gh9v-39yh5g.html"; depth:24; endswith; nocase; http.host; content:"j-0-09g-9bh-h-ggf-1324992141.cos.ap-bangkok.myqcloud.com"; depth:56; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356750/; classtype:trojan-activity;sid:84219850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xevioo/xeviohub/refs/heads/main/critscript.exe"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356162/; classtype:trojan-activity;sid:84219262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ff245185/payload/refs/heads/main/fast%20download.exe"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356145/; classtype:trojan-activity;sid:84219245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pr0xylife/asyncrat/refs/heads/main/asyncrat_09.02.2022.txt"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356134/; classtype:trojan-activity;sid:84219234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grozniy1/folder/refs/heads/main/444.exe"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356133/; classtype:trojan-activity;sid:84219233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deroxs/powerrat-leak/refs/heads/main/powerrat.exe"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356118/; classtype:trojan-activity;sid:84219218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rookievip/xx/main/loader.exe"; depth:29; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353957/; classtype:trojan-activity;sid:84217057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353403)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fericarr/newky/refs/heads/main/prueba.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353403/; classtype:trojan-activity;sid:84216503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fengjixuchui/cve-2022-26810/refs/heads/main/shellcode.bin"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353372/; classtype:trojan-activity;sid:84216472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353348)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deroxs/powerrat-leak/raw/refs/heads/main/powerrat.exe"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353348/; classtype:trojan-activity;sid:84216448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/resources/js/info2r.txt/"; depth:25; endswith; nocase; http.host; content:"188.81.134.196"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353349/; classtype:trojan-activity;sid:84216449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pr0xylife/asyncrat/raw/refs/heads/main/asyncrat_09.02.2022.txt"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353345/; classtype:trojan-activity;sid:84216445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dlc_update.data"; depth:16; endswith; nocase; http.host; content:"8.138.96.41"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353333/; classtype:trojan-activity;sid:84216433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353251)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/master.exe"; depth:11; endswith; nocase; http.host; content:"92.127.156.174"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353251/; classtype:trojan-activity;sid:84216351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//chromesetup.exe"; depth:17; endswith; nocase; http.host; content:"85.25.72.70"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353216/; classtype:trojan-activity;sid:84216316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353204)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp.ps1"; depth:7; endswith; nocase; http.host; content:"92.127.156.174"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353204/; classtype:trojan-activity;sid:84216304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cqhack/ddos-script/refs/heads/master/cqhack.pl"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353123/; classtype:trojan-activity;sid:84216223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3352821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaijiorder/cert/2a.hta"; depth:23; endswith; nocase; http.host; content:"182.92.99.95"; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3352821/; classtype:trojan-activity;sid:84215921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351932)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=12jgde-soib4liipbdhs55vkz7ek8_ua6"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351932/; classtype:trojan-activity;sid:84215032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ijeuwaesika/nna/raw/refs/heads/main/ifiinms.txt"; depth:48; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351478/; classtype:trojan-activity;sid:84214578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351477)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fsabxh/sfdawsdawdaw/raw/refs/heads/main/serials_checker.exe"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351477/; classtype:trojan-activity;sid:84214577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xevioo/xeviohub/raw/refs/heads/main/critscript.exe"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351430/; classtype:trojan-activity;sid:84214530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grozniy1/folder/raw/refs/heads/main/444.exe"; depth:44; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351428/; classtype:trojan-activity;sid:84214528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ff245185/payload/raw/refs/heads/main/fast%20download.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351377/; classtype:trojan-activity;sid:84214477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fericarr/newky/raw/refs/heads/main/prueba.exe"; depth:46; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351320/; classtype:trojan-activity;sid:84214420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351297)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/rust-reverse-shell/raw/refs/heads/main/shellcode.bin"; depth:67; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351297/; classtype:trojan-activity;sid:84214397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fengjixuchui/cve-2022-26810/raw/refs/heads/main/shellcode.bin"; depth:62; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351259/; classtype:trojan-activity;sid:84214359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3347308)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/component/vc2005sp1redist_x86.exe"; depth:34; endswith; nocase; http.host; content:"windriversfiles.imeitools.com"; depth:29; isdataat:!1,relative; metadata:created_at 2024_12_13; reference:url, urlhaus.abuse.ch/url/3347308/; classtype:trojan-activity;sid:84210408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3346530)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whoafg/problemonfmech/refs/heads/main/client.exe"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_12; reference:url, urlhaus.abuse.ch/url/3346530/; classtype:trojan-activity;sid:84209630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3346026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaijiorder/cert/41a1111.hta"; depth:28; endswith; nocase; http.host; content:"182.92.99.95"; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_12; reference:url, urlhaus.abuse.ch/url/3346026/; classtype:trojan-activity;sid:84209126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3345089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n00b69/woasetup/releases/download/installers/dxwebsetup.exe"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_11; reference:url, urlhaus.abuse.ch/url/3345089/; classtype:trojan-activity;sid:84208189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3345076)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaijiorder/cert/2a.hta"; depth:23; endswith; nocase; http.host; content:"182.92.99.95"; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_11; reference:url, urlhaus.abuse.ch/url/3345076/; classtype:trojan-activity;sid:84208176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3344216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.x86"; depth:16; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3344216/; classtype:trojan-activity;sid:84207316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3344177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.arm5"; depth:17; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3344177/; classtype:trojan-activity;sid:84207277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3344172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.arm7"; depth:17; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3344172/; classtype:trojan-activity;sid:84207272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3344116)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.ppc"; depth:16; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3344116/; classtype:trojan-activity;sid:84207216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3344054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.mpsl"; depth:17; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3344054/; classtype:trojan-activity;sid:84207154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3344015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.sh4"; depth:16; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3344015/; classtype:trojan-activity;sid:84207115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3343939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.arm6"; depth:17; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3343939/; classtype:trojan-activity;sid:84207039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3343827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.arm"; depth:16; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3343827/; classtype:trojan-activity;sid:84206927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3343814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.m68k"; depth:17; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3343814/; classtype:trojan-activity;sid:84206914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3343669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ab4g5/josho.mips"; depth:17; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3343669/; classtype:trojan-activity;sid:84206769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.arm"; depth:13; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340580/; classtype:trojan-activity;sid:84203680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.spc"; depth:13; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340578/; classtype:trojan-activity;sid:84203678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.m68k"; depth:14; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340577/; classtype:trojan-activity;sid:84203677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.arm7"; depth:14; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340567/; classtype:trojan-activity;sid:84203667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.x86"; depth:13; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340568/; classtype:trojan-activity;sid:84203668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.mips"; depth:14; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340569/; classtype:trojan-activity;sid:84203669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.arm5"; depth:14; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340570/; classtype:trojan-activity;sid:84203670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.ppc"; depth:13; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340573/; classtype:trojan-activity;sid:84203673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.arm6"; depth:14; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340574/; classtype:trojan-activity;sid:84203674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.sh4"; depth:13; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340575/; classtype:trojan-activity;sid:84203675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bins/hax.mpsl"; depth:14; endswith; nocase; http.host; content:"74.48.34.10"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340576/; classtype:trojan-activity;sid:84203676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dis3j/wagnerhook/releases/download/release/loader.exe"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340440/; classtype:trojan-activity;sid:84203540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/xbest%20v1.exe"; depth:33; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340399/; classtype:trojan-activity;sid:84203499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/complexo%20v4.exe"; depth:36; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340398/; classtype:trojan-activity;sid:84203498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/box3d.dll"; depth:28; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340395/; classtype:trojan-activity;sid:84203495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340396)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/lkwan.dll"; depth:28; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340396/; classtype:trojan-activity;sid:84203496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/flunix9.dll"; depth:30; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340397/; classtype:trojan-activity;sid:84203497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340392)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/elzhas%20pannel.dll"; depth:38; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340392/; classtype:trojan-activity;sid:84203492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/morovip.dll"; depth:30; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340393/; classtype:trojan-activity;sid:84203493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/hazaxd.dll"; depth:29; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340394/; classtype:trojan-activity;sid:84203494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/xbest.dll"; depth:28; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340391/; classtype:trojan-activity;sid:84203491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xbest11/ddl1/main/blue_and_white.dll"; depth:37; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340390/; classtype:trojan-activity;sid:84203490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/huuuuggga/aaaaa1/refs/heads/main/srtware.exe"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340363/; classtype:trojan-activity;sid:84203463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339245)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"186.138.107.5"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339245/; classtype:trojan-activity;sid:84202345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"182.93.83.124"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339221/; classtype:trojan-activity;sid:84202321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339179)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"47.49.114.179"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339179/; classtype:trojan-activity;sid:84202279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339161)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"37.220.123.125"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339161/; classtype:trojan-activity;sid:84202261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"216.155.92.203"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339119/; classtype:trojan-activity;sid:84202219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339121)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"89.216.107.99"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339121/; classtype:trojan-activity;sid:84202221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339124)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"93.87.31.84"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339124/; classtype:trojan-activity;sid:84202224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"212.85.166.12"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339084/; classtype:trojan-activity;sid:84202184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kabot/unix-privilege-escalation-exploits-pack/master/2012/vmsplice-local-root-exploit"; depth:86; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338656/; classtype:trojan-activity;sid:84201756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ga13372/jv/main/javaw.exe"; depth:26; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338560/; classtype:trojan-activity;sid:84201660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nicxlau/alfa-shell/master/alfa-obfuscated.php"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338548/; classtype:trojan-activity;sid:84201648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aissardp/payload/main/payload.exe"; depth:34; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338507/; classtype:trojan-activity;sid:84201607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cracker1337uwu/rrr/main/bypass.exe"; depth:35; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338505/; classtype:trojan-activity;sid:84201605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g1vi/cve-2023-2640-cve-2023-32629/main/exploit.sh"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338499/; classtype:trojan-activity;sid:84201599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nguyenmanmkt/repo1/main/exploit-2"; depth:34; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338493/; classtype:trojan-activity;sid:84201593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leetcipher/malware.development/main/self-injection/self-injection.exe"; depth:70; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338492/; classtype:trojan-activity;sid:84201592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338487)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cyberhunter00/remote_hijack/master/uac_bypass.exe"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338487/; classtype:trojan-activity;sid:84201587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cocomelonc/2022-01-14-malware-injection-13/master/hack.exe"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338475/; classtype:trojan-activity;sid:84201575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fxtazz/injection/main/index.js"; depth:31; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338467/; classtype:trojan-activity;sid:84201567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leetcipher/malware.development/main/process-injection/process-injection.exe"; depth:76; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338471/; classtype:trojan-activity;sid:84201571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sixaknow/uac_bypass_/main/module_377498327498dcxvc32434.dll"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338451/; classtype:trojan-activity;sid:84201551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338443)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pistacchietto/win-python-backdoor/master/standalone_payload.exe"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338443/; classtype:trojan-activity;sid:84201543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty9989/f/zip/refs/heads/main"; depth:29; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3337794/; classtype:trojan-activity;sid:84200894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty9989/c/zip/refs/heads/main"; depth:29; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3337795/; classtype:trojan-activity;sid:84200895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty9989/u/zip/refs/heads/main"; depth:29; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3337796/; classtype:trojan-activity;sid:84200896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ty9989/i/zip/refs/heads/main"; depth:29; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3337797/; classtype:trojan-activity;sid:84200897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rahmoundll/kak/main/glew64.dll"; depth:31; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337035/; classtype:trojan-activity;sid:84200135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nkaslq1/ankrnl/refs/heads/main/alphatweaks.exe"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337026/; classtype:trojan-activity;sid:84200126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337032)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haa15/driver-shitty/main/kdmapper_release.exe"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337032/; classtype:trojan-activity;sid:84200132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v0lt/virtualdub2/releases/download/2.1.3/virtualdub2_v2.1.3.667_win32.7z"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337015/; classtype:trojan-activity;sid:84200115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337012)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgmb/update.exe"; depth:16; endswith; nocase; http.host; content:"update.cg100iii.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337012/; classtype:trojan-activity;sid:84200112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgpro/update.exe"; depth:17; endswith; nocase; http.host; content:"update.cg100iii.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337010/; classtype:trojan-activity;sid:84200110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skibidixelaina/wuselaina/raw/refs/heads/main/build.exe"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337004/; classtype:trojan-activity;sid:84200104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keygroup777-ransomware/downloader/refs/heads/main/taskmoder.exe"; depth:64; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336992/; classtype:trojan-activity;sid:84200092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336993)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/z-beam/movaflag/releases/download/1.0.2/mova.exe"; depth:49; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336993/; classtype:trojan-activity;sid:84200093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keygroup777-ransomware/downloader/refs/heads/main/cssgo.exe"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336990/; classtype:trojan-activity;sid:84200090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keygroup777-ransomware/downloader/raw/refs/heads/main/black.exe"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336983/; classtype:trojan-activity;sid:84200083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nikolaevich23/make-pkg-bat/master/setup.exe"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336077/; classtype:trojan-activity;sid:84199177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eirxne/valorant-axeprime/main/axeprime.dll"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336072/; classtype:trojan-activity;sid:84199172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stephenfewer/reflectivedllinjection/refs/heads/master/bin/reflective_dll.dll"; depth:77; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336068/; classtype:trojan-activity;sid:84199168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anessdev/talha/main/talha.dll"; depth:30; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336058/; classtype:trojan-activity;sid:84199158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sqrtzeroknowledge/xworm-trojan/zip/refs/heads/main"; depth:51; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336049/; classtype:trojan-activity;sid:84199149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335208)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/barrigudinha157/barrigudinha/master/rage.dll"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335208/; classtype:trojan-activity;sid:84198308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/infectsocks32_sql_antivirus.vmp.dll"; depth:36; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335175/; classtype:trojan-activity;sid:84198275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shadowforce2008_64_add.vmp.dll"; depth:31; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335174/; classtype:trojan-activity;sid:84198274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/infectsocks64_sql_antivirus.vmp.dll"; depth:36; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335173/; classtype:trojan-activity;sid:84198273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upm2008.exe"; depth:12; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335166/; classtype:trojan-activity;sid:84198266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ndisinstaller3.2.32.1.exe"; depth:26; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335156/; classtype:trojan-activity;sid:84198256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/2018-11/20181122103207926164.doc"; depth:38; endswith; nocase; http.host; content:"xww.bucea.edu.cn"; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335149/; classtype:trojan-activity;sid:84198249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/statement/ul397wfyb/"; depth:29; endswith; nocase; http.host; content:"www.reifenquick.de"; depth:18; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335154/; classtype:trojan-activity;sid:84198254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iatinfect2008_64.exe"; depth:21; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335147/; classtype:trojan-activity;sid:84198247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335141)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/winsetaccess64.exe"; depth:19; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335141/; classtype:trojan-activity;sid:84198241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/writedat.exe"; depth:13; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335135/; classtype:trojan-activity;sid:84198235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335136)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mport.exe"; depth:10; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335136/; classtype:trojan-activity;sid:84198236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335134)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iland.dat"; depth:10; endswith; nocase; http.host; content:"211.204.100.20"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335134/; classtype:trojan-activity;sid:84198234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/hl8-8w4cs-6325/"; depth:24; endswith; nocase; http.host; content:"reifenquick.de"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335132/; classtype:trojan-activity;sid:84198232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335119)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mytime/files/3.3.7.0/mytime.exe"; depth:32; endswith; nocase; http.host; content:"down.ruanmei.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335119/; classtype:trojan-activity;sid:84198219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cg70/update.exe"; depth:16; endswith; nocase; http.host; content:"update.cg100iii.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335118/; classtype:trojan-activity;sid:84198218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/closed_957176_mxqsdoj6a4iz/close_warehouse/ql55hnq09iyn6lm_334stxvw03wyv/"; depth:82; endswith; nocase; http.host; content:"www.reifenquick.de"; depth:18; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335096/; classtype:trojan-activity;sid:84198196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335074)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/_upload/article/files/90/f4/62d98f264ab0abc4a1f14a32607a/089c9dc1-8248-47b5-b35d-310cd70469b4.doc"; depth:98; endswith; nocase; http.host; content:"hhbs.hhu.edu.cn"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335074/; classtype:trojan-activity;sid:84198174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.dbg"; depth:9; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333897/; classtype:trojan-activity;sid:84196997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.sh4"; depth:9; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333896/; classtype:trojan-activity;sid:84196996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.x86_64"; depth:12; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333895/; classtype:trojan-activity;sid:84196995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/namblack666/zxqqw/refs/heads/main/main.exe"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333657/; classtype:trojan-activity;sid:84196757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/namblack666/zxqqw/refs/heads/main/main1.exe"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333658/; classtype:trojan-activity;sid:84196758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nam-black/moneyandbitch/refs/heads/main/main1.exe"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333656/; classtype:trojan-activity;sid:84196756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nam-black/moneyandbitch/raw/refs/heads/main/main1.exe"; depth:54; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333651/; classtype:trojan-activity;sid:84196751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/azertyuiopexe/fud-crypter/zip/refs/heads/main"; depth:46; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333522/; classtype:trojan-activity;sid:84196622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joh81/exploi01/main/document.zip"; depth:33; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333521/; classtype:trojan-activity;sid:84196621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.8"; depth:49; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333518/; classtype:trojan-activity;sid:84196618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.10"; depth:50; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333513/; classtype:trojan-activity;sid:84196613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.3"; depth:49; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333514/; classtype:trojan-activity;sid:84196614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hwangyounggul33/windows10/refs/heads/main/privacypolicy.exe"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333511/; classtype:trojan-activity;sid:84196611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/caocaocc/yacd/zip/refs/heads/gh-pages"; depth:38; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333509/; classtype:trojan-activity;sid:84196609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.9.2"; depth:51; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333510/; classtype:trojan-activity;sid:84196610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.11"; depth:50; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333508/; classtype:trojan-activity;sid:84196608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333499)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fericarr/newky/refs/heads/main/agentnov.exe"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333499/; classtype:trojan-activity;sid:84196599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cirosantilli/china-dictatorship/zip/refs/heads/master"; depth:54; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333502/; classtype:trojan-activity;sid:84196602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.zip/refs/tags/0.8.1"; depth:48; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333503/; classtype:trojan-activity;sid:84196603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333495)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.5"; depth:49; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333495/; classtype:trojan-activity;sid:84196595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.7"; depth:49; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333496/; classtype:trojan-activity;sid:84196596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333493)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d-7uble/invoke-phant0m/zip/refs/heads/master"; depth:45; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333493/; classtype:trojan-activity;sid:84196593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333494)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.zip/refs/tags/0.7.1"; depth:48; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333494/; classtype:trojan-activity;sid:84196594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/54n4l/mimikatzwindows/zip/refs/heads/master"; depth:44; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333489/; classtype:trojan-activity;sid:84196589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333485)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.9"; depth:49; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333485/; classtype:trojan-activity;sid:84196585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.9.1"; depth:51; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333482/; classtype:trojan-activity;sid:84196582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crowly-ai/hello-world/refs/heads/main/zubovlekciya.exe"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333481/; classtype:trojan-activity;sid:84196581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333470)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bloodhoundad/bloodhound/master/collectors/sharphound.exe"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333470/; classtype:trojan-activity;sid:84196570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/calendar/down/calendar/setup.exe"; depth:33; endswith; nocase; http.host; content:"ojang.pe.kr"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333458/; classtype:trojan-activity;sid:84196558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/calendar/down/calendar.exe"; depth:27; endswith; nocase; http.host; content:"ojang.pe.kr"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333457/; classtype:trojan-activity;sid:84196557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/calendar/down/jeditor/jeditor.exe"; depth:34; endswith; nocase; http.host; content:"ojang.pe.kr"; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333456/; classtype:trojan-activity;sid:84196556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ytisf/thezoo/refs/heads/master/malware/binaries/ransomware.wannacry/ransomware.wannacry.zip"; depth:92; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333439/; classtype:trojan-activity;sid:84196539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333435)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newlog/exploiting/refs/heads/master/training/windows/practical_malware_analysis/labs/chapter_1l/lab01-02.exe"; depth:109; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333435/; classtype:trojan-activity;sid:84196535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/master/donut.exe"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333369/; classtype:trojan-activity;sid:84196469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.mpsl"; depth:10; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333359/; classtype:trojan-activity;sid:84196459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.i686"; depth:10; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333355/; classtype:trojan-activity;sid:84196455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.x86"; depth:9; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333357/; classtype:trojan-activity;sid:84196457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333350)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/getrektboy724/sementara/raw/master/donut.exe"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333350/; classtype:trojan-activity;sid:84196450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.arm7"; depth:10; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333351/; classtype:trojan-activity;sid:84196451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333352)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.m68k"; depth:10; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333352/; classtype:trojan-activity;sid:84196452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.arm4"; depth:10; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333353/; classtype:trojan-activity;sid:84196453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333343)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.mips"; depth:10; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333343/; classtype:trojan-activity;sid:84196443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.arm6"; depth:10; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333322/; classtype:trojan-activity;sid:84196422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333321)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/17793058/lg246dre.txt"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333321/; classtype:trojan-activity;sid:84196421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333316)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.arm5"; depth:10; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333316/; classtype:trojan-activity;sid:84196416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aqua.ppc"; depth:9; endswith; nocase; http.host; content:"103.163.119.220"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333317/; classtype:trojan-activity;sid:84196417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/storage/files/9/%e2%98%85%ec%a0%9c%ed%92%88%ec%82%ac%ec%9a%a9%ec%a0%84%20%ed%95%84%ec%88%98%ec%85%8b%ed%8c%85%e2%98%85.zip"; depth:123; endswith; nocase; http.host; content:"xn--yh4bx88a.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332955/; classtype:trojan-activity;sid:84196055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332954)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/storage/files/9/%e2%ab%b8%ec%a0%9c%ed%92%88%ec%82%ac%ec%9a%a9%ec%a0%84%20%ed%95%84%ec%88%98%ec%85%8b%ed%8c%85%e2%ab%b7.zip"; depth:123; endswith; nocase; http.host; content:"xn--yh4bx88a.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332954/; classtype:trojan-activity;sid:84196054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332792)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noccenter/noccenter/refs/heads/main/huong%20dan%20xu%20ly%20tai%20khoan%20mail%20noi%20bo.zip"; depth:94; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332792/; classtype:trojan-activity;sid:84195892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noccenter/noccenter/raw/refs/heads/main/huong%20dan%20xu%20ly%20tai%20khoan%20mail%20noi%20bo.zip"; depth:98; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332783/; classtype:trojan-activity;sid:84195883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xevioo/xeviohub/main/critscript.exe"; depth:36; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332771/; classtype:trojan-activity;sid:84195871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mae-luadev/mae-tests/main/system.exe"; depth:37; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332764/; classtype:trojan-activity;sid:84195864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mae-luadev/mae-tests/raw/main/system.exe"; depth:41; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332757/; classtype:trojan-activity;sid:84195857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/presema/kersal/refs/heads/main/opyhjdase.exe"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331919/; classtype:trojan-activity;sid:84195019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/presema/kersal/refs/heads/main/popapoers.exe"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331862/; classtype:trojan-activity;sid:84194962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/presema/kersal/refs/heads/main/ljgksdtihd.exe"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331858/; classtype:trojan-activity;sid:84194958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331850)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/presema/kersal/refs/heads/main/pfntjejghjsdkr.exe"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331850/; classtype:trojan-activity;sid:84194950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/presema/kersal/refs/heads/main/vikings.exe"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331828/; classtype:trojan-activity;sid:84194928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/presema/kersal/refs/heads/main/bnkrigkawd.exe"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331826/; classtype:trojan-activity;sid:84194926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frenzy-zwaake/discordrat-2.0/main/client-built.exe"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331699/; classtype:trojan-activity;sid:84194799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fofit-rater/1/refs/heads/main/xclient.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331669/; classtype:trojan-activity;sid:84194769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efedursun125/xfakeplayers/master/xclient.exe"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331670/; classtype:trojan-activity;sid:84194770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v2/long-glade-33dc08/original//rump_img.jpeg"; depth:45; endswith; nocase; http.host; content:"cdn.pixelbin.io"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331664/; classtype:trojan-activity;sid:84194764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zonicleaks/yappadabbadoo/main/xclient.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331653/; classtype:trojan-activity;sid:84194753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jikoos/rrr/main/xclient.exe"; depth:28; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331648/; classtype:trojan-activity;sid:84194748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/debug2.ps1"; depth:30; endswith; nocase; http.host; content:"www.drgenov.com"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331649/; classtype:trojan-activity;sid:84194749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frenzy-zwaake/discordrat-2.0/deferred-metadata/main/client-built.exe"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331639/; classtype:trojan-activity;sid:84194739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joeljosephpajeet/testexe/refs/heads/main/xclient.exe"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331633/; classtype:trojan-activity;sid:84194733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/debug4.ps1"; depth:30; endswith; nocase; http.host; content:"www.drgenov.com"; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331626/; classtype:trojan-activity;sid:84194726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cheetz/nishang/master/gather/keylogger.ps1"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331630/; classtype:trojan-activity;sid:84194730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331588)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cookieskush/pip-package-template/master/client-built.exe"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331588/; classtype:trojan-activity;sid:84194688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efedursun125/xfakeplayers/refs/heads/master/xclient.exe"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331574/; classtype:trojan-activity;sid:84194674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cidadejunina/js/vendor/debug2.ps1"; depth:34; endswith; nocase; http.host; content:"transparenciacanaa.com.br"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331534/; classtype:trojan-activity;sid:84194634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331498)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1_-w5me4evtzbdzix_v_ymzdelazhrv5z"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331498/; classtype:trojan-activity;sid:84194598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331500)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1nskagzrswpttoue3wbrhdqpyzlyve4tg"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331500/; classtype:trojan-activity;sid:84194600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1o3zw7sodji4uk954kngkdyshyl37gozq"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331490/; classtype:trojan-activity;sid:84194590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3319641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"120.26.166.249"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_04; reference:url, urlhaus.abuse.ch/url/3319641/; classtype:trojan-activity;sid:84182741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3318309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khangdz1801/raw/refs/heads/main/sound.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_03; reference:url, urlhaus.abuse.ch/url/3318309/; classtype:trojan-activity;sid:84181409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3317713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m2/plugin2.dll"; depth:15; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_02; reference:url, urlhaus.abuse.ch/url/3317713/; classtype:trojan-activity;sid:84180813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3317712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m2/plugin1.dll"; depth:15; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_02; reference:url, urlhaus.abuse.ch/url/3317712/; classtype:trojan-activity;sid:84180812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3317707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/m2/plugin3.dll"; depth:15; endswith; nocase; http.host; content:"165.154.184.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_02; reference:url, urlhaus.abuse.ch/url/3317707/; classtype:trojan-activity;sid:84180807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3317497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/images/media/thing2"; depth:32; endswith; nocase; http.host; content:"divvanews.com"; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_02; reference:url, urlhaus.abuse.ch/url/3317497/; classtype:trojan-activity;sid:84180597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/help.scr"; depth:9; endswith; nocase; http.host; content:"61.183.16.127"; depth:13; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308898/; classtype:trojan-activity;sid:84171998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"218.155.74.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308894/; classtype:trojan-activity;sid:84171994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"159.250.122.151"; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308882/; classtype:trojan-activity;sid:84171982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"141.155.36.213"; depth:14; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308875/; classtype:trojan-activity;sid:84171975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308847)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"5.26.174.234"; depth:12; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308847/; classtype:trojan-activity;sid:84171947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1idr9p3dgxkblhu7h4jckclzmtlibwsiw"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308798/; classtype:trojan-activity;sid:84171898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308797)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1c2pnucvma1shu90mnauhef6shildth-s"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308797/; classtype:trojan-activity;sid:84171897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3303817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1jbzzntbk1kuszoofww7hsqfdh066ontf"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_25; reference:url, urlhaus.abuse.ch/url/3303817/; classtype:trojan-activity;sid:84166917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3303818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1hkvynldkcbdd50_bsw3s9tk5elbduxtg"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_25; reference:url, urlhaus.abuse.ch/url/3303818/; classtype:trojan-activity;sid:84166918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/lnk/refs/heads/main/y.png"; depth:35; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300881/; classtype:trojan-activity;sid:84163981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/dcm/refs/heads/main/document.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300394/; classtype:trojan-activity;sid:84163494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/steamer/malwerjobs/refs/heads/master/test.xll"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300382/; classtype:trojan-activity;sid:84163482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/lnk/refs/heads/main/ud.bat"; depth:36; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300387/; classtype:trojan-activity;sid:84163487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/lnk/refs/heads/main/t.png"; depth:35; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300377/; classtype:trojan-activity;sid:84163477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/steamer/malwerjobs/refs/heads/master/template.dotm"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300378/; classtype:trojan-activity;sid:84163478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/steamer/malwerjobs/refs/heads/master/doadmin.png"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300374/; classtype:trojan-activity;sid:84163474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/steamer/malwerjobs/refs/heads/master/steamerx.exe"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300375/; classtype:trojan-activity;sid:84163475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/steamer/malwerjobs/refs/heads/master/justpoc.exe"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300376/; classtype:trojan-activity;sid:84163476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/lnk/refs/heads/main/u.xls"; depth:35; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300371/; classtype:trojan-activity;sid:84163471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/steamer/malwerjobs/refs/heads/master/scriptlet"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300372/; classtype:trojan-activity;sid:84163472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/es.hta"; depth:7; endswith; nocase; http.host; content:"pub-cdd0dd27ae6a4aee9841d397e0496374.r2.dev"; depth:43; isdataat:!1,relative; metadata:created_at 2024_11_22; reference:url, urlhaus.abuse.ch/url/3300068/; classtype:trojan-activity;sid:84163168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saked018/rivada/refs/heads/main/mis_file_9888123_received_xsls.zip"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298233/; classtype:trojan-activity;sid:84161333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298219)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/saked018/rivada/raw/refs/heads/main/mis_file_9888123_received_xsls.zip"; depth:71; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298219/; classtype:trojan-activity;sid:84161319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298207)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/dcm/raw/refs/heads/main/document.zip"; depth:46; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298207/; classtype:trojan-activity;sid:84161307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/ud/raw/refs/heads/main/ud.bat"; depth:39; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298202/; classtype:trojan-activity;sid:84161302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298205)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/lnk/raw/refs/heads/main/u.xls"; depth:39; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298205/; classtype:trojan-activity;sid:84161305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298201)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rouki555/lnk/raw/refs/heads/main/ud.bat"; depth:40; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298201/; classtype:trojan-activity;sid:84161301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3296209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crm/exe/update.exe"; depth:19; endswith; nocase; http.host; content:"www.zhikey.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_11_19; reference:url, urlhaus.abuse.ch/url/3296209/; classtype:trojan-activity;sid:84159309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3294913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ledshow1.exe"; depth:13; endswith; nocase; http.host; content:"101.200.220.118"; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_18; reference:url, urlhaus.abuse.ch/url/3294913/; classtype:trojan-activity;sid:84158013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3294809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/configureregistrysettings.ps1"; depth:30; endswith; nocase; http.host; content:"103.247.164.242"; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_18; reference:url, urlhaus.abuse.ch/url/3294809/; classtype:trojan-activity;sid:84157909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3294619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/noureddine-nt9/rgsdr/raw/refs/heads/main/cheet.exe"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_18; reference:url, urlhaus.abuse.ch/url/3294619/; classtype:trojan-activity;sid:84157719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3292014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n/tui/mininews/mininewsplus/3.0.0.26165/mininewsplus-2.exe"; depth:59; endswith; nocase; http.host; content:"mininews.kpzip.com"; depth:18; isdataat:!1,relative; metadata:created_at 2024_11_15; reference:url, urlhaus.abuse.ch/url/3292014/; classtype:trojan-activity;sid:84155114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3291869)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/stories/guides/guide2018.exe"; depth:36; endswith; nocase; http.host; content:"dcwblida.dz"; depth:11; isdataat:!1,relative; metadata:created_at 2024_11_15; reference:url, urlhaus.abuse.ch/url/3291869/; classtype:trojan-activity;sid:84154969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3291785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sample_photo.js"; depth:16; endswith; nocase; http.host; content:"ikincielesyaciankara.com.tr"; depth:27; isdataat:!1,relative; metadata:created_at 2024_11_15; reference:url, urlhaus.abuse.ch/url/3291785/; classtype:trojan-activity;sid:84154885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3289875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r00ts3c/ddos-rootsec/refs/heads/master/ddos%20scripts/l4/udp/10gbpsudp.py"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_14; reference:url, urlhaus.abuse.ch/url/3289875/; classtype:trojan-activity;sid:84152975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3289466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.255.216.26"; depth:13; isdataat:!1,relative; metadata:created_at 2024_11_13; reference:url, urlhaus.abuse.ch/url/3289466/; classtype:trojan-activity;sid:84152566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3287640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.171.188.254"; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_12; reference:url, urlhaus.abuse.ch/url/3287640/; classtype:trojan-activity;sid:84150740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"154.73.64.24"; depth:12; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286828/; classtype:trojan-activity;sid:84149928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.77.228.166"; depth:14; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286821/; classtype:trojan-activity;sid:84149921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kzxiaopeng2/kuaizip_setup_-808202126_xiaopeng2_001.exe"; depth:55; endswith; nocase; http.host; content:"d.kpzip.com"; depth:11; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286518/; classtype:trojan-activity;sid:84149618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haozip.convertimg.exe"; depth:22; endswith; nocase; http.host; content:"download.haozip.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286513/; classtype:trojan-activity;sid:84149613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.70.244.17"; depth:13; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286371/; classtype:trojan-activity;sid:84149471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286067)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/erez-goldberg/rust-reverse-shell/main/shellcode.bin"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286067/; classtype:trojan-activity;sid:84149167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3285570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.247.218.186"; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_10; reference:url, urlhaus.abuse.ch/url/3285570/; classtype:trojan-activity;sid:84148670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3281714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3cur3th1ssh1t/creds/master/obfuscatedps/dccuac.ps1"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_08; reference:url, urlhaus.abuse.ch/url/3281714/; classtype:trojan-activity;sid:84144814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3281085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/barrigudinha157/barrigudinha/raw/master/rage.dll"; depth:49; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_07; reference:url, urlhaus.abuse.ch/url/3281085/; classtype:trojan-activity;sid:84144185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3280680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fiies/stormfn-launcher/raw/refs/heads/main/stormfn-launcher.zip"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_07; reference:url, urlhaus.abuse.ch/url/3280680/; classtype:trojan-activity;sid:84143780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3279353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xavieprowel/crispy-palm-tree/releases/download/1/3e3ev3.exe"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3279353/; classtype:trojan-activity;sid:84142453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txdown_disk/%e8%bd%af%e4%bb%b6%e4%bd%bf%e7%94%a8/%e7%bc%ba%e5%a4%b1%e4%b8%8b%e8%bd%bd/plugin.dll"; depth:97; endswith; nocase; http.host; content:"disk.accord1key.cn"; depth:18; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278669/; classtype:trojan-activity;sid:84141769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ciphershld/ms-p-1a/master/setup%20ms%20p-1a.exe"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278573/; classtype:trojan-activity;sid:84141673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/minecradt/regdelete/readme-edits/hell9o.exe"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278576/; classtype:trojan-activity;sid:84141676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/openpeach/dotnetfx_cleanup_tool/refs/heads/master/cleanup_tool.exe"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278567/; classtype:trojan-activity;sid:84141667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278362)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1las2cmd3reobg45qhkqhawi90h4_u0kd"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278362/; classtype:trojan-activity;sid:84141462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=17hv9-3t2ilikbmcfql2z66ipd72x4mz7"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278361/; classtype:trojan-activity;sid:84141461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3276956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mig"; depth:4; endswith; nocase; http.host; content:"216.201.80.197"; depth:14; isdataat:!1,relative; metadata:created_at 2024_11_05; reference:url, urlhaus.abuse.ch/url/3276956/; classtype:trojan-activity;sid:84140056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3276896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/loistupidpet/sfdawsdawdaw/main/serials_checker.exe"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_05; reference:url, urlhaus.abuse.ch/url/3276896/; classtype:trojan-activity;sid:84139996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275669)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1kc4fdseohzqymz2x0ncqswph66uxdb1z"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275669/; classtype:trojan-activity;sid:84138769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1u_rahqbks7vd7qqc6wx3gxnjxtfqrzbp"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275667/; classtype:trojan-activity;sid:84138767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1-8qpzgr4-iis53p1-kr2-o6prrjmnksk"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275658/; classtype:trojan-activity;sid:84138758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275656)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ubqrhziusgl-cn_nie2_udj4qi6qrqsw"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275656/; classtype:trojan-activity;sid:84138756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ikoxnnlvglh6jhnfqkrsihss_p2dqkyp"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275240/; classtype:trojan-activity;sid:84138340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1r7oi2jekx0ks1wqpt0ms3_kqvukzy3dv"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275241/; classtype:trojan-activity;sid:84138341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1gmzqsemymffka4lve0jkwa06sklk7xhu"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275242/; classtype:trojan-activity;sid:84138342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3274064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/borisizdabezt/exitlag-hwid-spoofer/main/drv64.dll"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_03; reference:url, urlhaus.abuse.ch/url/3274064/; classtype:trojan-activity;sid:84137164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3274049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realstrings/lydian-spoofer/raw/main/spoofy.sys"; depth:47; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_03; reference:url, urlhaus.abuse.ch/url/3274049/; classtype:trojan-activity;sid:84137149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3274047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realstrings/lydian-spoofer/refs/heads/main/spoofy.sys"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_03; reference:url, urlhaus.abuse.ch/url/3274047/; classtype:trojan-activity;sid:84137147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3274048)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realstrings/lydian-spoofer/raw/refs/heads/main/spoofy.sys"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_03; reference:url, urlhaus.abuse.ch/url/3274048/; classtype:trojan-activity;sid:84137148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3272092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ordogos2/g575/releases/download/download/setup.7.0.zip"; depth:55; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3272092/; classtype:trojan-activity;sid:84135192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271922)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leakerbydragon1/leakerbydragon1/main/injector.exe"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271922/; classtype:trojan-activity;sid:84135022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leakerbydragon1/leakerbydragon1/main/injectorold.exe"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271923/; classtype:trojan-activity;sid:84135023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271924)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leakerbydragon1/leakerbydragon1/main/driver.sys"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271924/; classtype:trojan-activity;sid:84135024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271925)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leakerbydragon1/leakerbydragon1/main/loader.exe"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271925/; classtype:trojan-activity;sid:84135025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leakerbydragon1/leakerbydragon1/main/ogfn%20updater.exe"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271919/; classtype:trojan-activity;sid:84135019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leakerbydragon1/leakerbydragon1/main/pclient.exe"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271920/; classtype:trojan-activity;sid:84135020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/leakerbydragon1/leakerbydragon1/main/kdmapper_release.exe"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271921/; classtype:trojan-activity;sid:84135021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svchost.exe"; depth:12; endswith; nocase; http.host; content:"123.ywxww.net"; depth:13; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271663/; classtype:trojan-activity;sid:84134763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/undertalanted/mod/refs/heads/main/svchost.exe"; depth:46; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271634/; classtype:trojan-activity;sid:84134734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdifru877234/ilu123g5/main/svchost.exe"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271624/; classtype:trojan-activity;sid:84134724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/regolx1/hadb/refs/heads/main/svchost.exe"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271617/; classtype:trojan-activity;sid:84134717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271614)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chokopie333/doom/main/svchost.exe"; depth:34; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271614/; classtype:trojan-activity;sid:84134714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271612)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artem674118/erterytry/main/svchost.exe"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271612/; classtype:trojan-activity;sid:84134712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271609)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/morgantaraum/automatic-octo-barnacle/refs/heads/main/svchost.exe"; depth:65; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271609/; classtype:trojan-activity;sid:84134709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/media/furystorage/api/main/svchost.exe"; depth:39; endswith; nocase; http.host; content:"media.githubusercontent.com"; depth:27; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271610/; classtype:trojan-activity;sid:84134710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zodiac1616/test/refs/heads/main/svchost.exe"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271611/; classtype:trojan-activity;sid:84134711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sdifru877234/ilu123g5/raw/main/svchost.exe"; depth:43; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271605/; classtype:trojan-activity;sid:84134705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271594)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artem674118/erterytry/raw/main/svchost.exe"; depth:43; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271594/; classtype:trojan-activity;sid:84134694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chokopie333/doom/raw/main/svchost.exe"; depth:38; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271586/; classtype:trojan-activity;sid:84134686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/morgantaraum/automatic-octo-barnacle/raw/refs/heads/main/svchost.exe"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271587/; classtype:trojan-activity;sid:84134687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271590)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zodiac1616/test/raw/refs/heads/main/svchost.exe"; depth:48; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271590/; classtype:trojan-activity;sid:84134690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271366)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zzrevva1/osu-maple/refs/heads/main/extremeinjector.exe"; depth:55; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271366/; classtype:trojan-activity;sid:84134466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zzrevva1/osu-maple/raw/refs/heads/main/extremeinjector.exe"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271369/; classtype:trojan-activity;sid:84134469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/novocrm/static/winring0x64.sys"; depth:31; endswith; nocase; http.host; content:"118.189.172.141"; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270196/; classtype:trojan-activity;sid:84133296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270195)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ggassistant/update/2.3.11.29/tool/winring0x64.sys|3f|skq=1701042218"; depth:68; endswith; nocase; http.host; content:"shqdown.ggzuhao.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270195/; classtype:trojan-activity;sid:84133295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270193)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miguel-b-p/..../raw/main/winring0x64.sys"; depth:41; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270193/; classtype:trojan-activity;sid:84133293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/silenthashik/winring/raw/main/winring0x64.sys"; depth:46; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270185/; classtype:trojan-activity;sid:84133285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270186)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hak333444/xmrig/raw/main/winring0x64.sys"; depth:41; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270186/; classtype:trojan-activity;sid:84133286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/blob/master/bin/winring0/winring0x64.sys|3f|raw=true"; depth:65; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270188/; classtype:trojan-activity;sid:84133288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/so251/olaquerida/releases/download/1releasae/winring0x64.sys"; depth:61; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270189/; classtype:trojan-activity;sid:84133289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jsjsjsc79/advsd/raw/main/winring0x64.sys"; depth:41; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270191/; classtype:trojan-activity;sid:84133291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270192)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stickmengamer/idk/raw/main/winring0x64.sys"; depth:43; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270192/; classtype:trojan-activity;sid:84133292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270183)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sopranotech/dimeo/main/winring0x64.sys"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270183/; classtype:trojan-activity;sid:84133283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abrissyy/min/main/winring0x64.sys"; depth:34; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270184/; classtype:trojan-activity;sid:84133284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3269715)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sqrtzeroknowledge/xworm-trojan/archive/refs/heads/main.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3269715/; classtype:trojan-activity;sid:84132815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3265959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ygqwpvxadhjsxskr3u3tdw2u5dnzv0pp"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_30; reference:url, urlhaus.abuse.ch/url/3265959/; classtype:trojan-activity;sid:84129059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3265958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1uzjwtbh4hcs9i060hwf08hrnymnodugn"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_30; reference:url, urlhaus.abuse.ch/url/3265958/; classtype:trojan-activity;sid:84129058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3258033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ijeuwaesika/nna/refs/heads/main/ifiinms.txt"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3258033/; classtype:trojan-activity;sid:84121133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/net/net.xsl"; depth:12; endswith; nocase; http.host; content:"cat.xiaoshabi.nl"; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257471/; classtype:trojan-activity;sid:84120571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257473)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/javaw2/net/net.xsl"; depth:19; endswith; nocase; http.host; content:"sec.xiaoshabi.nl"; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257473/; classtype:trojan-activity;sid:84120573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/netstat.ps1"; depth:12; endswith; nocase; http.host; content:"cat.dashabi.in"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257450/; classtype:trojan-activity;sid:84120550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257451)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/javaw2/winring0x64.sys"; depth:23; endswith; nocase; http.host; content:"sec.dashabi.in"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257451/; classtype:trojan-activity;sid:84120551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257457)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/javaw2/javaw"; depth:13; endswith; nocase; http.host; content:"sec.dashabi.in"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257457/; classtype:trojan-activity;sid:84120557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/javaw2/instance.ps1"; depth:20; endswith; nocase; http.host; content:"sec.xiaojiji.nl"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257464/; classtype:trojan-activity;sid:84120564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/netstat.ps1"; depth:12; endswith; nocase; http.host; content:"cat.xiaojiji.nl"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257465/; classtype:trojan-activity;sid:84120565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3254228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kdot227/somalifuscator/archive/refs/heads/main.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_26; reference:url, urlhaus.abuse.ch/url/3254228/; classtype:trojan-activity;sid:84117328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3254222)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/robloxdev1223/requirements/raw/main/requirements.exe"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_26; reference:url, urlhaus.abuse.ch/url/3254222/; classtype:trojan-activity;sid:84117322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3252743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomemb.exe"; depth:11; endswith; nocase; http.host; content:"8.217.62.104"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_25; reference:url, urlhaus.abuse.ch/url/3252743/; classtype:trojan-activity;sid:84115843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3252742)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tom.ox"; depth:7; endswith; nocase; http.host; content:"8.217.62.104"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_25; reference:url, urlhaus.abuse.ch/url/3252742/; classtype:trojan-activity;sid:84115842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3252717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pootdigitsix.bin"; depth:17; endswith; nocase; http.host; content:"8.217.62.104"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_25; reference:url, urlhaus.abuse.ch/url/3252717/; classtype:trojan-activity;sid:84115817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3252709)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/libemb.dll"; depth:11; endswith; nocase; http.host; content:"8.217.62.104"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_25; reference:url, urlhaus.abuse.ch/url/3252709/; classtype:trojan-activity;sid:84115809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3252630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/17267811/stm.txt"; depth:40; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_25; reference:url, urlhaus.abuse.ch/url/3252630/; classtype:trojan-activity;sid:84115730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3249739)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/img_up/shop_pds/nicehana/client.exe"; depth:36; endswith; nocase; http.host; content:"www.xn--on3b15m2lco2u.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_23; reference:url, urlhaus.abuse.ch/url/3249739/; classtype:trojan-activity;sid:84112839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3249735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/client.exe"; depth:11; endswith; nocase; http.host; content:"119.193.158.215"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_23; reference:url, urlhaus.abuse.ch/url/3249735/; classtype:trojan-activity;sid:84112835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3249675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/quasar/quasar/releases/download/v1.4.1/quasar.v1.4.1.zip"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_23; reference:url, urlhaus.abuse.ch/url/3249675/; classtype:trojan-activity;sid:84112775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3249662)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/refs/heads/master/rat/njrat.exe"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_23; reference:url, urlhaus.abuse.ch/url/3249662/; classtype:trojan-activity;sid:84112762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3246018)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mestalic/site/refs/heads/main/file.exe"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3246018/; classtype:trojan-activity;sid:84109118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"185.152.219.150"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245733/; classtype:trojan-activity;sid:84108833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vz.txt"; depth:7; endswith; nocase; http.host; content:"51.79.124.111"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245732/; classtype:trojan-activity;sid:84108832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chinese.txt"; depth:12; endswith; nocase; http.host; content:"202.129.16.172"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245730/; classtype:trojan-activity;sid:84108830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hs.exe"; depth:7; endswith; nocase; http.host; content:"146.0.42.82"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245463/; classtype:trojan-activity;sid:84108563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kg.exe"; depth:7; endswith; nocase; http.host; content:"146.0.42.82"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245459/; classtype:trojan-activity;sid:84108559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keygen.exe"; depth:11; endswith; nocase; http.host; content:"146.0.42.82"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245458/; classtype:trojan-activity;sid:84108558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3243086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update/data/update.exe"; depth:23; endswith; nocase; http.host; content:"114.55.106.136"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3243086/; classtype:trojan-activity;sid:84106186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3243082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sysupdate/ckbgd/2.3.0624.zip"; depth:29; endswith; nocase; http.host; content:"8.131.63.6"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3243082/; classtype:trojan-activity;sid:84106182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3243077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sysupdate/ckbgd/2.3.0703.zip"; depth:29; endswith; nocase; http.host; content:"8.131.63.6"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3243077/; classtype:trojan-activity;sid:84106177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3242983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/flowseal/zapret-discord-youtube/releases/download/1.1.1/zapret-discord-youtube-1.1.1.rar"; depth:89; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3242983/; classtype:trojan-activity;sid:84106083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3242769)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/solr.sh"; depth:13; endswith; nocase; http.host; content:"119.192.128.163"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3242769/; classtype:trojan-activity;sid:84105869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3242663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack0832.zip"; depth:26; endswith; nocase; http.host; content:"cd.textfiles.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3242663/; classtype:trojan-activity;sid:84105763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3242642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rishabhkumardeveloper/malware_analysis_using_ml/main/wildfire-test-pe-file.exe"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3242642/; classtype:trojan-activity;sid:84105742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mori-miyako/discord-token-generator/zip/refs/heads/main"; depth:56; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241764/; classtype:trojan-activity;sid:84104864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scode18/all-tweaker/main/tweaks.7z"; depth:35; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241765/; classtype:trojan-activity;sid:84104865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/intergate0/none/main/main.exe"; depth:30; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241756/; classtype:trojan-activity;sid:84104856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241637)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s107000665/c1/master/1223.exe"; depth:30; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241637/; classtype:trojan-activity;sid:84104737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iciamyplant/ctf/master/plantrojan.exe"; depth:38; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241638/; classtype:trojan-activity;sid:84104738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fengjixuchui/cve-2022-26810/main/shellcode.bin"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241639/; classtype:trojan-activity;sid:84104739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/killbillpribil/world-of-tanks/master/world%20of%20tanks.exe"; depth:60; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241640/; classtype:trojan-activity;sid:84104740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mach1el/htb-scripts/master/exploit-fuse/shell.exe"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241641/; classtype:trojan-activity;sid:84104741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/khr0x40sh/whitelistevasion/master/installutil/script.exe"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241642/; classtype:trojan-activity;sid:84104742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241635)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/msf.exe"; depth:8; endswith; nocase; http.host; content:"qiniuyunxz.yxflzs.com"; depth:21; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241635/; classtype:trojan-activity;sid:84104735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c5hackr/phantom/main/phantom/resources/donut.exe"; depth:49; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241559/; classtype:trojan-activity;sid:84104659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241127)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/justincoding3/slumfun/main/obfuscated.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241127/; classtype:trojan-activity;sid:84104227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241126)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/r00t-3xp10it/redpill/main/utils/compiled.exe"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241126/; classtype:trojan-activity;sid:84104226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241125)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms14-068/ms14-068.exe"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241125/; classtype:trojan-activity;sid:84104225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241123)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prowindows365/hailhydra/refs/heads/main/hailhydra.exe"; depth:54; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241123/; classtype:trojan-activity;sid:84104223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/neo23x0/signature-base/archive/master.zip"; depth:42; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241055/; classtype:trojan-activity;sid:84104155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sad-dust/death/main/stealinfo.exe"; depth:34; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240999/; classtype:trojan-activity;sid:84104099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/redcanaryco/atomic-red-team/master/atomics/t1204.002/bin/test10.lnk"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240819/; classtype:trojan-activity;sid:84103919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cuckoobox/cuckoo/archive/master.zip"; depth:36; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240817/; classtype:trojan-activity;sid:84103917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/haxork8880/files/main/windowssync.txt.zip"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240813/; classtype:trojan-activity;sid:84103913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crjtpp/tpplab_public/main/poc-sample-lnk.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240814/; classtype:trojan-activity;sid:84103914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackerx237/miner/main/my-files.lnk"; depth:35; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240812/; classtype:trojan-activity;sid:84103912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scode18/all-tweaker/releases/download/beta_v0.6/all.tweaker.beta.v0.6.7z"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240811/; classtype:trojan-activity;sid:84103911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scode18/all-tweaker/raw/main/tweaks.7z"; depth:39; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240810/; classtype:trojan-activity;sid:84103910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240720)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dqwr1q23rwdfr/xxx/releases/download/xxx/vital.zip"; depth:50; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240720/; classtype:trojan-activity;sid:84103820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240639)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mohdjulaya09/code-sparrow-crypter-2.0-private-crack-leak/releases/download/%23crypter/codesparrow.crypter.2.0.crack.rar"; depth:120; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240639/; classtype:trojan-activity;sid:84103739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3239707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/demon.x64.bin"; depth:14; endswith; nocase; http.host; content:"8.138.96.41"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_17; reference:url, urlhaus.abuse.ch/url/3239707/; classtype:trojan-activity;sid:84102807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3238111)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/resources/js/info2r.txt"; depth:24; endswith; nocase; http.host; content:"188.81.134.196"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3238111/; classtype:trojan-activity;sid:84101211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3238073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ff245185/payload/main/fast%20download.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3238073/; classtype:trojan-activity;sid:84101173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3238061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/grozniy1/folder/main/444.exe"; depth:29; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3238061/; classtype:trojan-activity;sid:84101161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/da2dalus/the-malware-repo/blob/master/rat/njrat.exe|3f|raw=true"; depth:64; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237975/; classtype:trojan-activity;sid:84101075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5556.rar"; depth:9; endswith; nocase; http.host; content:"188.212.158.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237976/; classtype:trojan-activity;sid:84101076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joh81/exploi01/zip/refs/heads/main"; depth:35; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237861/; classtype:trojan-activity;sid:84100961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/steve824/a/zip/refs/heads/main"; depth:31; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237810/; classtype:trojan-activity;sid:84100910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/thebb5th/123/zip/refs/heads/main"; depth:33; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237737/; classtype:trojan-activity;sid:84100837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1_suia0iczdw2reew1f9hgunezxcwv52d"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237465/; classtype:trojan-activity;sid:84100565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1_3ozdjl5puad8qn3tipydynn5j7l13el"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237464/; classtype:trojan-activity;sid:84100564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/center.exe"; depth:11; endswith; nocase; http.host; content:"119.193.158.215"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236597/; classtype:trojan-activity;sid:84099697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/kedadecoder.zip"; depth:25; endswith; nocase; http.host; content:"153.37.77.156"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236587/; classtype:trojan-activity;sid:84099687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/kedadecoder.zip"; depth:25; endswith; nocase; http.host; content:"116.136.142.2"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236559/; classtype:trojan-activity;sid:84099659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236453)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3cur3th1ssh1t/creds/master/powershellscripts/invoke-petitpotam.ps1"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236453/; classtype:trojan-activity;sid:84099553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/x.rar"; depth:11; endswith; nocase; http.host; content:"119.192.128.163"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236450/; classtype:trojan-activity;sid:84099550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/xwgl/xw_xxgl.exe"; depth:22; endswith; nocase; http.host; content:"data.yhydl.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236324/; classtype:trojan-activity;sid:84099424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/xw_setup.exe"; depth:18; endswith; nocase; http.host; content:"data.yhydl.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236322/; classtype:trojan-activity;sid:84099422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/yhy_setup.exe"; depth:19; endswith; nocase; http.host; content:"data.yhydl.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236323/; classtype:trojan-activity;sid:84099423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/products/4001/updates/efatura/efatura.exe"; depth:42; endswith; nocase; http.host; content:"elisans.novayonetim.com"; depth:23; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236318/; classtype:trojan-activity;sid:84099418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/services/identification/server/gtptoolsdownloadhandler.ashx|3f|filename=gtp_6_browserplugin_setup.exe"; depth:102; endswith; nocase; http.host; content:"hnjgdl.geps.glodon.com"; depth:22; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236240/; classtype:trojan-activity;sid:84099340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/natgo.exe"; depth:10; endswith; nocase; http.host; content:"dl.natgo.cn"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236237/; classtype:trojan-activity;sid:84099337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/17267811/stm.txt"; depth:40; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236154/; classtype:trojan-activity;sid:84099254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chainguard-dev/bincapz/archive/refs/tags/v0.5.0.zip"; depth:52; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3235523/; classtype:trojan-activity;sid:84098623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/playmcbkuwu/vape/releases/download/stable/vape.v4.10.from.duckysolucky.zip"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3235522/; classtype:trojan-activity;sid:84098622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235514)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/barrigudinha157/barrigudinha/raw/master/rage.dll"; depth:49; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3235514/; classtype:trojan-activity;sid:84098614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meckazin/chromekatz/releases/download/0.4.7/chromekatzbofs.zip"; depth:63; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3235513/; classtype:trojan-activity;sid:84098613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235094)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xsh/update.exe"; depth:15; endswith; nocase; http.host; content:"101.126.11.168"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_14; reference:url, urlhaus.abuse.ch/url/3235094/; classtype:trojan-activity;sid:84098194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3234859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/petikvx/lockbit-black-builder/main/lockbit30/builder.exe"; depth:57; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_14; reference:url, urlhaus.abuse.ch/url/3234859/; classtype:trojan-activity;sid:84097959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3234858)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennessene/lockbit/refs/heads/main/builder.exe"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_14; reference:url, urlhaus.abuse.ch/url/3234858/; classtype:trojan-activity;sid:84097958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3231796)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/16737801/wave.zip|3f|"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_12; reference:url, urlhaus.abuse.ch/url/3231796/; classtype:trojan-activity;sid:84094896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3231794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/user-attachments/files/16419615/solara.zip"; depth:43; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_12; reference:url, urlhaus.abuse.ch/url/3231794/; classtype:trojan-activity;sid:84094894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3229631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kamilniftaliev/cryptoview/zip/refs/heads/main"; depth:46; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_11; reference:url, urlhaus.abuse.ch/url/3229631/; classtype:trojan-activity;sid:84092731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3228667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/winassist/login/login.7z"; depth:25; endswith; nocase; http.host; content:"win.down.55kantu.com"; depth:20; isdataat:!1,relative; metadata:created_at 2024_10_10; reference:url, urlhaus.abuse.ch/url/3228667/; classtype:trojan-activity;sid:84091767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3226239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.22.0/xmrig-6.22.0-linux-static-x64.tar.gz"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_09; reference:url, urlhaus.abuse.ch/url/3226239/; classtype:trojan-activity;sid:84089339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218033)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"109.207.216.197"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218033/; classtype:trojan-activity;sid:84081133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218030)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"86.106.101.159"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218030/; classtype:trojan-activity;sid:84081130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"212.3.211.157"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218022/; classtype:trojan-activity;sid:84081122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"117.247.101.217"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218007/; classtype:trojan-activity;sid:84081107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"109.207.217.114"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218009/; classtype:trojan-activity;sid:84081109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"166.147.146.187"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218011/; classtype:trojan-activity;sid:84081111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218001)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"213.96.13.100"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218001/; classtype:trojan-activity;sid:84081101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.205.197"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217787/; classtype:trojan-activity;sid:84080887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"85.130.160.219"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217802/; classtype:trojan-activity;sid:84080902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"89.35.233.220"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217784/; classtype:trojan-activity;sid:84080884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217775)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.191.89.122"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217775/; classtype:trojan-activity;sid:84080875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"89.35.233.220"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217753/; classtype:trojan-activity;sid:84080853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"86.106.155.155"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217757/; classtype:trojan-activity;sid:84080857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"87.97.161.106"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217760/; classtype:trojan-activity;sid:84080860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"80.28.228.106"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217750/; classtype:trojan-activity;sid:84080850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217745)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"87.97.161.106"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217745/; classtype:trojan-activity;sid:84080845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"92.203.169.41"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217740/; classtype:trojan-activity;sid:84080840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217717)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"87.97.161.106"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217717/; classtype:trojan-activity;sid:84080817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217719)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"89.35.233.220"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217719/; classtype:trojan-activity;sid:84080819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"87.97.161.106"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217729/; classtype:trojan-activity;sid:84080829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"213.96.13.100"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217689/; classtype:trojan-activity;sid:84080789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.43.16.137"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217684/; classtype:trojan-activity;sid:84080784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.45.183.125"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217681/; classtype:trojan-activity;sid:84080781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217682)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.45.183.125"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217682/; classtype:trojan-activity;sid:84080782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217665)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"213.96.13.100"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217665/; classtype:trojan-activity;sid:84080765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217674)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.191.89.120"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217674/; classtype:trojan-activity;sid:84080774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217638)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"14.161.6.225"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217638/; classtype:trojan-activity;sid:84080738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.205.197"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217625/; classtype:trojan-activity;sid:84080725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217621)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.205.197"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217621/; classtype:trojan-activity;sid:84080721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217618)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.205.197"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217618/; classtype:trojan-activity;sid:84080718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"118.212.35.175"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217562/; classtype:trojan-activity;sid:84080662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/123.ps1"; depth:8; endswith; nocase; http.host; content:"103.247.164.242"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217557/; classtype:trojan-activity;sid:84080657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217454)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"99.118.215.24"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217454/; classtype:trojan-activity;sid:84080554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"118.212.35.175"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217426/; classtype:trojan-activity;sid:84080526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"37.252.66.188"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217131/; classtype:trojan-activity;sid:84080231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217098)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"77.238.209.82"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217098/; classtype:trojan-activity;sid:84080198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"81.16.249.96"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217109/; classtype:trojan-activity;sid:84080209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217090)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"109.108.84.121"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217090/; classtype:trojan-activity;sid:84080190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"94.251.5.51"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217091/; classtype:trojan-activity;sid:84080191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217073)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"197.159.1.58"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217073/; classtype:trojan-activity;sid:84080173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217046)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"167.250.193.253"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217046/; classtype:trojan-activity;sid:84080146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217058)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"193.106.58.174"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217058/; classtype:trojan-activity;sid:84080158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"36.88.180.115"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217059/; classtype:trojan-activity;sid:84080159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217061)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"118.71.250.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217061/; classtype:trojan-activity;sid:84080161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217062)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"202.78.201.3"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217062/; classtype:trojan-activity;sid:84080162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217063)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"181.49.47.190"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217063/; classtype:trojan-activity;sid:84080163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"124.194.46.204"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217064/; classtype:trojan-activity;sid:84080164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"196.41.63.178"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217044/; classtype:trojan-activity;sid:84080144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"58.145.168.170"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217009/; classtype:trojan-activity;sid:84080109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"202.148.18.220"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217020/; classtype:trojan-activity;sid:84080120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"202.5.50.108"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217003/; classtype:trojan-activity;sid:84080103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"182.253.115.156"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217004/; classtype:trojan-activity;sid:84080104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"190.113.124.155"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216967/; classtype:trojan-activity;sid:84080067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"36.92.68.241"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216971/; classtype:trojan-activity;sid:84080071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"37.255.217.87"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216977/; classtype:trojan-activity;sid:84080077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"195.34.91.22"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216979/; classtype:trojan-activity;sid:84080079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216983)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"37.57.33.51"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216983/; classtype:trojan-activity;sid:84080083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"182.253.115.155"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216986/; classtype:trojan-activity;sid:84080086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"88.119.151.142"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216987/; classtype:trojan-activity;sid:84080087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"212.73.75.84"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216963/; classtype:trojan-activity;sid:84080063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216956)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"77.89.245.118"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216956/; classtype:trojan-activity;sid:84080056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216936)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"202.148.20.138"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216936/; classtype:trojan-activity;sid:84080036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216937)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"181.211.252.34"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216937/; classtype:trojan-activity;sid:84080037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"206.214.35.106"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216917/; classtype:trojan-activity;sid:84080017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216889)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"138.122.43.76"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216889/; classtype:trojan-activity;sid:84079989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216891)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"185.190.20.228"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216891/; classtype:trojan-activity;sid:84079991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"89.216.100.166"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216892/; classtype:trojan-activity;sid:84079992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"109.87.223.241"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216893/; classtype:trojan-activity;sid:84079993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"185.12.78.161"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216883/; classtype:trojan-activity;sid:84079983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216854)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"202.131.234.26"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216854/; classtype:trojan-activity;sid:84079954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216846)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"103.217.215.238"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216846/; classtype:trojan-activity;sid:84079946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"27.147.225.2"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216809/; classtype:trojan-activity;sid:84079909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"134.249.141.119"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216811/; classtype:trojan-activity;sid:84079911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"178.188.30.171"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216813/; classtype:trojan-activity;sid:84079913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"118.179.203.50"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216823/; classtype:trojan-activity;sid:84079923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"109.160.87.2"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216802/; classtype:trojan-activity;sid:84079902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"98.103.171.36"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216800/; classtype:trojan-activity;sid:84079900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"186.154.93.81"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216794/; classtype:trojan-activity;sid:84079894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"89.231.14.137"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216772/; classtype:trojan-activity;sid:84079872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"81.16.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216763/; classtype:trojan-activity;sid:84079863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"154.0.129.134"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216735/; classtype:trojan-activity;sid:84079835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"41.77.74.90"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216740/; classtype:trojan-activity;sid:84079840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"185.57.69.125"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216722/; classtype:trojan-activity;sid:84079822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"183.81.156.121"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216726/; classtype:trojan-activity;sid:84079826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"178.211.135.170"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216710/; classtype:trojan-activity;sid:84079810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"88.135.26.83"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216704/; classtype:trojan-activity;sid:84079804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216685)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"46.151.56.42"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216685/; classtype:trojan-activity;sid:84079785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216686)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"88.119.193.17"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216686/; classtype:trojan-activity;sid:84079786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216688)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"83.218.189.21"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216688/; classtype:trojan-activity;sid:84079788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"178.151.143.2"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216694/; classtype:trojan-activity;sid:84079794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216700)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"200.61.163.235"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216700/; classtype:trojan-activity;sid:84079800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"202.148.18.218"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216649/; classtype:trojan-activity;sid:84079749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"202.53.164.46"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216650/; classtype:trojan-activity;sid:84079750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"188.72.6.218"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216653/; classtype:trojan-activity;sid:84079753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216658)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"185.236.46.120"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216658/; classtype:trojan-activity;sid:84079758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216664)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"103.245.10.51"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216664/; classtype:trojan-activity;sid:84079764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"154.0.129.114"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216626/; classtype:trojan-activity;sid:84079726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"182.160.102.188"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216627/; classtype:trojan-activity;sid:84079727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216608)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"217.218.235.202"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216608/; classtype:trojan-activity;sid:84079708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"213.6.74.138"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216599/; classtype:trojan-activity;sid:84079699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"37.233.63.185"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216600/; classtype:trojan-activity;sid:84079700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"190.2.237.104"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216581/; classtype:trojan-activity;sid:84079681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"178.77.228.166"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216583/; classtype:trojan-activity;sid:84079683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"213.91.236.237"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216584/; classtype:trojan-activity;sid:84079684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"95.170.116.28"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216557/; classtype:trojan-activity;sid:84079657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"77.46.170.18"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216559/; classtype:trojan-activity;sid:84079659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"202.148.5.34"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216561/; classtype:trojan-activity;sid:84079661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216564)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"176.221.111.222"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216564/; classtype:trojan-activity;sid:84079664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216529)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"36.66.139.36"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216529/; classtype:trojan-activity;sid:84079629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216481)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"41.78.75.186"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216481/; classtype:trojan-activity;sid:84079581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"78.26.81.99"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216491/; classtype:trojan-activity;sid:84079591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"185.133.214.138"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216478/; classtype:trojan-activity;sid:84079578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216479)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"91.92.82.180"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216479/; classtype:trojan-activity;sid:84079579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216456)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/help.scr"; depth:9; endswith; nocase; http.host; content:"121.43.104.75"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216456/; classtype:trojan-activity;sid:84079556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216437)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"87.227.140.66"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216437/; classtype:trojan-activity;sid:84079537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"217.92.214.15"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216421/; classtype:trojan-activity;sid:84079521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216418)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"80.249.6.118"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216418/; classtype:trojan-activity;sid:84079518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216413)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"212.98.186.8"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216413/; classtype:trojan-activity;sid:84079513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"49.232.126.36"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216406/; classtype:trojan-activity;sid:84079506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216404)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"150.158.25.244"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216404/; classtype:trojan-activity;sid:84079504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"43.132.12.146"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216384/; classtype:trojan-activity;sid:84079484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"50.65.169.30"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216382/; classtype:trojan-activity;sid:84079482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"36.110.15.211"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216377/; classtype:trojan-activity;sid:84079477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"178.61.160.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216372/; classtype:trojan-activity;sid:84079472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"124.123.123.15"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216365/; classtype:trojan-activity;sid:84079465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"123.117.136.97"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216353/; classtype:trojan-activity;sid:84079453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"43.132.13.252"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216334/; classtype:trojan-activity;sid:84079434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216322)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"184.185.30.182"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216322/; classtype:trojan-activity;sid:84079422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"85.163.234.15"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216309/; classtype:trojan-activity;sid:84079409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"94.76.156.101"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216306/; classtype:trojan-activity;sid:84079406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; endswith; nocase; http.host; content:"103.187.151.107"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216302/; classtype:trojan-activity;sid:84079402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.217.215.238"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215823/; classtype:trojan-activity;sid:84078923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"27.147.225.2"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215826/; classtype:trojan-activity;sid:84078926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"203.160.56.67"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215829/; classtype:trojan-activity;sid:84078929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.57.69.125"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215816/; classtype:trojan-activity;sid:84078916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.233.63.185"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215785/; classtype:trojan-activity;sid:84078885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215795)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"176.221.111.222"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215795/; classtype:trojan-activity;sid:84078895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215482)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.179.203.50"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215482/; classtype:trojan-activity;sid:84078582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.26.81.99"; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215483/; classtype:trojan-activity;sid:84078583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.160.102.188"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215478/; classtype:trojan-activity;sid:84078578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.119.151.142"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215468/; classtype:trojan-activity;sid:84078568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.160.87.2"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215463/; classtype:trojan-activity;sid:84078563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.98.186.8"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215464/; classtype:trojan-activity;sid:84078564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"213.91.236.237"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215434/; classtype:trojan-activity;sid:84078534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215421)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"183.81.156.121"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215421/; classtype:trojan-activity;sid:84078521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215422)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"206.214.35.106"; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215422/; classtype:trojan-activity;sid:84078522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.255.217.87"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215417/; classtype:trojan-activity;sid:84078517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215393)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"134.249.141.119"; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215393/; classtype:trojan-activity;sid:84078493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"88.116.62.226"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215380/; classtype:trojan-activity;sid:84078480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215382)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.46.170.18"; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215382/; classtype:trojan-activity;sid:84078482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.238.209.82"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215371/; classtype:trojan-activity;sid:84078471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"83.218.189.21"; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215358/; classtype:trojan-activity;sid:84078458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3213897)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/matinrco/tor/releases/download/v0.4.5.10/tor-expert-bundle-v0.4.5.10.zip"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_05; reference:url, urlhaus.abuse.ch/url/3213897/; classtype:trojan-activity;sid:84076997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3206293)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ox2fa/justnow/refs/heads/main/2pac.php"; depth:39; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_03; reference:url, urlhaus.abuse.ch/url/3206293/; classtype:trojan-activity;sid:84069393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3200548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/slinky/slinkycrack.zip"; depth:23; endswith; nocase; http.host; content:"crystalpvp.ru"; depth:13; isdataat:!1,relative; metadata:created_at 2024_09_29; reference:url, urlhaus.abuse.ch/url/3200548/; classtype:trojan-activity;sid:84063648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3198753)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pinginfoview.exe"; depth:17; endswith; nocase; http.host; content:"139.198.15.223"; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_28; reference:url, urlhaus.abuse.ch/url/3198753/; classtype:trojan-activity;sid:84061853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3198696)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cen22.php"; depth:10; endswith; nocase; http.host; content:"39.100.33.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_09_28; reference:url, urlhaus.abuse.ch/url/3198696/; classtype:trojan-activity;sid:84061796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3195883)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scanport.exe"; depth:13; endswith; nocase; http.host; content:"139.198.15.223"; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_28; reference:url, urlhaus.abuse.ch/url/3195883/; classtype:trojan-activity;sid:84058983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3195736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fx8"; depth:4; endswith; nocase; http.host; content:"123.57.250.154"; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_28; reference:url, urlhaus.abuse.ch/url/3195736/; classtype:trojan-activity;sid:84058836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3193861)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/massgravel/microsoft-activation-scripts/b1b5299c4725d97349b18b59061647198f7cc59b/mas/all-in-one-version-kl/mas_aio.cmd"; depth:119; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_27; reference:url, urlhaus.abuse.ch/url/3193861/; classtype:trojan-activity;sid:84056961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3190323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"102.68.74.69"; depth:12; isdataat:!1,relative; metadata:created_at 2024_09_25; reference:url, urlhaus.abuse.ch/url/3190323/; classtype:trojan-activity;sid:84053423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3190315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"109.166.211.222"; depth:15; isdataat:!1,relative; metadata:created_at 2024_09_25; reference:url, urlhaus.abuse.ch/url/3190315/; classtype:trojan-activity;sid:84053415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3190313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"109.166.211.222"; depth:15; isdataat:!1,relative; metadata:created_at 2024_09_25; reference:url, urlhaus.abuse.ch/url/3190313/; classtype:trojan-activity;sid:84053413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3189225)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unknwon1352/qawfdasfaw/main/software.exe"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_24; reference:url, urlhaus.abuse.ch/url/3189225/; classtype:trojan-activity;sid:84052325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3188620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/repository/aa_v3.exe"; depth:21; endswith; nocase; http.host; content:"83.149.17.194"; depth:13; isdataat:!1,relative; metadata:created_at 2024_09_24; reference:url, urlhaus.abuse.ch/url/3188620/; classtype:trojan-activity;sid:84051720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3188034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/blueskyxn/changesource/master/besttrace"; depth:40; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_23; reference:url, urlhaus.abuse.ch/url/3188034/; classtype:trojan-activity;sid:84051134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186441)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dxl_win_tool_v9.6.iso"; depth:22; endswith; nocase; http.host; content:"down.fwqlt.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186441/; classtype:trojan-activity;sid:84049541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186440)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1-%e4%bf%ae%e6%94%b9%e7%ab%af%e5%8f%a3.iso"; depth:43; endswith; nocase; http.host; content:"down.fwqlt.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186440/; classtype:trojan-activity;sid:84049540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dxl_win_tool_v9.4.iso"; depth:22; endswith; nocase; http.host; content:"down.fwqlt.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186439/; classtype:trojan-activity;sid:84049539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1-%e4%bf%ae%e6%94%b9%e7%ab%af%e5%8f%a3.zip"; depth:43; endswith; nocase; http.host; content:"down.fwqlt.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186430/; classtype:trojan-activity;sid:84049530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1_dxl_windowsport.zip"; depth:22; endswith; nocase; http.host; content:"down.fwqlt.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186428/; classtype:trojan-activity;sid:84049528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3183909)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/plugins/z-downloads/"; depth:32; endswith; nocase; http.host; content:"ignetwork.us"; depth:12; isdataat:!1,relative; metadata:created_at 2024_09_21; reference:url, urlhaus.abuse.ch/url/3183909/; classtype:trojan-activity;sid:84047009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3174523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scribblercoder/browserthief/main/browserthief.ps1"; depth:50; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3174523/; classtype:trojan-activity;sid:84037623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3174364)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/foru.apk"; depth:9; endswith; nocase; http.host; content:"tecunonline.com"; depth:15; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3174364/; classtype:trojan-activity;sid:84037464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3174340)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/foru.apk"; depth:9; endswith; nocase; http.host; content:"www.tecunonline.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3174340/; classtype:trojan-activity;sid:84037440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3174264)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keygen"; depth:7; endswith; nocase; http.host; content:"146.0.42.82"; depth:11; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3174264/; classtype:trojan-activity;sid:84037364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3173868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file.exe"; depth:9; endswith; nocase; http.host; content:"85.25.72.70"; depth:11; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3173868/; classtype:trojan-activity;sid:84036968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3172240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/techsavvysenior/referralreactjs/archive/refs/heads/main.zip"; depth:60; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_09_14; reference:url, urlhaus.abuse.ch/url/3172240/; classtype:trojan-activity;sid:84035340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3163579)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/handler/download|3f|action=download|7c|26|7c|download_id=jgc6slaf|7c|26|7c|private_id=0|7c|26|7c|url=https%253a%252f%252fyoutransfer.net%252fjgc6slaf"; depth:150; endswith; nocase; http.host; content:"youtransfer.net"; depth:15; isdataat:!1,relative; metadata:created_at 2024_09_09; reference:url, urlhaus.abuse.ch/url/3163579/; classtype:trojan-activity;sid:84026679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3154718)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hackirby/discord-injection/main/injection.js"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_03; reference:url, urlhaus.abuse.ch/url/3154718/; classtype:trojan-activity;sid:84017818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3135730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/miners/myxmrig.tgz"; depth:19; endswith; nocase; http.host; content:"do-dear.com"; depth:11; isdataat:!1,relative; metadata:created_at 2024_08_30; reference:url, urlhaus.abuse.ch/url/3135730/; classtype:trojan-activity;sid:83998830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3135722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sosinchik/asd/main/zoom.py"; depth:27; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_30; reference:url, urlhaus.abuse.ch/url/3135722/; classtype:trojan-activity;sid:83998822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3135724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moneroocean/xmrig_setup/master/setup_moneroocean_miner.sh"; depth:58; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_30; reference:url, urlhaus.abuse.ch/url/3135724/; classtype:trojan-activity;sid:83998824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3135613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/log/orgn.txt"; depth:13; endswith; nocase; http.host; content:"epanpano.com"; depth:12; isdataat:!1,relative; metadata:created_at 2024_08_30; reference:url, urlhaus.abuse.ch/url/3135613/; classtype:trojan-activity;sid:83998713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3134374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/soft/wnbsqv3008.exe"; depth:20; endswith; nocase; http.host; content:"soft.wsyhn.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_29; reference:url, urlhaus.abuse.ch/url/3134374/; classtype:trojan-activity;sid:83997474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3134371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qqhelper_1540.exe"; depth:18; endswith; nocase; http.host; content:"down.qqfarmer.com.cn"; depth:20; isdataat:!1,relative; metadata:created_at 2024_08_29; reference:url, urlhaus.abuse.ch/url/3134371/; classtype:trojan-activity;sid:83997471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129654)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nova_flow/patcher.exe"; depth:22; endswith; nocase; http.host; content:"144.172.71.105"; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129654/; classtype:trojan-activity;sid:83992754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129577)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pages/update/css/self/[upg]css.exe"; depth:35; endswith; nocase; http.host; content:"cs.go.kg"; depth:8; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129577/; classtype:trojan-activity;sid:83992677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129478)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zoldownload/foobar2000_v1.6.7_beta_17@1704_129472.exe"; depth:54; endswith; nocase; http.host; content:"down10d.zol.com.cn"; depth:18; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129478/; classtype:trojan-activity;sid:83992578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129417)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/asmedises/pxray_cast_sort.exe"; depth:30; endswith; nocase; http.host; content:"www.medises.co.kr"; depth:17; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129417/; classtype:trojan-activity;sid:83992517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yuta1111x/selfbot/04ecdf46e8db9fce689d93905d759334b475c825/aquarius.exe"; depth:72; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129042/; classtype:trojan-activity;sid:83992142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3121841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xclient.exe"; depth:12; endswith; nocase; http.host; content:"103.54.153.49"; depth:13; isdataat:!1,relative; metadata:created_at 2024_08_22; reference:url, urlhaus.abuse.ch/url/3121841/; classtype:trojan-activity;sid:83984941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"190.104.213.45"; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112427/; classtype:trojan-activity;sid:83975527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112426)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"200.29.120.130"; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112426/; classtype:trojan-activity;sid:83975526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112419)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"93.182.76.169"; depth:13; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112419/; classtype:trojan-activity;sid:83975519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112420)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"93.182.76.169"; depth:13; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112420/; classtype:trojan-activity;sid:83975520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/webcam.dll"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108504/; classtype:trojan-activity;sid:83971604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/token%20grabber.dll"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108505/; classtype:trojan-activity;sid:83971605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108506)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/rootkit.dll"; depth:67; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108506/; classtype:trojan-activity;sid:83971606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/unrootkit.dll"; depth:69; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108507/; classtype:trojan-activity;sid:83971607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108503)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/passwordstealer.dll"; depth:75; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108503/; classtype:trojan-activity;sid:83971603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/openark/version.txt"; depth:20; endswith; nocase; http.host; content:"file.blackint3.com"; depth:18; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108502/; classtype:trojan-activity;sid:83971602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/openark/openark64.exe"; depth:22; endswith; nocase; http.host; content:"file.blackint3.com"; depth:18; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108492/; classtype:trojan-activity;sid:83971592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108491)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/openark/openark32.exe"; depth:22; endswith; nocase; http.host; content:"file.blackint3.com"; depth:18; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108491/; classtype:trojan-activity;sid:83971591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106560)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808120646if_/http:/154.216.19.139/bins/mirai.armv4l"; depth:61; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106560/; classtype:trojan-activity;sid:83969660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121041if_/http:/154.216.19.139/bins/mirai.armv6l"; depth:61; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106556/; classtype:trojan-activity;sid:83969656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106557)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808123114if_/http:/154.216.19.139/bins/mirai.arc"; depth:58; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106557/; classtype:trojan-activity;sid:83969657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122755if_/http:/154.216.19.139/bins/mirai.x86_64"; depth:61; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106551/; classtype:trojan-activity;sid:83969651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808120945if_/http:/154.216.19.139/bins/mirai.armv5l"; depth:61; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106553/; classtype:trojan-activity;sid:83969653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122159if_/http:/154.216.19.139/bins/mirai.powerpc"; depth:62; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106554/; classtype:trojan-activity;sid:83969654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106555)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121832if_/http:/154.216.19.139/bins/mirai.mipsel"; depth:61; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106555/; classtype:trojan-activity;sid:83969655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105147)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3q/blackdoor/main/extensions/test_move.bat"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105147/; classtype:trojan-activity;sid:83968247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105148)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3q/blackdoor/main/extensions/test_virus.bat"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105148/; classtype:trojan-activity;sid:83968248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3q/blackdoor/main/extensions/keylogger.exe"; depth:44; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105149/; classtype:trojan-activity;sid:83968249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3q/blackdoor/main/extensions/networks_profile.exe"; depth:51; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105150/; classtype:trojan-activity;sid:83968250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105145)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3q/blackdoor/main/backdoor.exe"; depth:32; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105145/; classtype:trojan-activity;sid:83968245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105146)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3q/blackdoor/main/extensions/fill_storage_move.bat"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105146/; classtype:trojan-activity;sid:83968246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105144)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s3q/blackdoor/main/extensions/fill_storage_virus.bat"; depth:53; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105144/; classtype:trojan-activity;sid:83968244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3103488)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"64.234.95.70"; depth:12; isdataat:!1,relative; metadata:created_at 2024_08_12; reference:url, urlhaus.abuse.ch/url/3103488/; classtype:trojan-activity;sid:83966588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3103489)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"170.55.7.234"; depth:12; isdataat:!1,relative; metadata:created_at 2024_08_12; reference:url, urlhaus.abuse.ch/url/3103489/; classtype:trojan-activity;sid:83966589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3103476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"187.247.242.34"; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_12; reference:url, urlhaus.abuse.ch/url/3103476/; classtype:trojan-activity;sid:83966576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3100042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joelgmsec/invoke-stealth/main/resources/betterxencrypt/betterxencrypt.ps1"; depth:74; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3100042/; classtype:trojan-activity;sid:83963142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099961)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122448if_/http:/154.216.19.139/bins/mirai.sh4"; depth:58; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099961/; classtype:trojan-activity;sid:83963061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122636if_/http:/154.216.19.139/bins/mirai.sparc"; depth:60; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099963/; classtype:trojan-activity;sid:83963063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099965)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121347if_/http:/154.216.19.139/bins/mirai.m68k"; depth:59; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099965/; classtype:trojan-activity;sid:83963065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099966)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121419if_/http:/154.216.19.139/bins/mirai.mips"; depth:59; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099966/; classtype:trojan-activity;sid:83963066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099960)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121308if_/http:/154.216.19.139/bins/mirai.i686"; depth:59; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099960/; classtype:trojan-activity;sid:83963060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097244)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808120223if_/http://154.216.19.139/bins/mirai.bin"; depth:59; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097244/; classtype:trojan-activity;sid:83960344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122755if_/http://154.216.19.139/bins/mirai.x86_64"; depth:62; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097239/; classtype:trojan-activity;sid:83960339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121041if_/http://154.216.19.139/bins/mirai.armv6l"; depth:62; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097240/; classtype:trojan-activity;sid:83960340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097241)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121230if_/http://154.216.19.139/bins/mirai.i586"; depth:60; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097241/; classtype:trojan-activity;sid:83960341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122636if_/http://154.216.19.139/bins/mirai.sparc"; depth:61; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097242/; classtype:trojan-activity;sid:83960342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097243)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121308if_/http://154.216.19.139/bins/mirai.i686"; depth:60; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097243/; classtype:trojan-activity;sid:83960343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097229)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122159if_/http://154.216.19.139/bins/mirai.powerpc"; depth:63; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097229/; classtype:trojan-activity;sid:83960329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121121if_/http://154.216.19.139/bins/mirai.armv7l"; depth:62; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097231/; classtype:trojan-activity;sid:83960331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808123114if_/http://154.216.19.139/bins/mirai.arc"; depth:59; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097232/; classtype:trojan-activity;sid:83960332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122448if_/http://154.216.19.139/bins/mirai.sh4"; depth:59; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097233/; classtype:trojan-activity;sid:83960333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097234)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121832if_/http://154.216.19.139/bins/mirai.mipsel"; depth:62; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097234/; classtype:trojan-activity;sid:83960334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808120945if_/http://154.216.19.139/bins/mirai.armv5l"; depth:62; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097235/; classtype:trojan-activity;sid:83960335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808120646if_/http://154.216.19.139/bins/mirai.armv4l"; depth:62; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097236/; classtype:trojan-activity;sid:83960336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808122936if_/http://154.216.19.139/bins/mirai.gnueabihf"; depth:65; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097237/; classtype:trojan-activity;sid:83960337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web/20240808121419if_/http://154.216.19.139/bins/mirai.mips"; depth:60; endswith; nocase; http.host; content:"web.archive.org"; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097238/; classtype:trojan-activity;sid:83960338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3092877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/02.08.2022.exe"; depth:15; endswith; nocase; http.host; content:"85.175.101.203"; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_06; reference:url, urlhaus.abuse.ch/url/3092877/; classtype:trojan-activity;sid:83955977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3086390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/compile/download/%5bwin"; depth:35; endswith; nocase; http.host; content:"8.218.138.77"; depth:12; isdataat:!1,relative; metadata:created_at 2024_08_03; reference:url, urlhaus.abuse.ch/url/3086390/; classtype:trojan-activity;sid:83949490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/komasinfo/idcb/main/cbs_applcation_details_072602024_xlsx.rar"; depth:62; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072990/; classtype:trojan-activity;sid:83936090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/adrinnno/ptwis/raw/main/file_cbs_app_details_no-0923871691_xlsx.zip"; depth:68; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072974/; classtype:trojan-activity;sid:83936074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reporgu/fakado/raw/main/transaction_file_9812009_end_ids_yesbr5_pdf.rar"; depth:72; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072975/; classtype:trojan-activity;sid:83936075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/komasinfo/idcb/raw/main/cbs_applcation_details_072602024_xlsx.rar"; depth:66; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072978/; classtype:trojan-activity;sid:83936078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072969)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/deannwas/policah/main/file_cbs_app_details_no-0923871691_xlsx.zip"; depth:66; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072969/; classtype:trojan-activity;sid:83936069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/reporgu/fakado/main/transaction_file_9812009_end_ids_yesbr5_pdf.rar"; depth:68; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072972/; classtype:trojan-activity;sid:83936072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3058866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cve-2023-36874.zip"; depth:19; endswith; nocase; http.host; content:"51.255.46.245"; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_21; reference:url, urlhaus.abuse.ch/url/3058866/; classtype:trojan-activity;sid:83921966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3058862)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nc64.exe"; depth:9; endswith; nocase; http.host; content:"51.255.46.245"; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_21; reference:url, urlhaus.abuse.ch/url/3058862/; classtype:trojan-activity;sid:83921962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3058863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nc64.zip"; depth:9; endswith; nocase; http.host; content:"51.255.46.245"; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_21; reference:url, urlhaus.abuse.ch/url/3058863/; classtype:trojan-activity;sid:83921963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3058864)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b64"; depth:4; endswith; nocase; http.host; content:"51.255.46.245"; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_21; reference:url, urlhaus.abuse.ch/url/3058864/; classtype:trojan-activity;sid:83921964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2949407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tan.jpg"; depth:8; endswith; nocase; http.host; content:"www999999safagqwhg-1327129302.cos.ap-chengdu.myqcloud.com"; depth:57; isdataat:!1,relative; metadata:created_at 2024_07_11; reference:url, urlhaus.abuse.ch/url/2949407/; classtype:trojan-activity;sid:83812507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2949385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1rsqnkyvcaein5m-gskl8coyuh8w5xrbd"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_07_11; reference:url, urlhaus.abuse.ch/url/2949385/; classtype:trojan-activity;sid:83812485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2949176)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tan.jpg"; depth:8; endswith; nocase; http.host; content:"www999999asgasg-1327129302.cos.ap-chengdu.myqcloud.com"; depth:54; isdataat:!1,relative; metadata:created_at 2024_07_11; reference:url, urlhaus.abuse.ch/url/2949176/; classtype:trojan-activity;sid:83812276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2944285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jijilovedada/jijilovedada/main/tools/cc/adaptorovernight.exe"; depth:61; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_07_08; reference:url, urlhaus.abuse.ch/url/2944285/; classtype:trojan-activity;sid:83807385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2942567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/compile/download/win"; depth:32; endswith; nocase; http.host; content:"8.218.138.77"; depth:12; isdataat:!1,relative; metadata:created_at 2024_07_07; reference:url, urlhaus.abuse.ch/url/2942567/; classtype:trojan-activity;sid:83805667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/000.exe"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934823/; classtype:trojan-activity;sid:83797923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934824)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/trojan.malpack.themida%20(anti%20vm).exe"; depth:102; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934824/; classtype:trojan-activity;sid:83797924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934818)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/jigsaw.exe"; depth:76; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934818/; classtype:trojan-activity;sid:83797918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/freeyoutubedownloader.exe"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934819/; classtype:trojan-activity;sid:83797919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934820)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/memz.exe"; depth:70; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934820/; classtype:trojan-activity;sid:83797920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/noescape.exe"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934821/; classtype:trojan-activity;sid:83797921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/destover.exe"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934822/; classtype:trojan-activity;sid:83797922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/meredrop.exe"; depth:74; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934816/; classtype:trojan-activity;sid:83797916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/redlinestealer.exe"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934817/; classtype:trojan-activity;sid:83797917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/hive%20ransomware.exe"; depth:87; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934811/; classtype:trojan-activity;sid:83797911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/wannacry.exe"; depth:78; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934812/; classtype:trojan-activity;sid:83797912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934813)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/nomoreransom.exe"; depth:82; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934813/; classtype:trojan-activity;sid:83797913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/petya.a.exe"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934808/; classtype:trojan-activity;sid:83797908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/cryptowall.exe"; depth:80; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934809/; classtype:trojan-activity;sid:83797909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934810)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/infinitycrypt.exe"; depth:83; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934810/; classtype:trojan-activity;sid:83797910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934805)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/coronavirus.exe"; depth:81; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934805/; classtype:trojan-activity;sid:83797905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2932460)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/445.jpg"; depth:8; endswith; nocase; http.host; content:"down.ftp21.cc"; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_04; reference:url, urlhaus.abuse.ch/url/2932460/; classtype:trojan-activity;sid:83795560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2914055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tq.jpg"; depth:7; endswith; nocase; http.host; content:"down.ftp21.cc"; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_30; reference:url, urlhaus.abuse.ch/url/2914055/; classtype:trojan-activity;sid:83777155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911217)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"116.58.62.74"; depth:12; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911217/; classtype:trojan-activity;sid:83774317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911215)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"122.179.136.112"; depth:15; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911215/; classtype:trojan-activity;sid:83774315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"130.185.193.208"; depth:15; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911212/; classtype:trojan-activity;sid:83774312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911196)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"78-20-115-5.access.telenet.be"; depth:29; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911196/; classtype:trojan-activity;sid:83774296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911194)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"195.103.203.106"; depth:15; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911194/; classtype:trojan-activity;sid:83774294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911190)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"78.20.115.5"; depth:11; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911190/; classtype:trojan-activity;sid:83774290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911191)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"88.28.218.163"; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911191/; classtype:trojan-activity;sid:83774291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911187)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"102.53.15.18"; depth:12; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911187/; classtype:trojan-activity;sid:83774287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911184)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"126.23.203.236"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911184/; classtype:trojan-activity;sid:83774284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911154)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"95.255.114.11"; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911154/; classtype:trojan-activity;sid:83774254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911133)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"102.53.15.17"; depth:12; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911133/; classtype:trojan-activity;sid:83774233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911113)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"softbank126023203236.bbtec.net"; depth:30; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911113/; classtype:trojan-activity;sid:83774213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911108)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"host-195-103-203-106.business.telecomitalia.it"; depth:46; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911108/; classtype:trojan-activity;sid:83774208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911105)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photo.scr"; depth:10; endswith; nocase; http.host; content:"host-95-255-114-11.business.telecomitalia.it"; depth:44; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911105/; classtype:trojan-activity;sid:83774205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2909335)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1pjt23vhtwzyzypmtn3-laqctzzr5vb5d"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2909335/; classtype:trojan-activity;sid:83772435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2909291)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"89.184.185.198"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2909291/; classtype:trojan-activity;sid:83772391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2909290)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"185.224.107.4"; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2909290/; classtype:trojan-activity;sid:83772390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"170.210.81.101"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908910/; classtype:trojan-activity;sid:83772010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"182.72.167.124"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908913/; classtype:trojan-activity;sid:83772013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908900)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"190.108.63.242"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908900/; classtype:trojan-activity;sid:83772000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908902)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"202.57.39.2"; depth:11; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908902/; classtype:trojan-activity;sid:83772002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908903)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"14.142.209.198"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908903/; classtype:trojan-activity;sid:83772003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908894)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tftp"; depth:5; endswith; nocase; http.host; content:"170.210.81.104"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908894/; classtype:trojan-activity;sid:83771994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2901197)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zwzonepieces/posapsi/master/chatlife.exe"; depth:41; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_06_22; reference:url, urlhaus.abuse.ch/url/2901197/; classtype:trojan-activity;sid:83764297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2894025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kailash-jakhar/webpack-v5-tutorial/main/quizpokemon.exe"; depth:56; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_06_17; reference:url, urlhaus.abuse.ch/url/2894025/; classtype:trojan-activity;sid:83757125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2888463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/help.scr"; depth:9; endswith; nocase; http.host; content:"118.178.133.241"; depth:15; isdataat:!1,relative; metadata:created_at 2024_06_14; reference:url, urlhaus.abuse.ch/url/2888463/; classtype:trojan-activity;sid:83751563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2888444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/help.scr"; depth:9; endswith; nocase; http.host; content:"124.67.254.109"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_14; reference:url, urlhaus.abuse.ch/url/2888444/; classtype:trojan-activity;sid:83751544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2888430)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/help.scr"; depth:9; endswith; nocase; http.host; content:"117.157.17.194"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_14; reference:url, urlhaus.abuse.ch/url/2888430/; classtype:trojan-activity;sid:83751530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2885860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/brunovale03/adegaads/main/offeredbuilt.exe"; depth:43; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_06_13; reference:url, urlhaus.abuse.ch/url/2885860/; classtype:trojan-activity;sid:83748960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2883708)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sirvivor32/sirvivor/main/lukejazz.exe"; depth:38; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_06_11; reference:url, urlhaus.abuse.ch/url/2883708/; classtype:trojan-activity;sid:83746808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2881768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cg100/update.exe"; depth:17; endswith; nocase; http.host; content:"update.cg100iii.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_06_10; reference:url, urlhaus.abuse.ch/url/2881768/; classtype:trojan-activity;sid:83744868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2879955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unp%20setup.exe"; depth:16; endswith; nocase; http.host; content:"36.138.125.70"; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_08; reference:url, urlhaus.abuse.ch/url/2879955/; classtype:trojan-activity;sid:83743055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2879655)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sharphound.exe"; depth:15; endswith; nocase; http.host; content:"92.127.156.174"; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_08; reference:url, urlhaus.abuse.ch/url/2879655/; classtype:trojan-activity;sid:83742755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2877890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ustaxes/ustaxes/files/15421286/2022and2023taxdocuments.zip"; depth:59; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_06_07; reference:url, urlhaus.abuse.ch/url/2877890/; classtype:trojan-activity;sid:83740990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2874107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=19nonxskhmwbvfxpr2ccmwd9xrhz1ldco"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_06_04; reference:url, urlhaus.abuse.ch/url/2874107/; classtype:trojan-activity;sid:83737207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2874109)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1p_knmkidu8kiejeem_ijrlumbjih3bkv"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_06_04; reference:url, urlhaus.abuse.ch/url/2874109/; classtype:trojan-activity;sid:83737209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2872168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/htwvlcdsfcrahhchdd97.bin"; depth:25; endswith; nocase; http.host; content:"ramirex.ro"; depth:10; isdataat:!1,relative; metadata:created_at 2024_06_02; reference:url, urlhaus.abuse.ch/url/2872168/; classtype:trojan-activity;sid:83735268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2872167)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rutschebanes.qxd"; depth:17; endswith; nocase; http.host; content:"ramirex.ro"; depth:10; isdataat:!1,relative; metadata:created_at 2024_06_02; reference:url, urlhaus.abuse.ch/url/2872167/; classtype:trojan-activity;sid:83735267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2871411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=18opq2_cuhgvezldmmbuzkt3tp3u8sgr_"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_06_01; reference:url, urlhaus.abuse.ch/url/2871411/; classtype:trojan-activity;sid:83734511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2871412)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1u0xueul0jt-4joz0qbxbmiqjn2i0gcde"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_06_01; reference:url, urlhaus.abuse.ch/url/2871412/; classtype:trojan-activity;sid:83734512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2870242)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1pvgvrcomccqllrfbaaxotcp-gyyh3onz"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2870242/; classtype:trojan-activity;sid:83733342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2870240)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ur2ibphmxipkxb5ernf34acfzzj2jga4"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2870240/; classtype:trojan-activity;sid:83733340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2870238)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1q2fszfukk1d8mxwia7wy6u4fse2vz07h"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2870238/; classtype:trojan-activity;sid:83733338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2870235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1wsqkirdngjlt8uu2lv9mzciks4my12jh"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2870235/; classtype:trojan-activity;sid:83733335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2869702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sheksweet/sheksweet1/main/rambledmime.exe"; depth:42; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2869702/; classtype:trojan-activity;sid:83732802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2868723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a.i_1003h.exe"; depth:14; endswith; nocase; http.host; content:"221.143.49.222"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_30; reference:url, urlhaus.abuse.ch/url/2868723/; classtype:trojan-activity;sid:83731823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2867270)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmed45sh/flutter-movie/master/crypted_c360a5b7.exe"; depth:52; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_05_28; reference:url, urlhaus.abuse.ch/url/2867270/; classtype:trojan-activity;sid:83730370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2867236)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ahmed45sh/apple-replica-starter-files/master/apple-replica/zintask.exe"; depth:71; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_05_28; reference:url, urlhaus.abuse.ch/url/2867236/; classtype:trojan-activity;sid:83730336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"221.10.233.217"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863372/; classtype:trojan-activity;sid:83726472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"223.108.58.13"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863341/; classtype:trojan-activity;sid:83726441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863345)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"123.143.141.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863345/; classtype:trojan-activity;sid:83726445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863330)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"223.108.58.15"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863330/; classtype:trojan-activity;sid:83726430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"82.77.57.16"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863333/; classtype:trojan-activity;sid:83726433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863334)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.49.168.84"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863334/; classtype:trojan-activity;sid:83726434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862050)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/8gikly"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862050/; classtype:trojan-activity;sid:83725150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862051)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/medjl1"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862051/; classtype:trojan-activity;sid:83725151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862052)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/dy1f16"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862052/; classtype:trojan-activity;sid:83725152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862053)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/kx3wl4"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862053/; classtype:trojan-activity;sid:83725153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/ppxodm"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862054/; classtype:trojan-activity;sid:83725154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862055)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/e7opy8"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862055/; classtype:trojan-activity;sid:83725155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/7dhid7"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862056/; classtype:trojan-activity;sid:83725156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/tbfvpd"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862049/; classtype:trojan-activity;sid:83725149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862047)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/g2js91"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862047/; classtype:trojan-activity;sid:83725147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862044)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/lt00vw"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862044/; classtype:trojan-activity;sid:83725144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862045)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/i7tdbr"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862045/; classtype:trojan-activity;sid:83725145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/3a9xj1"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862043/; classtype:trojan-activity;sid:83725143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862042)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/wyg3h5"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862042/; classtype:trojan-activity;sid:83725142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"212.3.211.157"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862022/; classtype:trojan-activity;sid:83725122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"102.216.105.81"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862020/; classtype:trojan-activity;sid:83725120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862017)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"123.143.141.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862017/; classtype:trojan-activity;sid:83725117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"123.143.141.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862004/; classtype:trojan-activity;sid:83725104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"24.234.159.5"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862007/; classtype:trojan-activity;sid:83725107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"80.24.87.77"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862009/; classtype:trojan-activity;sid:83725109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"166.144.131.188"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862010/; classtype:trojan-activity;sid:83725110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862014)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862014/; classtype:trojan-activity;sid:83725114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861986)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"188.147.175.138"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861986/; classtype:trojan-activity;sid:83725086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.208.134"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861979/; classtype:trojan-activity;sid:83725079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861982)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861982/; classtype:trojan-activity;sid:83725082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"132.255.192.122"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861971/; classtype:trojan-activity;sid:83725071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861974/; classtype:trojan-activity;sid:83725074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861957)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.183.208.134"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861957/; classtype:trojan-activity;sid:83725057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861958)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"80.24.87.77"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861958/; classtype:trojan-activity;sid:83725058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861959)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861959/; classtype:trojan-activity;sid:83725059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861950)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"95.47.248.146"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861950/; classtype:trojan-activity;sid:83725050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861948/; classtype:trojan-activity;sid:83725048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861919)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861919/; classtype:trojan-activity;sid:83725019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861923)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861923/; classtype:trojan-activity;sid:83725023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861927)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"223.82.83.143"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861927/; classtype:trojan-activity;sid:83725027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861929)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"95.230.215.65"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861929/; classtype:trojan-activity;sid:83725029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861930)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"141.134.214.217"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861930/; classtype:trojan-activity;sid:83725030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861931)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861931/; classtype:trojan-activity;sid:83725031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861935/; classtype:trojan-activity;sid:83725035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861939)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861939/; classtype:trojan-activity;sid:83725039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861940)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861940/; classtype:trojan-activity;sid:83725040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861941)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"123.143.141.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861941/; classtype:trojan-activity;sid:83725041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861943)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861943/; classtype:trojan-activity;sid:83725043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/dvbcvt"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861888/; classtype:trojan-activity;sid:83724988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861887)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/exw2o1"; depth:14; endswith; nocase; http.host; content:"www.sendspace.com"; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861887/; classtype:trojan-activity;sid:83724987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861843)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"118.69.157.212"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861843/; classtype:trojan-activity;sid:83724943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861852)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"178.176.204.250"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861852/; classtype:trojan-activity;sid:83724952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"80.24.87.77"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861838/; classtype:trojan-activity;sid:83724938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"202.3.248.179"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861834/; classtype:trojan-activity;sid:83724934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861831)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"178.176.204.240"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861831/; classtype:trojan-activity;sid:83724931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861828)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"141.134.214.217"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861828/; classtype:trojan-activity;sid:83724928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"123.143.141.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861826/; classtype:trojan-activity;sid:83724926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"68.107.218.106"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861827/; classtype:trojan-activity;sid:83724927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861822/; classtype:trojan-activity;sid:83724922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"174.71.237.86"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861819/; classtype:trojan-activity;sid:83724919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861814/; classtype:trojan-activity;sid:83724914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861802)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"24.234.159.5"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861802/; classtype:trojan-activity;sid:83724902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861800/; classtype:trojan-activity;sid:83724900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"132.255.192.122"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861798/; classtype:trojan-activity;sid:83724898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861794/; classtype:trojan-activity;sid:83724894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"178.183.208.134"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861791/; classtype:trojan-activity;sid:83724891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861790)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"123.143.141.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861790/; classtype:trojan-activity;sid:83724890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861789)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"91.231.190.163"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861789/; classtype:trojan-activity;sid:83724889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"46.250.54.75"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861781/; classtype:trojan-activity;sid:83724881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861777/; classtype:trojan-activity;sid:83724877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861770/; classtype:trojan-activity;sid:83724870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861773)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861773/; classtype:trojan-activity;sid:83724873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861755/; classtype:trojan-activity;sid:83724855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861750)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861750/; classtype:trojan-activity;sid:83724850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861749/; classtype:trojan-activity;sid:83724849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861743)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"123.143.141.75"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861743/; classtype:trojan-activity;sid:83724843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861735)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861735/; classtype:trojan-activity;sid:83724835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"31.0.241.65"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861737/; classtype:trojan-activity;sid:83724837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"81.42.247.62"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861740/; classtype:trojan-activity;sid:83724840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861729/; classtype:trojan-activity;sid:83724829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861731)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"166.144.131.188"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861731/; classtype:trojan-activity;sid:83724831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"46.250.54.75"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861733/; classtype:trojan-activity;sid:83724833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861721)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861721/; classtype:trojan-activity;sid:83724821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861725/; classtype:trojan-activity;sid:83724825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861716)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"188.170.32.148"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861716/; classtype:trojan-activity;sid:83724816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"80.14.38.66"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861710/; classtype:trojan-activity;sid:83724810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861707)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"209.162.229.229"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861707/; classtype:trojan-activity;sid:83724807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861695)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"102.216.105.81"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861695/; classtype:trojan-activity;sid:83724795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861702)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"188.147.175.138"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861702/; classtype:trojan-activity;sid:83724802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861692/; classtype:trojan-activity;sid:83724792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"202.3.248.178"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861693/; classtype:trojan-activity;sid:83724793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861680)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861680/; classtype:trojan-activity;sid:83724780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861675)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"80.24.87.77"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861675/; classtype:trojan-activity;sid:83724775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861670)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861670/; classtype:trojan-activity;sid:83724770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861667)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861667/; classtype:trojan-activity;sid:83724767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"31.173.70.100"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861657/; classtype:trojan-activity;sid:83724757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861659)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861659/; classtype:trojan-activity;sid:83724759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"212.3.211.157"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861661/; classtype:trojan-activity;sid:83724761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861643)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861643/; classtype:trojan-activity;sid:83724743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861640)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"174.71.237.86"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861640/; classtype:trojan-activity;sid:83724740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861633)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"77.237.29.219"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861633/; classtype:trojan-activity;sid:83724733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861636)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"95.47.248.146"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861636/; classtype:trojan-activity;sid:83724736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"118.69.157.212"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861616/; classtype:trojan-activity;sid:83724716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"82.148.194.54"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861595/; classtype:trojan-activity;sid:83724695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"69.75.168.226"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861597/; classtype:trojan-activity;sid:83724697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861600)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"223.82.83.143"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861600/; classtype:trojan-activity;sid:83724700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"178.183.208.134"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861610/; classtype:trojan-activity;sid:83724710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"24.234.159.5"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861592/; classtype:trojan-activity;sid:83724692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861582/; classtype:trojan-activity;sid:83724682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861568/; classtype:trojan-activity;sid:83724668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"113.160.251.236"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861569/; classtype:trojan-activity;sid:83724669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"118.69.157.212"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861573/; classtype:trojan-activity;sid:83724673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861559)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"68.226.36.150"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861559/; classtype:trojan-activity;sid:83724659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"95.230.215.65"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861553/; classtype:trojan-activity;sid:83724653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861549/; classtype:trojan-activity;sid:83724649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861547)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//sshd"; depth:6; endswith; nocase; http.host; content:"76.53.38.126"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861547/; classtype:trojan-activity;sid:83724647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"91.231.190.163"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861543/; classtype:trojan-activity;sid:83724643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2859511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"92.66.30.68"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_22; reference:url, urlhaus.abuse.ch/url/2859511/; classtype:trojan-activity;sid:83722611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2859508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"82.148.194.54"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_22; reference:url, urlhaus.abuse.ch/url/2859508/; classtype:trojan-activity;sid:83722608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2859027)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ustaxes/ustaxes/files/15378217/all.2023.tax.documents.zip"; depth:58; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_05_21; reference:url, urlhaus.abuse.ch/url/2859027/; classtype:trojan-activity;sid:83722127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857892)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"202.3.248.178"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857892/; classtype:trojan-activity;sid:83720992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857875/; classtype:trojan-activity;sid:83720975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857859)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"174.71.237.86"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857859/; classtype:trojan-activity;sid:83720959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857851)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"144.6.87.144"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857851/; classtype:trojan-activity;sid:83720951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857849)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"118.69.157.212"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857849/; classtype:trojan-activity;sid:83720949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857844)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"185.2.229.122"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857844/; classtype:trojan-activity;sid:83720944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857837)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857837/; classtype:trojan-activity;sid:83720937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"149.62.200.106"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857838/; classtype:trojan-activity;sid:83720938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"118.69.157.212"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857834/; classtype:trojan-activity;sid:83720934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857822)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.176.204.250"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857822/; classtype:trojan-activity;sid:83720922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857821)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.176.204.240"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857821/; classtype:trojan-activity;sid:83720921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"202.3.248.179"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857807/; classtype:trojan-activity;sid:83720907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857794)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"68.107.218.106"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857794/; classtype:trojan-activity;sid:83720894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"68.226.36.150"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857788/; classtype:trojan-activity;sid:83720888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857785/; classtype:trojan-activity;sid:83720885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"69.75.168.226"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857772/; classtype:trojan-activity;sid:83720872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857747/; classtype:trojan-activity;sid:83720847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857749)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"118.69.157.212"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857749/; classtype:trojan-activity;sid:83720849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857730/; classtype:trojan-activity;sid:83720830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857692)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"31.173.70.100"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857692/; classtype:trojan-activity;sid:83720792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857687)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"113.160.251.236"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857687/; classtype:trojan-activity;sid:83720787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857672/; classtype:trojan-activity;sid:83720772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857666)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857666/; classtype:trojan-activity;sid:83720766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"144.6.87.144"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857653/; classtype:trojan-activity;sid:83720753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857651)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"46.250.54.75"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857651/; classtype:trojan-activity;sid:83720751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857652)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"188.170.32.148"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857652/; classtype:trojan-activity;sid:83720752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"118.69.157.212"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857642/; classtype:trojan-activity;sid:83720742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857634)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"31.0.241.65"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857634/; classtype:trojan-activity;sid:83720734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857630/; classtype:trojan-activity;sid:83720730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857624)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"118.69.157.212"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857624/; classtype:trojan-activity;sid:83720724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857620)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"174.71.237.86"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857620/; classtype:trojan-activity;sid:83720720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"178.176.204.250"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857610/; classtype:trojan-activity;sid:83720710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857601)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"212.93.103.10"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857601/; classtype:trojan-activity;sid:83720701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857587)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"24.234.159.5"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857587/; classtype:trojan-activity;sid:83720687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857584)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"223.108.58.13"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857584/; classtype:trojan-activity;sid:83720684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857580)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857580/; classtype:trojan-activity;sid:83720680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857582)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857582/; classtype:trojan-activity;sid:83720682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"80.14.38.66"; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857573/; classtype:trojan-activity;sid:83720673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857570)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"77.237.29.219"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857570/; classtype:trojan-activity;sid:83720670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"46.250.54.75"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857553/; classtype:trojan-activity;sid:83720653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"202.139.20.12"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857535/; classtype:trojan-activity;sid:83720635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857527)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"174.71.237.86"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857527/; classtype:trojan-activity;sid:83720627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"164.126.129.225"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857521/; classtype:trojan-activity;sid:83720621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857524/; classtype:trojan-activity;sid:83720624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"209.162.229.229"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857525/; classtype:trojan-activity;sid:83720625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857502)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"223.108.58.15"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857502/; classtype:trojan-activity;sid:83720602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857496)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"112.4.110.42"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857496/; classtype:trojan-activity;sid:83720596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857483)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857483/; classtype:trojan-activity;sid:83720583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857484/; classtype:trojan-activity;sid:83720584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"91.164.39.142"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857486/; classtype:trojan-activity;sid:83720586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857468)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"31.222.113.214"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857468/; classtype:trojan-activity;sid:83720568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"102.68.74.45"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857465/; classtype:trojan-activity;sid:83720565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"165.73.108.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857463/; classtype:trojan-activity;sid:83720563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"174.71.237.86"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857447/; classtype:trojan-activity;sid:83720547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sshd"; depth:5; endswith; nocase; http.host; content:"68.226.36.150"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857448/; classtype:trojan-activity;sid:83720548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2846768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/assets/css/setup.msi"; depth:21; endswith; nocase; http.host; content:"zenglobalenerji.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_05_11; reference:url, urlhaus.abuse.ch/url/2846768/; classtype:trojan-activity;sid:83709868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2845681)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app/filesrc/android/apk/2023/zonghengxsandroid_7.5.6.63_zh-zhh5.apk"; depth:68; endswith; nocase; http.host; content:"static.zongheng.com"; depth:19; isdataat:!1,relative; metadata:created_at 2024_05_10; reference:url, urlhaus.abuse.ch/url/2845681/; classtype:trojan-activity;sid:83708781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842725)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"89.231.14.137"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842725/; classtype:trojan-activity;sid:83705825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"88.119.193.17"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842724/; classtype:trojan-activity;sid:83705824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842722)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"88.116.62.226"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842722/; classtype:trojan-activity;sid:83705822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"88.119.151.142"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842723/; classtype:trojan-activity;sid:83705823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842653)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"178.77.228.38"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842653/; classtype:trojan-activity;sid:83705753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842411)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.77.228.38"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2842411/; classtype:trojan-activity;sid:83705511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"109.245.220.229"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2842036/; classtype:trojan-activity;sid:83705136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"116.58.51.90"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2842006/; classtype:trojan-activity;sid:83705106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"212.107.232.167"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2842007/; classtype:trojan-activity;sid:83705107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841987)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"109.87.223.241"; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841987/; classtype:trojan-activity;sid:83705087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"202.148.5.34"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841988/; classtype:trojan-activity;sid:83705088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"151.236.247.230"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841974/; classtype:trojan-activity;sid:83705074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"81.16.249.96"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841976/; classtype:trojan-activity;sid:83705076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cryptography_module_windows.exe"; depth:32; endswith; nocase; http.host; content:"122.170.110.131"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841807/; classtype:trojan-activity;sid:83704907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841714)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.148.5.34"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841714/; classtype:trojan-activity;sid:83704814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.253.115.156"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841712/; classtype:trojan-activity;sid:83704812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"151.236.247.230"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841650/; classtype:trojan-activity;sid:83704750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841631)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"182.253.115.155"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841631/; classtype:trojan-activity;sid:83704731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841613)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.245.220.229"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841613/; classtype:trojan-activity;sid:83704713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"116.58.51.90"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841602/; classtype:trojan-activity;sid:83704702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841576)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"81.16.249.96"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841576/; classtype:trojan-activity;sid:83704676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.107.232.167"; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841573/; classtype:trojan-activity;sid:83704673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834467)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl"; depth:5; endswith; nocase; http.host; content:"66.71.249.146"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834467/; classtype:trojan-activity;sid:83697567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834459)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cron"; depth:5; endswith; nocase; http.host; content:"45.76.122.186"; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834459/; classtype:trojan-activity;sid:83697559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834442)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl"; depth:5; endswith; nocase; http.host; content:"66.71.242.67"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834442/; classtype:trojan-activity;sid:83697542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834400)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl"; depth:5; endswith; nocase; http.host; content:"66.71.242.68"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834400/; classtype:trojan-activity;sid:83697500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl"; depth:5; endswith; nocase; http.host; content:"66.71.242.70"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834387/; classtype:trojan-activity;sid:83697487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/curl"; depth:5; endswith; nocase; http.host; content:"66.71.242.69"; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834372/; classtype:trojan-activity;sid:83697472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2830963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kampfkarren/roblox/files/15001743/roexec.zip"; depth:45; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_29; reference:url, urlhaus.abuse.ch/url/2830963/; classtype:trojan-activity;sid:83694063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2830955)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/delta-io/delta/files/15016110/delta.zip"; depth:40; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_29; reference:url, urlhaus.abuse.ch/url/2830955/; classtype:trojan-activity;sid:83694055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2824078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mazacoin/maza/releases/download/v0.16.3/maza-0.16.3-win64-setup-unsigned.exe"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_23; reference:url, urlhaus.abuse.ch/url/2824078/; classtype:trojan-activity;sid:83687178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2824079)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mazacoin/maza/releases/download/v0.16.3/maza-0.16.3-osx-unsigned.dmg"; depth:69; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_23; reference:url, urlhaus.abuse.ch/url/2824079/; classtype:trojan-activity;sid:83687179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2824077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mazacoin/maza/releases/download/v0.16.3/maza-0.16.3-win32-setup-unsigned.exe"; depth:77; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_23; reference:url, urlhaus.abuse.ch/url/2824077/; classtype:trojan-activity;sid:83687177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"197.159.1.58"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822907/; classtype:trojan-activity;sid:83686007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"37.252.66.188"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822895/; classtype:trojan-activity;sid:83685995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822888)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"200.69.219.25"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822888/; classtype:trojan-activity;sid:83685988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"217.65.15.51"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822867/; classtype:trojan-activity;sid:83685967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"202.148.20.138"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822873/; classtype:trojan-activity;sid:83685973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822863)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"41.77.74.90"; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822863/; classtype:trojan-activity;sid:83685963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"36.88.180.115"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822823/; classtype:trojan-activity;sid:83685923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822830)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"167.250.193.253"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822830/; classtype:trojan-activity;sid:83685930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822809)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"95.170.116.28"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822809/; classtype:trojan-activity;sid:83685909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822781)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"95.158.175.214"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822781/; classtype:trojan-activity;sid:83685881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822724)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"118.179.121.235"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822724/; classtype:trojan-activity;sid:83685824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"196.41.63.178"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822726/; classtype:trojan-activity;sid:83685826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822698)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"98.103.171.36"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822698/; classtype:trojan-activity;sid:83685798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"186.154.93.81"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822619/; classtype:trojan-activity;sid:83685719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"43.245.131.27"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822605/; classtype:trojan-activity;sid:83685705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"89.216.100.166"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822606/; classtype:trojan-activity;sid:83685706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"181.211.252.34"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822592/; classtype:trojan-activity;sid:83685692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822583)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"103.245.10.51"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822583/; classtype:trojan-activity;sid:83685683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"91.92.82.180"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822548/; classtype:trojan-activity;sid:83685648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"202.53.164.214"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822544/; classtype:trojan-activity;sid:83685644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"95.170.119.100"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822543/; classtype:trojan-activity;sid:83685643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822522)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"78.140.32.219"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822522/; classtype:trojan-activity;sid:83685622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822471)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"190.2.237.104"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822471/; classtype:trojan-activity;sid:83685571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822475)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"118.71.250.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822475/; classtype:trojan-activity;sid:83685575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822462)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"200.61.163.235"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822462/; classtype:trojan-activity;sid:83685562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"185.71.69.198"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822432/; classtype:trojan-activity;sid:83685532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"213.6.74.138"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822416/; classtype:trojan-activity;sid:83685516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"193.106.58.174"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822407/; classtype:trojan-activity;sid:83685507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"37.157.212.138"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822405/; classtype:trojan-activity;sid:83685505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"202.148.18.220"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822386/; classtype:trojan-activity;sid:83685486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822384)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"190.113.124.155"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822384/; classtype:trojan-activity;sid:83685484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822371)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"109.108.84.121"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822371/; classtype:trojan-activity;sid:83685471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822372)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"154.84.212.18"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822372/; classtype:trojan-activity;sid:83685472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822328)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"202.148.18.218"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822328/; classtype:trojan-activity;sid:83685428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"185.236.46.120"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822287/; classtype:trojan-activity;sid:83685387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"103.90.207.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822259/; classtype:trojan-activity;sid:83685359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"41.215.23.222"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822249/; classtype:trojan-activity;sid:83685349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822189)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"58.145.168.170"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822189/; classtype:trojan-activity;sid:83685289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822173)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"81.16.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822173/; classtype:trojan-activity;sid:83685273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822165)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"211.186.82.229"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822165/; classtype:trojan-activity;sid:83685265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822168)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"185.190.20.228"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822168/; classtype:trojan-activity;sid:83685268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822169)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"195.34.91.22"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822169/; classtype:trojan-activity;sid:83685269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"188.44.110.215"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822142/; classtype:trojan-activity;sid:83685242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822102)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"138.122.43.76"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822102/; classtype:trojan-activity;sid:83685202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"78.26.180.129"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822070/; classtype:trojan-activity;sid:83685170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822064)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"103.187.151.107"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822064/; classtype:trojan-activity;sid:83685164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"154.0.129.134"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822054/; classtype:trojan-activity;sid:83685154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822007)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"200.122.211.138"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822007/; classtype:trojan-activity;sid:83685107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822004)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"94.251.5.51"; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822004/; classtype:trojan-activity;sid:83685104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"77.89.245.118"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822006/; classtype:trojan-activity;sid:83685106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"178.188.30.171"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821976/; classtype:trojan-activity;sid:83685076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"36.92.68.241"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821977/; classtype:trojan-activity;sid:83685077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"212.73.75.84"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821967/; classtype:trojan-activity;sid:83685067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821963)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"91.204.154.197"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821963/; classtype:trojan-activity;sid:83685063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821949)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"154.0.129.114"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821949/; classtype:trojan-activity;sid:83685049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821860)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.148.18.218"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821860/; classtype:trojan-activity;sid:83684960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821841)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.69.219.25"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821841/; classtype:trojan-activity;sid:83684941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821834)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"194.183.186.164"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821834/; classtype:trojan-activity;sid:83684934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821836)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"81.16.242.236"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821836/; classtype:trojan-activity;sid:83684936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.148.20.138"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821829/; classtype:trojan-activity;sid:83684929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821806)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"154.0.129.134"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821806/; classtype:trojan-activity;sid:83684906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821807)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.148.18.220"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821807/; classtype:trojan-activity;sid:83684907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"196.41.63.178"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821800/; classtype:trojan-activity;sid:83684900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821772)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"185.236.46.120"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821772/; classtype:trojan-activity;sid:83684872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821760)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"188.72.6.218"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821760/; classtype:trojan-activity;sid:83684860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.211.252.34"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821755/; classtype:trojan-activity;sid:83684855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821740)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.151.143.2"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821740/; classtype:trojan-activity;sid:83684840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"178.188.30.171"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821737/; classtype:trojan-activity;sid:83684837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821729)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.53.164.46"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821729/; classtype:trojan-activity;sid:83684829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821693)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.5.50.108"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821693/; classtype:trojan-activity;sid:83684793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"193.106.58.174"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821697/; classtype:trojan-activity;sid:83684797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"211.186.82.229"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821699/; classtype:trojan-activity;sid:83684799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821676)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"154.0.129.114"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821676/; classtype:trojan-activity;sid:83684776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821657)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.78.201.3"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821657/; classtype:trojan-activity;sid:83684757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821619)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"200.61.163.235"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821619/; classtype:trojan-activity;sid:83684719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"167.250.193.253"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821627/; classtype:trojan-activity;sid:83684727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821616)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.2.237.104"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821616/; classtype:trojan-activity;sid:83684716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818981)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.252.66.188"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818981/; classtype:trojan-activity;sid:83682081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.71.250.6"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818974/; classtype:trojan-activity;sid:83682074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"78.140.32.219"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818975/; classtype:trojan-activity;sid:83682075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818865)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"41.215.23.222"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818865/; classtype:trojan-activity;sid:83681965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"124.194.46.204"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818833/; classtype:trojan-activity;sid:83681933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818838)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"138.122.43.76"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818838/; classtype:trojan-activity;sid:83681938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"58.145.168.170"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818798/; classtype:trojan-activity;sid:83681898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2817357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1w6j0xeptoliyrblijhnxbm_qnnoptzfw"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_18; reference:url, urlhaus.abuse.ch/url/2817357/; classtype:trojan-activity;sid:83680457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2817356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1nurs33pjxezqhl9ciafopya6u7i1vpkv"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_18; reference:url, urlhaus.abuse.ch/url/2817356/; classtype:trojan-activity;sid:83680456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2817239)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pbhhdf/12/raw/main/keepvid-pro_full2578.exe"; depth:44; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_18; reference:url, urlhaus.abuse.ch/url/2817239/; classtype:trojan-activity;sid:83680339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2814101)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"212.73.75.84"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_16; reference:url, urlhaus.abuse.ch/url/2814101/; classtype:trojan-activity;sid:83677201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2814095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.128.195.138"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_16; reference:url, urlhaus.abuse.ch/url/2814095/; classtype:trojan-activity;sid:83677195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2814082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"195.34.91.22"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_16; reference:url, urlhaus.abuse.ch/url/2814082/; classtype:trojan-activity;sid:83677182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813137)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"77.89.245.118"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813137/; classtype:trojan-activity;sid:83676237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"46.151.56.42"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813107/; classtype:trojan-activity;sid:83676207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813100)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"118.179.121.235"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813100/; classtype:trojan-activity;sid:83676200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813072)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.187.151.107"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813072/; classtype:trojan-activity;sid:83676172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813060)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"41.77.74.90"; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813060/; classtype:trojan-activity;sid:83676160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813049)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.108.84.121"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813049/; classtype:trojan-activity;sid:83676149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813039)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.92.68.241"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813039/; classtype:trojan-activity;sid:83676139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"217.65.15.51"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809149/; classtype:trojan-activity;sid:83672249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809140)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"202.53.164.214"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809140/; classtype:trojan-activity;sid:83672240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"181.49.47.190"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809130/; classtype:trojan-activity;sid:83672230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"36.88.180.115"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809132/; classtype:trojan-activity;sid:83672232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"94.251.5.51"; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809089/; classtype:trojan-activity;sid:83672189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.158.175.214"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809071/; classtype:trojan-activity;sid:83672171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"37.57.33.51"; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808967/; classtype:trojan-activity;sid:83672067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.227.118.45"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808935/; classtype:trojan-activity;sid:83672035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808928)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.170.116.28"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808928/; classtype:trojan-activity;sid:83672028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"154.84.212.18"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808907/; classtype:trojan-activity;sid:83672007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808875)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"217.218.235.202"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808875/; classtype:trojan-activity;sid:83671975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808855)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.12.99.194"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808855/; classtype:trojan-activity;sid:83671955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.245.10.51"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808823/; classtype:trojan-activity;sid:83671923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808814)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"186.154.93.81"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808814/; classtype:trojan-activity;sid:83671914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808710)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"190.113.124.155"; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808710/; classtype:trojan-activity;sid:83671810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808599)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"91.92.82.180"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808599/; classtype:trojan-activity;sid:83671699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808575)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"41.190.69.6"; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808575/; classtype:trojan-activity;sid:83671675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"103.90.207.234"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808492/; classtype:trojan-activity;sid:83671592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808448)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"109.92.143.90"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808448/; classtype:trojan-activity;sid:83671548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808416)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"95.170.119.100"; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808416/; classtype:trojan-activity;sid:83671516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808385)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"43.245.131.27"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808385/; classtype:trojan-activity;sid:83671485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808374)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i"; depth:2; endswith; nocase; http.host; content:"98.103.171.36"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808374/; classtype:trojan-activity;sid:83671474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2807492)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ping"; depth:5; endswith; nocase; http.host; content:"2.57.122.121"; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_10; reference:url, urlhaus.abuse.ch/url/2807492/; classtype:trojan-activity;sid:83670592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2800910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1psjfkavxoi-3yv-87eskdpuwzjd5jomd"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_04; reference:url, urlhaus.abuse.ch/url/2800910/; classtype:trojan-activity;sid:83664010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2800895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1i33affjfkkztyuz_nusrz4jqs45gwzjs"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_04; reference:url, urlhaus.abuse.ch/url/2800895/; classtype:trojan-activity;sid:83663995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2800893)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1pssupirwdhnwaztrwz6_7dw9r4h_zau9"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_04; reference:url, urlhaus.abuse.ch/url/2800893/; classtype:trojan-activity;sid:83663993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2799349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1b3zgfh-ofoq4nkifk7j0manbu5aqvhet"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_02; reference:url, urlhaus.abuse.ch/url/2799349/; classtype:trojan-activity;sid:83662449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2799230)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1oe1ixppk9tdxfmairsjhsacdgh2litag"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_02; reference:url, urlhaus.abuse.ch/url/2799230/; classtype:trojan-activity;sid:83662330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2799188)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1osqxhd1ncdyo-hhavradwbm9_itb2p49"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_02; reference:url, urlhaus.abuse.ch/url/2799188/; classtype:trojan-activity;sid:83662288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2798325)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/armv7l"; depth:7; endswith; nocase; http.host; content:"75.119.134.80"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_01; reference:url, urlhaus.abuse.ch/url/2798325/; classtype:trojan-activity;sid:83661425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2798324)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i386"; depth:5; endswith; nocase; http.host; content:"75.119.134.80"; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_01; reference:url, urlhaus.abuse.ch/url/2798324/; classtype:trojan-activity;sid:83661424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2798232)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1_gv_k0ynz9_n6h6n7bvistk9oi2njezj"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_01; reference:url, urlhaus.abuse.ch/url/2798232/; classtype:trojan-activity;sid:83661332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2795037)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=171-yky-j89krighojrmmetm69vbmd5m4"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2795037/; classtype:trojan-activity;sid:83658137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2794611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1l-zoyasmfcwfa655dud7ekudjq3ywquk"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2794611/; classtype:trojan-activity;sid:83657711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2794606)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1smjsns4djerxm11i8rx6ldttpsynidio"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2794606/; classtype:trojan-activity;sid:83657706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2794563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1uzj6rbkjyyfcvpddyaduabxfay7w4_9w"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2794563/; classtype:trojan-activity;sid:83657663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2793641)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1t36pjqs33b0q_k78zbmxjrlbrzkssrbu"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_27; reference:url, urlhaus.abuse.ch/url/2793641/; classtype:trojan-activity;sid:83656741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2793611)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1x6cd0z6l79ciefoo627uiws_6yscm_xn"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_27; reference:url, urlhaus.abuse.ch/url/2793611/; classtype:trojan-activity;sid:83656711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2793603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1qxwff0k49bjdhwzotirkvqlqhebzgphg"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_27; reference:url, urlhaus.abuse.ch/url/2793603/; classtype:trojan-activity;sid:83656703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2792386)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=19-hbu_sfsiwgjfm4yp1k22atk3nmwao8"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_25; reference:url, urlhaus.abuse.ch/url/2792386/; classtype:trojan-activity;sid:83655486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2792375)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1p5myromjprou5-vehst_hpzb7pbwagjw"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_25; reference:url, urlhaus.abuse.ch/url/2792375/; classtype:trojan-activity;sid:83655475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2792369)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1tnxrxchvmoxftew7sl3fr0m9yw4o3x2x"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_25; reference:url, urlhaus.abuse.ch/url/2792369/; classtype:trojan-activity;sid:83655469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2790578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.index/scan.tar"; depth:16; endswith; nocase; http.host; content:"58.216.207.82"; depth:13; isdataat:!1,relative; metadata:created_at 2024_03_23; reference:url, urlhaus.abuse.ch/url/2790578/; classtype:trojan-activity;sid:83653678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2789734)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ugl_xjshxerwwbal1fatflznekorqco5"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_22; reference:url, urlhaus.abuse.ch/url/2789734/; classtype:trojan-activity;sid:83652834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2789249)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1aygcpsnow8esde5bkkuaj0bygkowvttd"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_21; reference:url, urlhaus.abuse.ch/url/2789249/; classtype:trojan-activity;sid:83652349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2787791)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ykwsyyt/help/hddrive1095_xinanplug3030_20230619_inno.exe"; depth:57; endswith; nocase; http.host; content:"60.22.23.50"; depth:11; isdataat:!1,relative; metadata:created_at 2024_03_20; reference:url, urlhaus.abuse.ch/url/2787791/; classtype:trojan-activity;sid:83650891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2787399)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1stvkjdfiwxw79oezmc62wzmjjaeftyze"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_20; reference:url, urlhaus.abuse.ch/url/2787399/; classtype:trojan-activity;sid:83650499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2787397)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1hditwve1kadzeycbldxttxi4mmhddgyp"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_20; reference:url, urlhaus.abuse.ch/url/2787397/; classtype:trojan-activity;sid:83650497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2787024)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bash"; depth:5; endswith; nocase; http.host; content:"65.49.44.84"; depth:11; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2787024/; classtype:trojan-activity;sid:83650124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2786866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1udpahhkabfdjz32b558xh_lwxs0snowc"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2786866/; classtype:trojan-activity;sid:83649966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2786829)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1re9cqjrafya6wcb5e0zcolwdorvsf9pi"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2786829/; classtype:trojan-activity;sid:83649929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2786663)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/washywashy14/7zip-bin/master/win/er5thygfd.zip"; depth:47; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2786663/; classtype:trojan-activity;sid:83649763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2786661)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/washywashy14/7zip-bin/master/win/uemlxaw.zip"; depth:45; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2786661/; classtype:trojan-activity;sid:83649761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2785768)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zev3n/ubuntu-gnome-privilege-escalation/main/cve-2020-1612%5b6_7%5d_exploit.sh"; depth:79; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2024_03_18; reference:url, urlhaus.abuse.ch/url/2785768/; classtype:trojan-activity;sid:83648868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2785466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/licensing/deployment/yellow%20pages%20scraper.exe"; depth:50; endswith; nocase; http.host; content:"www.blackhattoolz.com"; depth:21; isdataat:!1,relative; metadata:created_at 2024_03_18; reference:url, urlhaus.abuse.ch/url/2785466/; classtype:trojan-activity;sid:83648566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2785447)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/licensing/updates/tinder%20bot.exe"; depth:35; endswith; nocase; http.host; content:"www.blackhattoolz.com"; depth:21; isdataat:!1,relative; metadata:created_at 2024_03_18; reference:url, urlhaus.abuse.ch/url/2785447/; classtype:trojan-activity;sid:83648547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2782882)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/driveapplet.exe"; depth:16; endswith; nocase; http.host; content:"noithaticon.vn"; depth:14; isdataat:!1,relative; metadata:created_at 2024_03_14; reference:url, urlhaus.abuse.ch/url/2782882/; classtype:trojan-activity;sid:83645982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2782434)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/17c4755d1d45ed1bb454/8703634058188758823"; depth:41; endswith; nocase; http.host; content:"f24-zfcloud.zdn.vn"; depth:18; isdataat:!1,relative; metadata:created_at 2024_03_13; reference:url, urlhaus.abuse.ch/url/2782434/; classtype:trojan-activity;sid:83645534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2780273)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ge6chcvywbep4kgx_odpxtvfi3vj-zwy"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_11; reference:url, urlhaus.abuse.ch/url/2780273/; classtype:trojan-activity;sid:83643373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2776130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"//pcs/click|3f|adurl=//bamautzky.de/red.php"; depth:43; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_03_05; reference:url, urlhaus.abuse.ch/url/2776130/; classtype:trojan-activity;sid:83639230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2772697)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/x.rar"; depth:11; endswith; nocase; http.host; content:"106.254.250.98"; depth:14; isdataat:!1,relative; metadata:created_at 2024_02_29; reference:url, urlhaus.abuse.ch/url/2772697/; classtype:trojan-activity;sid:83635797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2772689)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/met111.sh"; depth:15; endswith; nocase; http.host; content:"106.254.250.98"; depth:14; isdataat:!1,relative; metadata:created_at 2024_02_29; reference:url, urlhaus.abuse.ch/url/2772689/; classtype:trojan-activity;sid:83635789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2769015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/calendar/down/jeditor/jeditor.exe"; depth:34; endswith; nocase; http.host; content:"www.ojang.pe.kr"; depth:15; isdataat:!1,relative; metadata:created_at 2024_02_24; reference:url, urlhaus.abuse.ch/url/2769015/; classtype:trojan-activity;sid:83632115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765933)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2024/e_r1.bmp"; depth:33; endswith; nocase; http.host; content:"catbaparadisehotel.com.vn"; depth:25; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765933/; classtype:trojan-activity;sid:83629033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765626)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hitmanpro.zip"; depth:14; endswith; nocase; http.host; content:"hitman-pro.ru"; depth:13; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765626/; classtype:trojan-activity;sid:83628726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765602)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f||7c|26|7c|adurl=https://patricstoremegans2.com/"; depth:61; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765602/; classtype:trojan-activity;sid:83628702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765586)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2024/e_default.bmp"; depth:38; endswith; nocase; http.host; content:"catbaparadisehotel.com.vn"; depth:25; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765586/; classtype:trojan-activity;sid:83628686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765431)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.x86_64"; depth:17; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765431/; classtype:trojan-activity;sid:83628531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764512)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.x86_64"; depth:17; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764512/; classtype:trojan-activity;sid:83627612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.i686"; depth:15; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764507/; classtype:trojan-activity;sid:83627607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764508)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.mips"; depth:15; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764508/; classtype:trojan-activity;sid:83627608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764509)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.x86"; depth:14; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764509/; classtype:trojan-activity;sid:83627609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764510)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.arm"; depth:14; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764510/; classtype:trojan-activity;sid:83627610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764511)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.spc"; depth:14; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764511/; classtype:trojan-activity;sid:83627611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763764)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.sh4"; depth:14; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763764/; classtype:trojan-activity;sid:83626864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763765)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.m68k"; depth:15; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763765/; classtype:trojan-activity;sid:83626865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763766)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.powerpc"; depth:18; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763766/; classtype:trojan-activity;sid:83626866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763767)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.sparc"; depth:16; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763767/; classtype:trojan-activity;sid:83626867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763429)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.mipsel"; depth:17; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763429/; classtype:trojan-activity;sid:83626529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763428)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.mips"; depth:15; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763428/; classtype:trojan-activity;sid:83626528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2761815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dt9.txt"; depth:8; endswith; nocase; http.host; content:"delp-heizungsbau.de"; depth:19; isdataat:!1,relative; metadata:created_at 2024_02_15; reference:url, urlhaus.abuse.ch/url/2761815/; classtype:trojan-activity;sid:83624915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.arm5"; depth:15; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760086/; classtype:trojan-activity;sid:83623186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760087)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.arm6"; depth:15; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760087/; classtype:trojan-activity;sid:83623187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.arm7"; depth:15; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760088/; classtype:trojan-activity;sid:83623188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760083)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ri/la.bot.arm"; depth:14; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760083/; classtype:trojan-activity;sid:83623183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760068)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/multi"; depth:6; endswith; nocase; http.host; content:"31.220.3.140"; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760068/; classtype:trojan-activity;sid:83623168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.i686"; depth:15; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754788/; classtype:trojan-activity;sid:83617888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754787)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.spc"; depth:14; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754787/; classtype:trojan-activity;sid:83617887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754786)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.mips"; depth:15; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754786/; classtype:trojan-activity;sid:83617886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.x86"; depth:14; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754784/; classtype:trojan-activity;sid:83617884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.arm"; depth:14; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754785/; classtype:trojan-activity;sid:83617885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754783)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cn/sysnew.x86_64"; depth:17; endswith; nocase; http.host; content:"best.obs.cn-sz1.ctyun.cn"; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754783/; classtype:trojan-activity;sid:83617883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754299)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1wuy2y3vbxibdfqcs6-kx96nocarzixfd"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_31; reference:url, urlhaus.abuse.ch/url/2754299/; classtype:trojan-activity;sid:83617399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2753677)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//projetodegente.com"; depth:40; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_30; reference:url, urlhaus.abuse.ch/url/2753677/; classtype:trojan-activity;sid:83616777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751573)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//higreens.co.in"; depth:36; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_25; reference:url, urlhaus.abuse.ch/url/2751573/; classtype:trojan-activity;sid:83614673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//kavyasourcing.com/"; depth:40; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_25; reference:url, urlhaus.abuse.ch/url/2751543/; classtype:trojan-activity;sid:83614643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751237)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=https://cliffg.me"; depth:37; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_24; reference:url, urlhaus.abuse.ch/url/2751237/; classtype:trojan-activity;sid:83614337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; endswith; nocase; http.host; content:"streammobs.com"; depth:14; isdataat:!1,relative; metadata:created_at 2024_01_24; reference:url, urlhaus.abuse.ch/url/2751172/; classtype:trojan-activity;sid:83614272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=https://streammobs.com/"; depth:43; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_24; reference:url, urlhaus.abuse.ch/url/2751171/; classtype:trojan-activity;sid:83614271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749355)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=https://redeamazoniaazul.org/"; depth:49; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_18; reference:url, urlhaus.abuse.ch/url/2749355/; classtype:trojan-activity;sid:83612455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749356)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//www.jd-forever.com/"; depth:41; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_18; reference:url, urlhaus.abuse.ch/url/2749356/; classtype:trojan-activity;sid:83612456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749357)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//old.umcl.us/"; depth:34; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_18; reference:url, urlhaus.abuse.ch/url/2749357/; classtype:trojan-activity;sid:83612457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749182)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=https://wegrowcoaching.com/"; depth:47; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_17; reference:url, urlhaus.abuse.ch/url/2749182/; classtype:trojan-activity;sid:83612282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=https://dongyu.us/"; depth:38; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_17; reference:url, urlhaus.abuse.ch/url/2749177/; classtype:trojan-activity;sid:83612277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1lrviuk1wka4di3qh7ach-b7m1ics2hbp"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_16; reference:url, urlhaus.abuse.ch/url/2749054/; classtype:trojan-activity;sid:83612154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748605)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ssslllap1/asdasd/raw/main/crypted.exe"; depth:38; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2024_01_13; reference:url, urlhaus.abuse.ch/url/2748605/; classtype:trojan-activity;sid:83611705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ifvzub1blhmwsirshbe2wu5b1tus3ls-"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_12; reference:url, urlhaus.abuse.ch/url/2748365/; classtype:trojan-activity;sid:83611465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1yydiodtw09banou13ro8ielf9rcmljxy"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_12; reference:url, urlhaus.abuse.ch/url/2748363/; classtype:trojan-activity;sid:83611463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748360)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=11cbyky_wegqjut6afr8jannw7vub-xxf"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_12; reference:url, urlhaus.abuse.ch/url/2748360/; classtype:trojan-activity;sid:83611460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1gv5qahzp_toxgct3ezfvvy4q3a5vvh6s"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_12; reference:url, urlhaus.abuse.ch/url/2748349/; classtype:trojan-activity;sid:83611449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2747896)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//vaibhavtripathi.in"; depth:40; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_10; reference:url, urlhaus.abuse.ch/url/2747896/; classtype:trojan-activity;sid:83610996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2747890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//procuratio.nu/"; depth:36; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_10; reference:url, urlhaus.abuse.ch/url/2747890/; classtype:trojan-activity;sid:83610990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2747826)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1u-vaalebjnomuhbyimsdjqctjqfyiwna"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_10; reference:url, urlhaus.abuse.ch/url/2747826/; classtype:trojan-activity;sid:83610926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2743461)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=12rmvuwgpj0dzbb3haoaww2lviavhvb4r"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_12_22; reference:url, urlhaus.abuse.ch/url/2743461/; classtype:trojan-activity;sid:83606561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2742817)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=https://synergyconsulting.us"; depth:48; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2023_12_20; reference:url, urlhaus.abuse.ch/url/2742817/; classtype:trojan-activity;sid:83605917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2742524)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//www.deltabehavioralhealth.org/"; depth:52; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2023_12_19; reference:url, urlhaus.abuse.ch/url/2742524/; classtype:trojan-activity;sid:83605624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2742518)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1k0bqhrtnu4v1yexoni5p1utyjuohmfzm"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_12_19; reference:url, urlhaus.abuse.ch/url/2742518/; classtype:trojan-activity;sid:83605618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2742516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1fhqpevblkipshqumjmsbzeetdzhzxv-j"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_12_19; reference:url, urlhaus.abuse.ch/url/2742516/; classtype:trojan-activity;sid:83605616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2740202)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//balkarsoftware.cubistech.com"; depth:50; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2023_12_13; reference:url, urlhaus.abuse.ch/url/2740202/; classtype:trojan-activity;sid:83603302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2734979)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/404"; depth:4; endswith; nocase; http.host; content:"31.184.194.114"; depth:14; isdataat:!1,relative; metadata:created_at 2023_11_24; reference:url, urlhaus.abuse.ch/url/2734979/; classtype:trojan-activity;sid:83598079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2733212)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=//churchinmanila.org/"; depth:41; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2023_11_20; reference:url, urlhaus.abuse.ch/url/2733212/; classtype:trojan-activity;sid:83596312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2730213)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1sjm5t0ktlepibtv3kgaousspnw3zonom"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_13; reference:url, urlhaus.abuse.ch/url/2730213/; classtype:trojan-activity;sid:83593313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2730069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cronusxd/update/releases/download/programa/universal.cheat.all.games.rar"; depth:73; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2023_11_12; reference:url, urlhaus.abuse.ch/url/2730069/; classtype:trojan-activity;sid:83593169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2729736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=https://posicionamientonatural.es/"; depth:54; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2023_11_10; reference:url, urlhaus.abuse.ch/url/2729736/; classtype:trojan-activity;sid:83592836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2729405)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pcs/click|3f|adurl=https://namaacont.com/"; depth:42; endswith; nocase; http.host; content:"adclick.g.doubleclick.net"; depth:25; isdataat:!1,relative; metadata:created_at 2023_11_09; reference:url, urlhaus.abuse.ch/url/2729405/; classtype:trojan-activity;sid:83592505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2727395)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frankcastle2/0/main/0j"; depth:23; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2023_11_03; reference:url, urlhaus.abuse.ch/url/2727395/; classtype:trojan-activity;sid:83590495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726994)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1lhnnwoydntgqibsykxwgd32s5xftxvfh"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726994/; classtype:trojan-activity;sid:83590094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726921)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1oxpqeutyreby186exx4zeofyz0rjocsp"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726921/; classtype:trojan-activity;sid:83590021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726920)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1e2y5yppu_zjj4o3wmuo-2j8n9lbthkzc"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726920/; classtype:trojan-activity;sid:83590020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726917)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1heka7sgmbcessdhxtvmfwxownz7sipbb"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726917/; classtype:trojan-activity;sid:83590017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726906)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1_ldguopt2cg7fblntw3ltxgtxqtmlflc"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726906/; classtype:trojan-activity;sid:83590006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726907)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=10lygpyju_dlg3x6r9oslzgblshakstl-"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726907/; classtype:trojan-activity;sid:83590007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726777)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1sqvm1xsoranfnvqst_kkdmn8yhgulm4k"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_31; reference:url, urlhaus.abuse.ch/url/2726777/; classtype:trojan-activity;sid:83589877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726774)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1cz1lqyxis4wvr7nlc71ukekxyhj5xu-l"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_31; reference:url, urlhaus.abuse.ch/url/2726774/; classtype:trojan-activity;sid:83589874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1zqzivoxid6wgvjstzd0lg2vxnpnc-puf"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_30; reference:url, urlhaus.abuse.ch/url/2726592/; classtype:trojan-activity;sid:83589692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726432)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drakeo03/rbxfpsunlocker-x64-hotfix1/zip/refs/heads/main"; depth:56; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2023_10_28; reference:url, urlhaus.abuse.ch/url/2726432/; classtype:trojan-activity;sid:83589532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726089)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1gfn3lqd1rvybut4ha-ldl92wt8ysrzfc"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_26; reference:url, urlhaus.abuse.ch/url/2726089/; classtype:trojan-activity;sid:83589189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2722703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/image.png"; depth:10; endswith; nocase; http.host; content:"ircftp.net"; depth:10; isdataat:!1,relative; metadata:created_at 2023_10_20; reference:url, urlhaus.abuse.ch/url/2722703/; classtype:trojan-activity;sid:83585803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2719389)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1satmexzn3qpvqzfxnc-5dtnnn8lihdxh"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_12; reference:url, urlhaus.abuse.ch/url/2719389/; classtype:trojan-activity;sid:83582489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2713056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rter/"; depth:6; endswith; nocase; http.host; content:"tanscarattorneys.co.tz"; depth:22; isdataat:!1,relative; metadata:created_at 2023_09_21; reference:url, urlhaus.abuse.ch/url/2713056/; classtype:trojan-activity;sid:83576156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2708874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/readme.txt"; depth:11; endswith; nocase; http.host; content:"svirtual.sanviatorperu.edu.pe"; depth:29; isdataat:!1,relative; metadata:created_at 2023_09_01; reference:url, urlhaus.abuse.ch/url/2708874/; classtype:trojan-activity;sid:83571974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2702776)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/scler.ttf"; depth:19; endswith; nocase; http.host; content:"scainseto.com.br"; depth:16; isdataat:!1,relative; metadata:created_at 2023_08_08; reference:url, urlhaus.abuse.ch/url/2702776/; classtype:trojan-activity;sid:83565876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2693150)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/housenetshare.exe"; depth:18; endswith; nocase; http.host; content:"stdown.dinju.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_07_31; reference:url, urlhaus.abuse.ch/url/2693150/; classtype:trojan-activity;sid:83556250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2692699)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v2/long-glade-33dc08/original/rump_img.jpeg"; depth:44; endswith; nocase; http.host; content:"cdn.pixelbin.io"; depth:15; isdataat:!1,relative; metadata:created_at 2023_07_30; reference:url, urlhaus.abuse.ch/url/2692699/; classtype:trojan-activity;sid:83555799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2689990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"176.102.192.245"; depth:15; isdataat:!1,relative; metadata:created_at 2023_07_26; reference:url, urlhaus.abuse.ch/url/2689990/; classtype:trojan-activity;sid:83553090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2688262)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"124.194.46.204"; depth:14; isdataat:!1,relative; metadata:created_at 2023_07_23; reference:url, urlhaus.abuse.ch/url/2688262/; classtype:trojan-activity;sid:83551362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2629977)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|confirm=t|7c|26|7c|id=145b1fbjtyee3w1rjsazo7hzcoiiaxzum|7c|26|7c|uuid=eb581596-9566-4a21-b3b6-e6909eb42ff6|7c|26|7c|at=akkf8vzrltviqrn7wljfjcwisgcc:1683793107077"; depth:193; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_05_11; reference:url, urlhaus.abuse.ch/url/2629977/; classtype:trojan-activity;sid:83493077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2615310)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"103.227.118.45"; depth:14; isdataat:!1,relative; metadata:created_at 2023_04_21; reference:url, urlhaus.abuse.ch/url/2615310/; classtype:trojan-activity;sid:83478410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2615287)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"181.49.47.190"; depth:13; isdataat:!1,relative; metadata:created_at 2023_04_21; reference:url, urlhaus.abuse.ch/url/2615287/; classtype:trojan-activity;sid:83478387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2581006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/salatikochen/salatapps/archive/refs/heads/main.zip"; depth:51; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2023_03_22; reference:url, urlhaus.abuse.ch/url/2581006/; classtype:trojan-activity;sid:83444106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2573732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/me/me.js"; depth:9; endswith; nocase; http.host; content:"lumacrea.com"; depth:12; isdataat:!1,relative; metadata:created_at 2023_03_16; reference:url, urlhaus.abuse.ch/url/2573732/; classtype:trojan-activity;sid:83436832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2573712)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cor/cor.js"; depth:11; endswith; nocase; http.host; content:"swiftfusion.tech"; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_16; reference:url, urlhaus.abuse.ch/url/2573712/; classtype:trojan-activity;sid:83436812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2572553)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/au/au.js"; depth:9; endswith; nocase; http.host; content:"beak.in"; depth:7; isdataat:!1,relative; metadata:created_at 2023_03_15; reference:url, urlhaus.abuse.ch/url/2572553/; classtype:trojan-activity;sid:83435653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2572505)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ed/ed.js"; depth:9; endswith; nocase; http.host; content:"htdentshop.com"; depth:14; isdataat:!1,relative; metadata:created_at 2023_03_15; reference:url, urlhaus.abuse.ch/url/2572505/; classtype:trojan-activity;sid:83435605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571484)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarica/"; depth:9; endswith; nocase; http.host; content:"gabyagozetim.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571484/; classtype:trojan-activity;sid:83434584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571476)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarica/"; depth:9; endswith; nocase; http.host; content:"riderspin.com"; depth:13; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571476/; classtype:trojan-activity;sid:83434576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connect/"; depth:9; endswith; nocase; http.host; content:"riderspin.com"; depth:13; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571410/; classtype:trojan-activity;sid:83434510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571398)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connect/"; depth:9; endswith; nocase; http.host; content:"records.dennisign.se"; depth:20; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571398/; classtype:trojan-activity;sid:83434498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agenzia/"; depth:9; endswith; nocase; http.host; content:"donkeytourscroatia.com"; depth:22; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571387/; classtype:trojan-activity;sid:83434487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connect/"; depth:9; endswith; nocase; http.host; content:"gabyagozetim.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571323/; classtype:trojan-activity;sid:83434423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agenzia/"; depth:9; endswith; nocase; http.host; content:"gabyagozetim.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571282/; classtype:trojan-activity;sid:83434382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agenzia/"; depth:9; endswith; nocase; http.host; content:"twu-hwt.org"; depth:11; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571166/; classtype:trojan-activity;sid:83434266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571162)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarica/"; depth:9; endswith; nocase; http.host; content:"admin.byte.in.ua"; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571162/; classtype:trojan-activity;sid:83434262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571158)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agenzia/"; depth:9; endswith; nocase; http.host; content:"records.dennisign.se"; depth:20; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571158/; classtype:trojan-activity;sid:83434258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571135)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connect/"; depth:9; endswith; nocase; http.host; content:"donkeytourscroatia.com"; depth:22; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571135/; classtype:trojan-activity;sid:83434235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571043)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarica/"; depth:9; endswith; nocase; http.host; content:"donkeytourscroatia.com"; depth:22; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571043/; classtype:trojan-activity;sid:83434143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570990)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/agenzia/"; depth:9; endswith; nocase; http.host; content:"riderspin.com"; depth:13; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570990/; classtype:trojan-activity;sid:83434090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570811)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connect/"; depth:9; endswith; nocase; http.host; content:"twu-hwt.org"; depth:11; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570811/; classtype:trojan-activity;sid:83433911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connect/"; depth:9; endswith; nocase; http.host; content:"admin.byte.in.ua"; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570642/; classtype:trojan-activity;sid:83433742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarica/"; depth:9; endswith; nocase; http.host; content:"embedone.com"; depth:12; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570563/; classtype:trojan-activity;sid:83433663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570501)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarica/"; depth:9; endswith; nocase; http.host; content:"records.dennisign.se"; depth:20; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570501/; classtype:trojan-activity;sid:83433601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570450)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scarica/"; depth:9; endswith; nocase; http.host; content:"twu-hwt.org"; depth:11; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570450/; classtype:trojan-activity;sid:83433550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/almr/almr.js"; depth:13; endswith; nocase; http.host; content:"abdulahad.net"; depth:13; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570115/; classtype:trojan-activity;sid:83433215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2568876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teev/teev.js"; depth:13; endswith; nocase; http.host; content:"nusatoyota.co.id"; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_13; reference:url, urlhaus.abuse.ch/url/2568876/; classtype:trojan-activity;sid:83431976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2545788)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tedburke/commandcam/archive/refs/heads/master.zip"; depth:50; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2023_02_20; reference:url, urlhaus.abuse.ch/url/2545788/; classtype:trojan-activity;sid:83408888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2540034)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unlockteame/unlimited/zip/refs/heads/main"; depth:42; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2023_02_14; reference:url, urlhaus.abuse.ch/url/2540034/; classtype:trojan-activity;sid:83403134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2532808)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/connect/index.php"; depth:18; endswith; nocase; http.host; content:"gabyagozetim.com"; depth:16; isdataat:!1,relative; metadata:created_at 2023_02_07; reference:url, urlhaus.abuse.ch/url/2532808/; classtype:trojan-activity;sid:83395908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2440082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moom825/discord-rat-2.0/raw/master/discord%20rat/resources/token%20grabber.dll"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2022_11_30; reference:url, urlhaus.abuse.ch/url/2440082/; classtype:trojan-activity;sid:83303182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2440081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/moom825/discord-rat-2.0/raw/master/discord%20rat/resources/passwordstealer.dll"; depth:79; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2022_11_30; reference:url, urlhaus.abuse.ch/url/2440081/; classtype:trojan-activity;sid:83303181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2425972)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|confirm=no_antivirus|7c|26|7c|id=1cpaqimeblbmxrxoli6d3cczgkrbzpy8_"; depth:98; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2022_11_18; reference:url, urlhaus.abuse.ch/url/2425972/; classtype:trojan-activity;sid:83289072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2408069)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/analytics/zy5ntk/"; depth:18; endswith; nocase; http.host; content:"fromthetrenchesworldreport.com"; depth:30; isdataat:!1,relative; metadata:created_at 2022_11_11; reference:url, urlhaus.abuse.ch/url/2408069/; classtype:trojan-activity;sid:83271169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2406761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/dl/wpoxoxqe2in4fju/doc7november00065.js"; depth:42; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2022_11_10; reference:url, urlhaus.abuse.ch/url/2406761/; classtype:trojan-activity;sid:83269861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2393391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/block-supports/5.png"; depth:33; endswith; nocase; http.host; content:"fullstacknir.com"; depth:16; isdataat:!1,relative; metadata:created_at 2022_11_01; reference:url, urlhaus.abuse.ch/url/2393391/; classtype:trojan-activity;sid:83256491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2302899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/janchuk/voidrat/raw/master/voidrat.exe"; depth:39; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2022_09_14; reference:url, urlhaus.abuse.ch/url/2302899/; classtype:trojan-activity;sid:83165999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2252574)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/updates1/up.exe"; depth:16; endswith; nocase; http.host; content:"1717.1000uc.com"; depth:15; isdataat:!1,relative; metadata:created_at 2022_06_30; reference:url, urlhaus.abuse.ch/url/2252574/; classtype:trojan-activity;sid:83115674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2250908)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ema_kvcebm137.bin"; depth:18; endswith; nocase; http.host; content:"mersped.mycpanel.rs"; depth:19; isdataat:!1,relative; metadata:created_at 2022_06_27; reference:url, urlhaus.abuse.ch/url/2250908/; classtype:trojan-activity;sid:83114008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2246139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"178.219.38.228"; depth:14; isdataat:!1,relative; metadata:created_at 2022_06_20; reference:url, urlhaus.abuse.ch/url/2246139/; classtype:trojan-activity;sid:83109239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2237175)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cg100/cg100.exe"; depth:16; endswith; nocase; http.host; content:"update.cg100iii.com"; depth:19; isdataat:!1,relative; metadata:created_at 2022_06_14; reference:url, urlhaus.abuse.ch/url/2237175/; classtype:trojan-activity;sid:83100275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2237174)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgmb/benzmonster.exe"; depth:21; endswith; nocase; http.host; content:"update.cg100iii.com"; depth:19; isdataat:!1,relative; metadata:created_at 2022_06_14; reference:url, urlhaus.abuse.ch/url/2237174/; classtype:trojan-activity;sid:83100274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2230406)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/newsales/adm_atu.exe"; depth:26; endswith; nocase; http.host; content:"palharesinformatica.com.br"; depth:26; isdataat:!1,relative; metadata:created_at 2022_06_08; reference:url, urlhaus.abuse.ch/url/2230406/; classtype:trojan-activity;sid:83093506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2171312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/verkaufsberater_service/ozrw36a2y1ch2cluzy/"; depth:44; endswith; nocase; http.host; content:"farschid.de"; depth:11; isdataat:!1,relative; metadata:created_at 2022_04_29; reference:url, urlhaus.abuse.ch/url/2171312/; classtype:trojan-activity;sid:83034412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2164668)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/verkaufsberater_service/uadjw/"; depth:31; endswith; nocase; http.host; content:"farschid.de"; depth:11; isdataat:!1,relative; metadata:created_at 2022_04_26; reference:url, urlhaus.abuse.ch/url/2164668/; classtype:trojan-activity;sid:83027768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2124302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xmrig/xmrig/releases/download/v6.10.0/xmrig-6.10.0-linux-static-x64.tar.gz"; depth:75; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2022_03_31; reference:url, urlhaus.abuse.ch/url/2124302/; classtype:trojan-activity;sid:82987402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2119354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/verkaufsberater_service/3cxmq4uaxy/"; depth:36; endswith; nocase; http.host; content:"farschid.de"; depth:11; isdataat:!1,relative; metadata:created_at 2022_03_29; reference:url, urlhaus.abuse.ch/url/2119354/; classtype:trojan-activity;sid:82982454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2119353)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/verkaufsberater_service/3cxmq4uaxy/|3f|i=1"; depth:43; endswith; nocase; http.host; content:"farschid.de"; depth:11; isdataat:!1,relative; metadata:created_at 2022_03_29; reference:url, urlhaus.abuse.ch/url/2119353/; classtype:trojan-activity;sid:82982453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2114263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/plugins/yjmqxmidki/a/hyehwggs.ps1"; depth:45; endswith; nocase; http.host; content:"trtmyanmar.com"; depth:14; isdataat:!1,relative; metadata:created_at 2022_03_24; reference:url, urlhaus.abuse.ch/url/2114263/; classtype:trojan-activity;sid:82977363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2109541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/23"; depth:11; endswith; nocase; http.host; content:"182.52.51.239"; depth:13; isdataat:!1,relative; metadata:created_at 2022_03_21; reference:url, urlhaus.abuse.ch/url/2109541/; classtype:trojan-activity;sid:82972641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2109542)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/23s"; depth:12; endswith; nocase; http.host; content:"182.52.51.239"; depth:13; isdataat:!1,relative; metadata:created_at 2022_03_21; reference:url, urlhaus.abuse.ch/url/2109542/; classtype:trojan-activity;sid:82972642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2086235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1gvnzexvvs3vpv0-ihflwnmzmhij3qqly"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2022_03_09; reference:url, urlhaus.abuse.ch/url/2086235/; classtype:trojan-activity;sid:82949335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2053942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zp-user/protected%20client.js"; depth:30; endswith; nocase; http.host; content:"dreamwatchevent.com"; depth:19; isdataat:!1,relative; metadata:created_at 2022_02_22; reference:url, urlhaus.abuse.ch/url/2053942/; classtype:trojan-activity;sid:82917042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2021785)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hksweep/vendor/font-awesome/svgs/brands/subtraction.php"; depth:56; endswith; nocase; http.host; content:"rxquickpay.com"; depth:14; isdataat:!1,relative; metadata:created_at 2022_02_01; reference:url, urlhaus.abuse.ch/url/2021785/; classtype:trojan-activity;sid:82884885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2021799)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/src/js/scripts/gallery/photo-swipe/retraction.php"; depth:50; endswith; nocase; http.host; content:"acms.saleseos.com"; depth:17; isdataat:!1,relative; metadata:created_at 2022_02_01; reference:url, urlhaus.abuse.ch/url/2021799/; classtype:trojan-activity;sid:82884899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2021757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/src/js/scripts/gallery/photo-swipe/highlight.php"; depth:49; endswith; nocase; http.host; content:"acms.saleseos.com"; depth:17; isdataat:!1,relative; metadata:created_at 2022_02_01; reference:url, urlhaus.abuse.ch/url/2021757/; classtype:trojan-activity;sid:82884857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2021704)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/src/js/scripts/gallery/photo-swipe/zany.php"; depth:44; endswith; nocase; http.host; content:"acms.saleseos.com"; depth:17; isdataat:!1,relative; metadata:created_at 2022_02_01; reference:url, urlhaus.abuse.ch/url/2021704/; classtype:trojan-activity;sid:82884804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2021723)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/app/webroot/assets/global/plugins/jquery-file-upload/server/php/files/dwarves.php"; depth:82; endswith; nocase; http.host; content:"tpp.om-stock.com"; depth:16; isdataat:!1,relative; metadata:created_at 2022_02_01; reference:url, urlhaus.abuse.ch/url/2021723/; classtype:trojan-activity;sid:82884823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2019377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/public/userbackend/plugins/dropzone/min/assents.php"; depth:52; endswith; nocase; http.host; content:"theholidayroads.com"; depth:19; isdataat:!1,relative; metadata:created_at 2022_01_31; reference:url, urlhaus.abuse.ch/url/2019377/; classtype:trojan-activity;sid:82882477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2019378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/public/userbackend/plugins/dropzone/min/tautly.php"; depth:51; endswith; nocase; http.host; content:"theholidayroads.com"; depth:19; isdataat:!1,relative; metadata:created_at 2022_01_31; reference:url, urlhaus.abuse.ch/url/2019378/; classtype:trojan-activity;sid:82882478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2019365)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/public/userbackend/plugins/dropzone/min/knave.php"; depth:50; endswith; nocase; http.host; content:"theholidayroads.com"; depth:19; isdataat:!1,relative; metadata:created_at 2022_01_31; reference:url, urlhaus.abuse.ch/url/2019365/; classtype:trojan-activity;sid:82882465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2019358)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/public/userbackend/plugins/dropzone/min/stare.php"; depth:50; endswith; nocase; http.host; content:"theholidayroads.com"; depth:19; isdataat:!1,relative; metadata:created_at 2022_01_31; reference:url, urlhaus.abuse.ch/url/2019358/; classtype:trojan-activity;sid:82882458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2008178)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/comply.php"; depth:11; endswith; nocase; http.host; content:"www.crazywickedaddiction.com"; depth:28; isdataat:!1,relative; metadata:created_at 2022_01_27; reference:url, urlhaus.abuse.ch/url/2008178/; classtype:trojan-activity;sid:82871278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2008138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/squalid.php"; depth:12; endswith; nocase; http.host; content:"continentalgroup.net.in"; depth:23; isdataat:!1,relative; metadata:created_at 2022_01_27; reference:url, urlhaus.abuse.ch/url/2008138/; classtype:trojan-activity;sid:82871238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2008130)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/development/public/uploads/images/categories/beirut.php"; depth:56; endswith; nocase; http.host; content:"www.crazywickedaddiction.com"; depth:28; isdataat:!1,relative; metadata:created_at 2022_01_27; reference:url, urlhaus.abuse.ch/url/2008130/; classtype:trojan-activity;sid:82871230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891112)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/honduras.php"; depth:13; endswith; nocase; http.host; content:"xenon.studio"; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891112/; classtype:trojan-activity;sid:82754212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891095)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/assets2/theme/css/gluttonous.php"; depth:33; endswith; nocase; http.host; content:"xenon.studio"; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891095/; classtype:trojan-activity;sid:82754195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/searching.php"; depth:14; endswith; nocase; http.host; content:"xenon.studio"; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891066/; classtype:trojan-activity;sid:82754166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/assets2/theme/css/linearization.php"; depth:36; endswith; nocase; http.host; content:"xenon.studio"; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891070/; classtype:trojan-activity;sid:82754170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891071)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wrongdoer.php"; depth:14; endswith; nocase; http.host; content:"xenon.studio"; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891071/; classtype:trojan-activity;sid:82754171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1890257)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lib/crypta.js"; depth:14; endswith; nocase; http.host; content:"reauthenticator.com"; depth:19; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1890257/; classtype:trojan-activity;sid:82753357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/actionably.php"; depth:15; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888166/; classtype:trojan-activity;sid:82751266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888149)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/roughness.php"; depth:14; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888149/; classtype:trojan-activity;sid:82751249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888139)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/intermission.php"; depth:17; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888139/; classtype:trojan-activity;sid:82751239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/redesign.php"; depth:13; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888114/; classtype:trojan-activity;sid:82751214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888115)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/antienuretic.php"; depth:17; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888115/; classtype:trojan-activity;sid:82751215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fizz.php"; depth:9; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888106/; classtype:trojan-activity;sid:82751206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888086)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/designer.php"; depth:13; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888086/; classtype:trojan-activity;sid:82751186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888092)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frustrating.php"; depth:16; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888092/; classtype:trojan-activity;sid:82751192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888081)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/conditioner.php"; depth:16; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888081/; classtype:trojan-activity;sid:82751181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888082)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unthinkably.php"; depth:16; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888082/; classtype:trojan-activity;sid:82751182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unexplainable.php"; depth:18; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888084/; classtype:trojan-activity;sid:82751184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1888085)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whiz.php"; depth:9; endswith; nocase; http.host; content:"kramersmarionnettes.com"; depth:23; isdataat:!1,relative; metadata:created_at 2021_12_15; reference:url, urlhaus.abuse.ch/url/1888085/; classtype:trojan-activity;sid:82751185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1839228)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sublimely.php"; depth:14; endswith; nocase; http.host; content:"muledo.com"; depth:10; isdataat:!1,relative; metadata:created_at 2021_12_01; reference:url, urlhaus.abuse.ch/url/1839228/; classtype:trojan-activity;sid:82702328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1837873)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/investigative.php"; depth:18; endswith; nocase; http.host; content:"muledo.com"; depth:10; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1837873/; classtype:trojan-activity;sid:82700973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1773622)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/semitrailer.php"; depth:16; endswith; nocase; http.host; content:"muledo.com"; depth:10; isdataat:!1,relative; metadata:created_at 2021_11_10; reference:url, urlhaus.abuse.ch/url/1773622/; classtype:trojan-activity;sid:82636722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1773603)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/donkey.php"; depth:11; endswith; nocase; http.host; content:"muledo.com"; depth:10; isdataat:!1,relative; metadata:created_at 2021_11_10; reference:url, urlhaus.abuse.ch/url/1773603/; classtype:trojan-activity;sid:82636703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1761107)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/svr_netchecker/server.asp|3f|v_command=3002|7c|26|7c|v_progname=sjptmanagerlauncher.exe"; depth:88; endswith; nocase; http.host; content:"server.toeicswt.co.kr"; depth:21; isdataat:!1,relative; metadata:created_at 2021_11_07; reference:url, urlhaus.abuse.ch/url/1761107/; classtype:trojan-activity;sid:82624207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1744285)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/chimney.php"; depth:12; endswith; nocase; http.host; content:"lawfirm.paperbirdtech.com"; depth:25; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1744285/; classtype:trojan-activity;sid:82607385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1743733)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zoologies.php"; depth:14; endswith; nocase; http.host; content:"bridgeroad.maverickpreviews.com"; depth:31; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1743733/; classtype:trojan-activity;sid:82606833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1743713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/whacked.php"; depth:12; endswith; nocase; http.host; content:"bridgeroad.maverickpreviews.com"; depth:31; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1743713/; classtype:trojan-activity;sid:82606813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1743650)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toggle.php"; depth:11; endswith; nocase; http.host; content:"lawfirm.paperbirdtech.com"; depth:25; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1743650/; classtype:trojan-activity;sid:82606750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1743660)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unplug.php"; depth:11; endswith; nocase; http.host; content:"bridgeroad.maverickpreviews.com"; depth:31; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1743660/; classtype:trojan-activity;sid:82606760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1704978)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download|3f|cid=04a3894062e7d373|7c|26|7c|resid=4a3894062e7d373%21192|7c|26|7c|authkey=ab7i1w77n6tsb3m"; depth:103; endswith; nocase; http.host; content:"onedrive.live.com"; depth:17; isdataat:!1,relative; metadata:created_at 2021_10_21; reference:url, urlhaus.abuse.ch/url/1704978/; classtype:trojan-activity;sid:82568078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1698617)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download|3f|cid=75ea534baf13442d|7c|26|7c|resid=75ea534baf13442d%21128|7c|26|7c|authkey=akd4vmzywc14zgq|7c|26|7c|em=2"; depth:118; endswith; nocase; http.host; content:"onedrive.live.com"; depth:17; isdataat:!1,relative; metadata:created_at 2021_10_20; reference:url, urlhaus.abuse.ch/url/1698617/; classtype:trojan-activity;sid:82561717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1695302)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download|3f|cid=07e7986a5bf9243c|7c|26|7c|resid=7e7986a5bf9243c%21490|7c|26|7c|authkey=abhawhbvtpoyc2a"; depth:103; endswith; nocase; http.host; content:"onedrive.live.com"; depth:17; isdataat:!1,relative; metadata:created_at 2021_10_19; reference:url, urlhaus.abuse.ch/url/1695302/; classtype:trojan-activity;sid:82558402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1678523)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload/vltktanthutn.exe"; depth:24; endswith; nocase; http.host; content:"kimyen.net"; depth:10; isdataat:!1,relative; metadata:created_at 2021_10_14; reference:url, urlhaus.abuse.ch/url/1678523/; classtype:trojan-activity;sid:82541623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1658131)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download|3f|cid=539bd593e9568c65|7c|26|7c|resid=539bd593e9568c65%21136|7c|26|7c|authkey=aepr2tr-q36tt8u|7c|26|7c|em=2"; depth:118; endswith; nocase; http.host; content:"onedrive.live.com"; depth:17; isdataat:!1,relative; metadata:created_at 2021_10_06; reference:url, urlhaus.abuse.ch/url/1658131/; classtype:trojan-activity;sid:82521231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1658066)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secure.php"; depth:11; endswith; nocase; http.host; content:"deagroup-ks.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_10_06; reference:url, urlhaus.abuse.ch/url/1658066/; classtype:trojan-activity;sid:82521166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1658054)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/approx.php"; depth:11; endswith; nocase; http.host; content:"deagroup-ks.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_10_06; reference:url, urlhaus.abuse.ch/url/1658054/; classtype:trojan-activity;sid:82521154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1657096)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update/ana/update.exe"; depth:22; endswith; nocase; http.host; content:"www.teknoarge.com"; depth:17; isdataat:!1,relative; metadata:created_at 2021_10_06; reference:url, urlhaus.abuse.ch/url/1657096/; classtype:trojan-activity;sid:82520196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1647561)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=12ma_yvbmprts6e_vkfnmwikrnwsarqbw"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_29; reference:url, urlhaus.abuse.ch/url/1647561/; classtype:trojan-activity;sid:82510661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1640507)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download|3f|cid=2cc133e5e8e9b372|7c|26|7c|resid=2cc133e5e8e9b372%21113|7c|26|7c|authkey=agftuffxlpqkaz8|7c|26|7c|em=2"; depth:118; endswith; nocase; http.host; content:"onedrive.live.com"; depth:17; isdataat:!1,relative; metadata:created_at 2021_09_23; reference:url, urlhaus.abuse.ch/url/1640507/; classtype:trojan-activity;sid:82503607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1624890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1o9jg3oqyewncoptigwscdbtfmvtfqygj"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_16; reference:url, urlhaus.abuse.ch/url/1624890/; classtype:trojan-activity;sid:82487990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1619497)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/decapitate.php"; depth:15; endswith; nocase; http.host; content:"tiacreation.club"; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_14; reference:url, urlhaus.abuse.ch/url/1619497/; classtype:trojan-activity;sid:82482597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1604292)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/promethium.php"; depth:15; endswith; nocase; http.host; content:"lawfirm.paperbirdtech.com"; depth:25; isdataat:!1,relative; metadata:created_at 2021_09_09; reference:url, urlhaus.abuse.ch/url/1604292/; classtype:trojan-activity;sid:82467392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1602881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/photon.php"; depth:11; endswith; nocase; http.host; content:"lawfirm.paperbirdtech.com"; depth:25; isdataat:!1,relative; metadata:created_at 2021_09_08; reference:url, urlhaus.abuse.ch/url/1602881/; classtype:trojan-activity;sid:82465981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1602867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/philanthropic.php"; depth:18; endswith; nocase; http.host; content:"lawfirm.paperbirdtech.com"; depth:25; isdataat:!1,relative; metadata:created_at 2021_09_08; reference:url, urlhaus.abuse.ch/url/1602867/; classtype:trojan-activity;sid:82465967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1602778)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wash.php"; depth:9; endswith; nocase; http.host; content:"lawfirm.paperbirdtech.com"; depth:25; isdataat:!1,relative; metadata:created_at 2021_09_08; reference:url, urlhaus.abuse.ch/url/1602778/; classtype:trojan-activity;sid:82465878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582138)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/coon.php"; depth:9; endswith; nocase; http.host; content:"allendostmen.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582138/; classtype:trojan-activity;sid:82445238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582118)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/manly.php"; depth:10; endswith; nocase; http.host; content:"allendostmen.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582118/; classtype:trojan-activity;sid:82445218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582120)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/customary.php"; depth:14; endswith; nocase; http.host; content:"bito.com.pk"; depth:11; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582120/; classtype:trojan-activity;sid:82445220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582106)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lecher.php"; depth:11; endswith; nocase; http.host; content:"allendostmen.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582106/; classtype:trojan-activity;sid:82445206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582084)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tribally.php"; depth:13; endswith; nocase; http.host; content:"bito.com.pk"; depth:11; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582084/; classtype:trojan-activity;sid:82445184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/responsiveness.php"; depth:19; endswith; nocase; http.host; content:"bito.com.pk"; depth:11; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582088/; classtype:trojan-activity;sid:82445188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582075)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/binders.php"; depth:12; endswith; nocase; http.host; content:"bito.com.pk"; depth:11; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582075/; classtype:trojan-activity;sid:82445175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gratifying.php"; depth:15; endswith; nocase; http.host; content:"bito.com.pk"; depth:11; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582059/; classtype:trojan-activity;sid:82445159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582025)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clarinet.php"; depth:13; endswith; nocase; http.host; content:"bito.com.pk"; depth:11; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582025/; classtype:trojan-activity;sid:82445125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582020)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/galosh.php"; depth:11; endswith; nocase; http.host; content:"bito.com.pk"; depth:11; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582020/; classtype:trojan-activity;sid:82445120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582015)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/strobing.php"; depth:13; endswith; nocase; http.host; content:"allendostmen.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582015/; classtype:trojan-activity;sid:82445115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1560761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/safmanager/safman_setup.exe"; depth:38; endswith; nocase; http.host; content:"www.saf-oil.ru"; depth:14; isdataat:!1,relative; metadata:created_at 2021_08_24; reference:url, urlhaus.abuse.ch/url/1560761/; classtype:trojan-activity;sid:82423861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teachable.php"; depth:14; endswith; nocase; http.host; content:"chat-server.maverickpreviews.com"; depth:32; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503427/; classtype:trojan-activity;sid:82366527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503410)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/aggressive.php"; depth:15; endswith; nocase; http.host; content:"chat-server.maverickpreviews.com"; depth:32; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503410/; classtype:trojan-activity;sid:82366510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503377)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/belt.php"; depth:9; endswith; nocase; http.host; content:"bridgeroad.maverickpreviews.com"; depth:31; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503377/; classtype:trojan-activity;sid:82366477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503368)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/anarchical.php"; depth:15; endswith; nocase; http.host; content:"bridgeroad.maverickpreviews.com"; depth:31; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503368/; classtype:trojan-activity;sid:82366468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503361)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/newborn.php"; depth:12; endswith; nocase; http.host; content:"chat-server.maverickpreviews.com"; depth:32; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503361/; classtype:trojan-activity;sid:82366461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ruckus.php"; depth:11; endswith; nocase; http.host; content:"www.cutting-edge.in"; depth:19; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503351/; classtype:trojan-activity;sid:82366451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unanswerable.php"; depth:17; endswith; nocase; http.host; content:"chat-server.maverickpreviews.com"; depth:32; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503338/; classtype:trojan-activity;sid:82366438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503341)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/harass.php"; depth:11; endswith; nocase; http.host; content:"www.cutting-edge.in"; depth:19; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503341/; classtype:trojan-activity;sid:82366441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1473823)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/sweat.php"; depth:10; endswith; nocase; http.host; content:"www.cutting-edge.in"; depth:19; isdataat:!1,relative; metadata:created_at 2021_07_22; reference:url, urlhaus.abuse.ch/url/1473823/; classtype:trojan-activity;sid:82336923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1470181)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/power.txt"; depth:10; endswith; nocase; http.host; content:"103.106.250.161"; depth:15; isdataat:!1,relative; metadata:created_at 2021_07_21; reference:url, urlhaus.abuse.ch/url/1470181/; classtype:trojan-activity;sid:82333281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1422022)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1n8_s6gijerearczwh74blkygodig64eo"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_07_03; reference:url, urlhaus.abuse.ch/url/1422022/; classtype:trojan-activity;sid:82285122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1422010)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1yfqtugahqhqrulwugdekeavffktsl8ci"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_07_03; reference:url, urlhaus.abuse.ch/url/1422010/; classtype:trojan-activity;sid:82285110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1391235)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1sbd1rnw8luztjmsh6gdlzupvyupbopa0|7c|26|7c|revid=0b3yyjts_woklr2vnyxvqohlidxbxn1l2wwjntxfnwvi5v0h3pq"; depth:135; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_23; reference:url, urlhaus.abuse.ch/url/1391235/; classtype:trojan-activity;sid:82254335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1378480)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1ctmywlj5wouiug1wgizy3ke7yj1u0yor|7c|26|7c|revid=0b_t0-zked1mgagxwmxcwywq5q0q1uk1uoxcwaup6l2ovmtdjpq"; depth:135; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_19; reference:url, urlhaus.abuse.ch/url/1378480/; classtype:trojan-activity;sid:82241580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1372338)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1alq8r5tnr6wwiftqa3l6d9fymv7y0g9m"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_06_17; reference:url, urlhaus.abuse.ch/url/1372338/; classtype:trojan-activity;sid:82235438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1364815)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update_vbase/voklight.exe"; depth:26; endswith; nocase; http.host; content:"visam.info"; depth:10; isdataat:!1,relative; metadata:created_at 2021_06_14; reference:url, urlhaus.abuse.ch/url/1364815/; classtype:trojan-activity;sid:82227915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1364597)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/update_vbase/voklightd.exe"; depth:27; endswith; nocase; http.host; content:"visam.info"; depth:10; isdataat:!1,relative; metadata:created_at 2021_06_14; reference:url, urlhaus.abuse.ch/url/1364597/; classtype:trojan-activity;sid:82227697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1350517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1tilqozot07vylvdmmsfs7ia452jwhktj|7c|26|7c|revid=0b7gsmqzks4xkcdjcwhuvatj2qvlvchnmnnovu2ldzstek2jzpq"; depth:135; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_10; reference:url, urlhaus.abuse.ch/url/1350517/; classtype:trojan-activity;sid:82213617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1348672)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1etpmpb2shvuny5dxj5awfpxklxqpbzgx"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_06_10; reference:url, urlhaus.abuse.ch/url/1348672/; classtype:trojan-activity;sid:82211772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1343323)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hoopoe.php"; depth:11; endswith; nocase; http.host; content:"thementordirectory.com"; depth:22; isdataat:!1,relative; metadata:created_at 2021_06_09; reference:url, urlhaus.abuse.ch/url/1343323/; classtype:trojan-activity;sid:82206423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1343313)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hare.php"; depth:9; endswith; nocase; http.host; content:"thementordirectory.com"; depth:22; isdataat:!1,relative; metadata:created_at 2021_06_09; reference:url, urlhaus.abuse.ch/url/1343313/; classtype:trojan-activity;sid:82206413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1343296)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/donate.php"; depth:11; endswith; nocase; http.host; content:"thementordirectory.com"; depth:22; isdataat:!1,relative; metadata:created_at 2021_06_09; reference:url, urlhaus.abuse.ch/url/1343296/; classtype:trojan-activity;sid:82206396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1331376)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1b6t1mjnjcvndcy-mdqq0neqrbocqyju4"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_06_06; reference:url, urlhaus.abuse.ch/url/1331376/; classtype:trojan-activity;sid:82194476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1327898)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inst77player/inst77player_1.0.0.1.exe"; depth:38; endswith; nocase; http.host; content:"softdl.360tpcdn.com"; depth:19; isdataat:!1,relative; metadata:created_at 2021_06_05; reference:url, urlhaus.abuse.ch/url/1327898/; classtype:trojan-activity;sid:82190998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1319551)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1nw1gmzg6lwtuhs0tte969xcfpp9_dc5q"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_06_03; reference:url, urlhaus.abuse.ch/url/1319551/; classtype:trojan-activity;sid:82182651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vszvhw0lywviz_dpqozkdip0orjsf7411ucirwqegcgfxwqqb3nqpbn3d7orqqxnatypulra_ssggie/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314578/; classtype:trojan-activity;sid:82177678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314581)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vr-asdhfa85lnhp1g6rll18x2htnflvy5zggxzrfveecvbhjiwaes9o9w3dn49od7lplixl3u59icjr/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314581/; classtype:trojan-activity;sid:82177681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314569)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vqb__8qdiraoo-s_qrzkk8o_8brsuwaeje3ivcd5efhddlux4gw5otilj5ezfenwjzaha-zojj_7srj/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314569/; classtype:trojan-activity;sid:82177669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314562)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vqha4kutkvbpn1c9r1jolub-v1dyh36itza-2zhojxuluskoxk6iogpy8b8iscqqjskaf3wduc6oykt/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314562/; classtype:trojan-activity;sid:82177662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314563)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vqm_l1o1djktv6pcfwixdz1gjaqrg26rpb3n3uqpk0jqvif91b_irdew7mo34hhhoffbjohoztlmdtp/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314563/; classtype:trojan-activity;sid:82177663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314556)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vrxkt9v4qcom-0wjceb6bexufgpr_vdebkc-kra8h7gutbblset1veguumqxs3npiv4qw-7_1kiy3jm/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314556/; classtype:trojan-activity;sid:82177656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vspnrqtfaftwpvbd8o61fbvozlhc3z0x8jy4glnji-v80xrxnlemgt89l5imnr_7kxst0gn9ydkjj0q/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314548/; classtype:trojan-activity;sid:82177648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vsftpbjz498ict3ab9-tehopymacl8ygytkgufxpnwlfphfxyyh5jmfj_2llrrddsiu8vypu1ksvp5p/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314549/; classtype:trojan-activity;sid:82177649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314543)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vs1h7txewarzqve-jwxnwcgzibofoz58qrk8kerhmfz8mpippgfjeoijthgmm-tw7lwcipr8acup_ft/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314543/; classtype:trojan-activity;sid:82177643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314544)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vr92cz6z4uh71ogqyzgn6vtdc54xoa0iovizmkmogvekyix648nysfipvt4qto6uvtrp9jsatoeuhk3/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314544/; classtype:trojan-activity;sid:82177644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vtuc-a7s7ylxnfwqp8oxz6no5uwdmabudx-6glkwrnzjwqwgdtcpdvwp0x0l03qdarzrzonj_adevlw/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314545/; classtype:trojan-activity;sid:82177645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314534)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vqe1vc-nlfenfgigyaugmmg1dq4l0-haikp9qxkacc32ig0xtg6go8lejdoogo0vfeoie4tcyy4_bn4/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314534/; classtype:trojan-activity;sid:82177634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314535)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vsrvkllojuhzbqokettk0u2b1whglldp35-o1zgt_jlem2z2odwedj0z9sgtukvikdowcuan-0fj5wn/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314535/; classtype:trojan-activity;sid:82177635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314537)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vqvbpr6y2jjnkxfpcwt9uv7pqycg6vdoowr-xnakhtl9ns4tk44rpa91em8usoc992uqyrpn6ucy5ep/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314537/; classtype:trojan-activity;sid:82177637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314526)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vq8kqm4rsobvbpga8ncnzs-1xulwuezfri9x1ktowpiijctqe1uq0iged6iq7sa5zuhnh56egsebkoj/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314526/; classtype:trojan-activity;sid:82177626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287391)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vtecbrofm9hcrdmzz8g7ktneypnrpr1s7bvyoit3r8jd7rjanmysk9yyuhvzmdp3dmkd-xss7kpyffa/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287391/; classtype:trojan-activity;sid:82150491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vt544w_wvxhvfskbx2zio7pht-jzhb1nvr7y1qhtxccjopcfxzhm1mottjhjsdudpgs9lfrjcqzoi8n/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287387/; classtype:trojan-activity;sid:82150487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287378)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vtcfdv_0srlqbmtfzi6hivmikknsfqd5bubuem-s-mzpzfsva62zyncoy-phkzysuhuddl0yhlyajye/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287378/; classtype:trojan-activity;sid:82150478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287373)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vrtnhy8ipm82egefg7zhukj5qwbit31-jlhdsxovff8rcefw2uhpndpuclv_ffrqqdjhxyxympj3ame/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287373/; classtype:trojan-activity;sid:82150473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vt4iy9nlwuov8hsmpykbfkn1fh1ydp7ms8dudg2ldfjgxf8rumdtzgiw7ukoifo3ap-pb7ybzlcdfqi/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287333/; classtype:trojan-activity;sid:82150433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vtyg409rjv4omi3oujyjsc6ajzflluuz37ofzbpjjihmrewoh2ehp2pwbfllgyy_yzqdrldwcaejvd5/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278913/; classtype:trojan-activity;sid:82142013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278910)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vr1e4kzyqneoh2tjc5rh_unlfwjdo31gedrveg0wdyrprmm3yfdxjqxdvyy535adzu5p9m4mrvdau9v/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278910/; classtype:trojan-activity;sid:82142010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278905)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vrvmutaxfc2ewkvy_l_cewfjwv4md_uadqlv4onmlyc0frnp7jod3ru93sm6y-tmoj0nrvbfylt739z/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278905/; classtype:trojan-activity;sid:82142005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278895)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vtpholmraa4dir0lg8z5yhqljwbzp0qkypc3jax6d3l0hs6n23kpm2iqgccjvbvug5th443jjbzs2uv/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278895/; classtype:trojan-activity;sid:82141995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278899)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/d/e/2pacx-1vqyowyoxata2couqa6uc3gwi59sq5maualr7yfmq6luzvtefqopogncbli8hx6vubkt2b65qerqhzy8/pub"; depth:104; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278899/; classtype:trojan-activity;sid:82141999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1237690)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1m8jszvq-ztfrul7vgsb6q-n3ftgnkbdj|7c|26|7c|revid=0bxrhybf9__wnmgjlnmxmunzznlu0v204azc4edmzcep6a0hzpq"; depth:135; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_15; reference:url, urlhaus.abuse.ch/url/1237690/; classtype:trojan-activity;sid:82100790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1233306)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1gv_nk9llqw4fxudo-khja7nuuj1kevvw|7c|26|7c|revid=0b7zefp-g6n7vm0zhowo4be9pvus4mmh0ymxvd3r6zlu3ylznpq"; depth:135; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_14; reference:url, urlhaus.abuse.ch/url/1233306/; classtype:trojan-activity;sid:82096406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1228819)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=140vkyfrfhbqkukc2hnw-gsvi5wjw6iyi"; depth:68; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_13; reference:url, urlhaus.abuse.ch/url/1228819/; classtype:trojan-activity;sid:82091919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1220349)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1h_dyp_d5lst4akyf2qezxl7j1scvbtvs|7c|26|7c|revid=0b5thckui5i0mdk5moelbnm9vuhnydvjnvwpyq01vrg5xvwhrpq"; depth:135; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_11; reference:url, urlhaus.abuse.ch/url/1220349/; classtype:trojan-activity;sid:82083449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1199812)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1uygnpwzzyzn2rodsrimg0-sloxy_letg"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_05_06; reference:url, urlhaus.abuse.ch/url/1199812/; classtype:trojan-activity;sid:82062912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1198558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/view/59bmj3vj18vh2/drive/storage/a/files/download|3f|id=625899581658508733"; depth:75; endswith; nocase; http.host; content:"sites.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2021_05_06; reference:url, urlhaus.abuse.ch/url/1198558/; classtype:trojan-activity;sid:82061658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1182816)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1zxejnkdwqezrbgani5vjk2y2nhmpkg0z|7c|26|7c|revid=0b-bo0wgwxcblsui1mehkbhrlu01rwxnyrxzxanbdendmbndnpq"; depth:135; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1182816/; classtype:trojan-activity;sid:82045916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181763)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload_control/download.blog|3f|fhandle=mep5euraznm5lmjsb2cuzgf1bs5uzxq6l0lnqudflzavns5legu=|7c|26|7c|filename=%ec%9d%b8%ed%84%b0%eb%84%b7_%ec%a2%85%eb%9f%89%ec%a0%9c_%ed%85%8c%ec%8a%a4%ed%8a%b8.exe"; depth:199; endswith; nocase; http.host; content:"cfs9.blog.daum.net"; depth:18; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181763/; classtype:trojan-activity;sid:82044863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload_control/download.blog|3f|fhandle=ymxvzze5mtk5nubmczezlnrpc3rvcnkuy29toi9hdhrhy2gvmc8xnzawmdawmdawmdauzxhl|7c|26|7c|filename=oleaut32.dll%bf%c0%b7%f9%c7%d8%b0%e1%c7%cf%b1%e2.exe"; depth:184; endswith; nocase; http.host; content:"cfs13.tistory.com"; depth:17; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181758/; classtype:trojan-activity;sid:82044858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181756)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload_control/download.blog|3f|fhandle=mdczafhaznmxmc5ibg9nlmrhdw0ubmv0oi9jtufhrs8wlzkwlmv4zq==|7c|26|7c|filename=xp_sp3_%ed%85%8c%eb%a7%88%ed%8c%a8%ec%b9%98.exe"; depth:163; endswith; nocase; http.host; content:"cfs10.blog.daum.net"; depth:19; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181756/; classtype:trojan-activity;sid:82044856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181754)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload_control/download.blog|3f|fhandle=ymxvzze5mtk5nubmczezlnrpc3rvcnkuy29toi9hdhrhy2gvmc8xnzawmdawmdawmdauzxhl|7c|26|7c|filename=oleaut32.dll%ef%bf%bd%ef%bf%bd%ef%bf%bd%ef%bf%bd%ef%bf%bd%d8%b0%ef%bf%bd%ef%bf%bd%cf%b1%ef%bf%bd.exe"; depth:232; endswith; nocase; http.host; content:"cfs13.tistory.com"; depth:17; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181754/; classtype:trojan-activity;sid:82044854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload_control/download.blog|3f|fhandle=metnwe5aznm3lmjsb2cuzgf1bs5uzxq6l0lnqudflzavmc5legu=|7c|26|7c|filename=%ec%9d%b8%ed%84%b0%eb%84%b7_%ec%a2%85%eb%9f%89%ec%a0%9c_%ed%85%8c%ec%8a%a4%ed%8a%b8-cksal16.exe/%ec%9d%b8%ed%84%b0%eb%84%b7_%ec%a2%85%eb%9f%89%ec%a0%9c_%ed%85%8c%ec%8a%a4%ed%8a%b8-cksal16.exe"; depth:303; endswith; nocase; http.host; content:"cfs7.blog.daum.net"; depth:18; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181755/; classtype:trojan-activity;sid:82044855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1152444)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1jpl-uouydm5hypqm67uokyddrblbpxvw|7c|26|7c|revid=0b7zpiprmoc5ubhpwclq0cxdyte5vwtrbymnidznhtgm3bzvrpq"; depth:135; endswith; nocase; http.host; content:"docs.google.com"; depth:15; isdataat:!1,relative; metadata:created_at 2021_04_22; reference:url, urlhaus.abuse.ch/url/1152444/; classtype:trojan-activity;sid:82015544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1139359)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"191.33.171.242"; depth:14; isdataat:!1,relative; metadata:created_at 2021_04_19; reference:url, urlhaus.abuse.ch/url/1139359/; classtype:trojan-activity;sid:82002459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1069008)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/opj5cs64q.rar"; depth:14; endswith; nocase; http.host; content:"outpost.co.ke"; depth:13; isdataat:!1,relative; metadata:created_at 2021_03_15; reference:url, urlhaus.abuse.ch/url/1069008/; classtype:trojan-activity;sid:81932108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1068684)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/njtzac0.tar"; depth:12; endswith; nocase; http.host; content:"mysura.it"; depth:9; isdataat:!1,relative; metadata:created_at 2021_03_15; reference:url, urlhaus.abuse.ch/url/1068684/; classtype:trojan-activity;sid:81931784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (957784)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gamewd/yhdl.exe"; depth:16; endswith; nocase; http.host; content:"download.caihong.com"; depth:20; isdataat:!1,relative; metadata:created_at 2021_01_13; reference:url, urlhaus.abuse.ch/url/957784/; classtype:trojan-activity;sid:81820884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (936427)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/bxjesdj7w3meuh7iatiurbsgh/"; depth:36; endswith; nocase; http.host; content:"cdaonline.com.ar"; depth:16; isdataat:!1,relative; metadata:created_at 2020_12_21; reference:url, urlhaus.abuse.ch/url/936427/; classtype:trojan-activity;sid:81799527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (765703)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/lm/7cfvaaa9jo/"; depth:27; endswith; nocase; http.host; content:"ncxps.com"; depth:9; isdataat:!1,relative; metadata:created_at 2020_10_29; reference:url, urlhaus.abuse.ch/url/765703/; classtype:trojan-activity;sid:81628803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (756747)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/rrrv7ilgm2dzpohaklkhewb8rkju15bmqeewccglap/"; depth:56; endswith; nocase; http.host; content:"ncxps.com"; depth:9; isdataat:!1,relative; metadata:created_at 2020_10_27; reference:url, urlhaus.abuse.ch/url/756747/; classtype:trojan-activity;sid:81619847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (756736)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/4ld2g8w3rrmhtgvvvpeq2orlcqm71yyxveriw5rzitvii3/"; depth:60; endswith; nocase; http.host; content:"ncxps.com"; depth:9; isdataat:!1,relative; metadata:created_at 2020_10_27; reference:url, urlhaus.abuse.ch/url/756736/; classtype:trojan-activity;sid:81619836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (734911)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/esp/"; depth:14; endswith; nocase; http.host; content:"www.steamrub.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_10_22; reference:url, urlhaus.abuse.ch/url/734911/; classtype:trojan-activity;sid:81598011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (733798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/oct/w9hmkanqe5py4r/"; depth:32; endswith; nocase; http.host; content:"ncxps.com"; depth:9; isdataat:!1,relative; metadata:created_at 2020_10_22; reference:url, urlhaus.abuse.ch/url/733798/; classtype:trojan-activity;sid:81596898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (723755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/sites/ci6p05scnuonqslqmehm/"; depth:37; endswith; nocase; http.host; content:"cdaonline.com.ar"; depth:16; isdataat:!1,relative; metadata:created_at 2020_10_20; reference:url, urlhaus.abuse.ch/url/723755/; classtype:trojan-activity;sid:81586855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (637433)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paetools.exe"; depth:13; endswith; nocase; http.host; content:"soft.110route.com"; depth:17; isdataat:!1,relative; metadata:created_at 2020_10_01; reference:url, urlhaus.abuse.ch/url/637433/; classtype:trojan-activity;sid:81500533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (613088)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mikf/gallery-dl/releases/download/v1.15.0/gallery-dl.exe"; depth:57; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2020_09_26; reference:url, urlhaus.abuse.ch/url/613088/; classtype:trojan-activity;sid:81476188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (593578)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/js/jquery/jquery.js"; depth:32; endswith; nocase; http.host; content:"chuguadventures.co.tz"; depth:21; isdataat:!1,relative; metadata:created_at 2020_09_22; reference:url, urlhaus.abuse.ch/url/593578/; classtype:trojan-activity;sid:81456678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (554647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/file/x7z9wbk77tt6v9/"; depth:30; endswith; nocase; http.host; content:"cdaonline.com.ar"; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_18; reference:url, urlhaus.abuse.ch/url/554647/; classtype:trojan-activity;sid:81417747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (490516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; depth:26; endswith; nocase; http.host; content:"cd.textfiles.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_14; reference:url, urlhaus.abuse.ch/url/490516/; classtype:trojan-activity;sid:81353616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (453216)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/enteihacking/mt/master/asycivic.jpg"; depth:36; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2020_09_04; reference:url, urlhaus.abuse.ch/url/453216/; classtype:trojan-activity;sid:81316316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (453035)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1g_x0a_gnyxai5glsipkq1b2mqknanuw8"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_04; reference:url, urlhaus.abuse.ch/url/453035/; classtype:trojan-activity;sid:81316135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (452177)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=14muad9cmj6mxsd9lrccuo1egxyf5f-ty"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_03; reference:url, urlhaus.abuse.ch/url/452177/; classtype:trojan-activity;sid:81315277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (451466)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1yrmkzxf4rmy9utrikbh6rgvsokehbmeo"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_02; reference:url, urlhaus.abuse.ch/url/451466/; classtype:trojan-activity;sid:81314566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (447394)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1sm7b9902i8v4yitepf6gzomqc84ltloi"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_08_31; reference:url, urlhaus.abuse.ch/url/447394/; classtype:trojan-activity;sid:81310494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (446803)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1gavcby-nhlq22ohbgm530exffsrg1aub"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_08_30; reference:url, urlhaus.abuse.ch/url/446803/; classtype:trojan-activity;sid:81309903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (438705)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/file/21mnqlvi/oz88535657v7rbazasyth9x8i/"; depth:49; endswith; nocase; http.host; content:"www.reifenquick.de"; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_21; reference:url, urlhaus.abuse.ch/url/438705/; classtype:trojan-activity;sid:81301805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (436727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/statement/ul397wfyb/"; depth:29; endswith; nocase; http.host; content:"www.reifenquick.de"; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_19; reference:url, urlhaus.abuse.ch/url/436727/; classtype:trojan-activity;sid:81299827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (434592)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/closed_957176_mxqsdoj6a4iz/close_warehouse/ql55hnq09iyn6lm_334stxvw03wyv/"; depth:82; endswith; nocase; http.host; content:"www.reifenquick.de"; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_17; reference:url, urlhaus.abuse.ch/url/434592/; classtype:trojan-activity;sid:81297692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (434320)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/hl8-8w4cs-6325/"; depth:24; endswith; nocase; http.host; content:"reifenquick.de"; depth:14; isdataat:!1,relative; metadata:created_at 2020_08_17; reference:url, urlhaus.abuse.ch/url/434320/; classtype:trojan-activity;sid:81297420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (432117)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/hl8-8w4cs-6325/"; depth:24; endswith; nocase; http.host; content:"www.reifenquick.de"; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_13; reference:url, urlhaus.abuse.ch/url/432117/; classtype:trojan-activity;sid:81295217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (426974)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/images/t55prjrdcx/0y8615606244201084438n0kq7whr/"; depth:49; endswith; nocase; http.host; content:"seismophonic.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_08_07; reference:url, urlhaus.abuse.ch/url/426974/; classtype:trojan-activity;sid:81290074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (426390)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/scripts/open-0627720493640-azq24pffjrm/guarded-space/gxkx9t42ra6yf-6x7uyx330389w/"; depth:82; endswith; nocase; http.host; content:"www.reifenquick.de"; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_06; reference:url, urlhaus.abuse.ch/url/426390/; classtype:trojan-activity;sid:81289490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (422458)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/invoice/aog-3515110/"; depth:21; endswith; nocase; http.host; content:"lindnerelektroanlagen.de"; depth:24; isdataat:!1,relative; metadata:created_at 2020_07_30; reference:url, urlhaus.abuse.ch/url/422458/; classtype:trojan-activity;sid:81285558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (420521)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/css/parts_service/ly944myw/"; depth:28; endswith; nocase; http.host; content:"hitstation.nl"; depth:13; isdataat:!1,relative; metadata:created_at 2020_07_28; reference:url, urlhaus.abuse.ch/url/420521/; classtype:trojan-activity;sid:81283621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (419868)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/paradiselost/statement/s7nr8p8ut/"; depth:34; endswith; nocase; http.host; content:"damiancollier.com"; depth:17; isdataat:!1,relative; metadata:created_at 2020_07_27; reference:url, urlhaus.abuse.ch/url/419868/; classtype:trojan-activity;sid:81282968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (410755)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/d35ha/processhide/master/bins/processhide32.exe"; depth:48; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2020_07_10; reference:url, urlhaus.abuse.ch/url/410755/; classtype:trojan-activity;sid:81273855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (390013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1am1ztjjhswzwdbvue5tke5mbkwjud0w5"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_06_15; reference:url, urlhaus.abuse.ch/url/390013/; classtype:trojan-activity;sid:81253113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (390009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1hd7ffgig6btbzuy2_2kds_t4u637qxjn"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_06_15; reference:url, urlhaus.abuse.ch/url/390009/; classtype:trojan-activity;sid:81253109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (368318)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/threatsim/exe/pdf.exe"; depth:22; endswith; nocase; http.host; content:"0022a601.pphost.net"; depth:19; isdataat:!1,relative; metadata:created_at 2020_05_25; reference:url, urlhaus.abuse.ch/url/368318/; classtype:trojan-activity;sid:81231418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (368317)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/threatsim/doc/774d0427cd607b1c09131cc277a68c9edd7cf01499d356bcb1ef4a08e6fc322a.doc"; depth:83; endswith; nocase; http.host; content:"0022a601.pphost.net"; depth:19; isdataat:!1,relative; metadata:created_at 2020_05_25; reference:url, urlhaus.abuse.ch/url/368317/; classtype:trojan-activity;sid:81231417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (368315)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/threatsim/exe/xerox01_pdf.exe"; depth:30; endswith; nocase; http.host; content:"0022a601.pphost.net"; depth:19; isdataat:!1,relative; metadata:created_at 2020_05_25; reference:url, urlhaus.abuse.ch/url/368315/; classtype:trojan-activity;sid:81231415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (368312)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/threatsim/doc/46cad0e0ca3b2d6d9d3ce691ca2887b18abc80acf0e81799fbb290cce104c8eb.doc"; depth:83; endswith; nocase; http.host; content:"0022a601.pphost.net"; depth:19; isdataat:!1,relative; metadata:created_at 2020_05_25; reference:url, urlhaus.abuse.ch/url/368312/; classtype:trojan-activity;sid:81231412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (368311)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/threatsim/exe/njrat.exe"; depth:24; endswith; nocase; http.host; content:"0022a601.pphost.net"; depth:19; isdataat:!1,relative; metadata:created_at 2020_05_25; reference:url, urlhaus.abuse.ch/url/368311/; classtype:trojan-activity;sid:81231411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (368309)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/threatsim/exe/order_pdf.exe"; depth:28; endswith; nocase; http.host; content:"0022a601.pphost.net"; depth:19; isdataat:!1,relative; metadata:created_at 2020_05_25; reference:url, urlhaus.abuse.ch/url/368309/; classtype:trojan-activity;sid:81231409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (368303)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/threatsim/exe/640.exe"; depth:22; endswith; nocase; http.host; content:"0022a601.pphost.net"; depth:19; isdataat:!1,relative; metadata:created_at 2020_05_25; reference:url, urlhaus.abuse.ch/url/368303/; classtype:trojan-activity;sid:81231403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (366549)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1pyl4hq8sbp5qatm1zz9vmsze1cuy2uzw"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_05_22; reference:url, urlhaus.abuse.ch/url/366549/; classtype:trojan-activity;sid:81229649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (355363)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/u/0/uc|3f|id=1osjrfvjdy1vblk4fya98jp5jlnk7rutv|7c|26|7c|export=download"; depth:72; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_05_01; reference:url, urlhaus.abuse.ch/url/355363/; classtype:trojan-activity;sid:81218463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (351490)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc|3f|export=download|7c|26|7c|id=1nndvq_2_7doyyuqvcvwmory_4lyrplb7"; depth:68; endswith; nocase; http.host; content:"drive.google.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_04_26; reference:url, urlhaus.abuse.ch/url/351490/; classtype:trojan-activity;sid:81214590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (322758)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload_control/download.blog|3f|fhandle=ymxvzzcxmzyyqgzzns50axn0b3j5lmnvbtovyxr0ywnolzavmtqwmdawmdawmdawlmv4zq%3d%3d|7c|26|7c|filename=crack-pro20.exe"; depth:151; endswith; nocase; http.host; content:"cfs5.tistory.com"; depth:16; isdataat:!1,relative; metadata:created_at 2020_03_08; reference:url, urlhaus.abuse.ch/url/322758/; classtype:trojan-activity;sid:81185858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (318948)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; depth:59; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2020_02_26; reference:url, urlhaus.abuse.ch/url/318948/; classtype:trojan-activity;sid:81182048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (318947)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; depth:78; endswith; nocase; http.host; content:"raw.githubusercontent.com"; depth:25; isdataat:!1,relative; metadata:created_at 2020_02_26; reference:url, urlhaus.abuse.ch/url/318947/; classtype:trojan-activity;sid:81182047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (314465)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fta.exe"; depth:8; endswith; nocase; http.host; content:"vincentdemiero.com"; depth:18; isdataat:!1,relative; metadata:created_at 2020_02_14; reference:url, urlhaus.abuse.ch/url/314465/; classtype:trojan-activity;sid:81177565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (314464)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/documeynt9897.zip"; depth:18; endswith; nocase; http.host; content:"vincentdemiero.com"; depth:18; isdataat:!1,relative; metadata:created_at 2020_02_14; reference:url, urlhaus.abuse.ch/url/314464/; classtype:trojan-activity;sid:81177564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (314463)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fvs.zip"; depth:8; endswith; nocase; http.host; content:"vincentdemiero.com"; depth:18; isdataat:!1,relative; metadata:created_at 2020_02_14; reference:url, urlhaus.abuse.ch/url/314463/; classtype:trojan-activity;sid:81177563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (308942)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wordpress/wp-lm9-32/"; depth:21; endswith; nocase; http.host; content:"www.chenwangqiao.com"; depth:20; isdataat:!1,relative; metadata:created_at 2020_02_05; reference:url, urlhaus.abuse.ch/url/308942/; classtype:trojan-activity;sid:81172042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (306649)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wordpress/3waa9-ke38h-15/"; depth:26; endswith; nocase; http.host; content:"www.chenwangqiao.com"; depth:20; isdataat:!1,relative; metadata:created_at 2020_02_03; reference:url, urlhaus.abuse.ch/url/306649/; classtype:trojan-activity;sid:81169749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (304070)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wordpress/file/"; depth:16; endswith; nocase; http.host; content:"www.chenwangqiao.com"; depth:20; isdataat:!1,relative; metadata:created_at 2020_01_31; reference:url, urlhaus.abuse.ch/url/304070/; classtype:trojan-activity;sid:81167170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (273997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-snapshots/sites/gxagnw43b99/"; depth:32; endswith; nocase; http.host; content:"embalageral.hospedagemdesites.ws"; depth:32; isdataat:!1,relative; metadata:created_at 2019_12_20; reference:url, urlhaus.abuse.ch/url/273997/; classtype:trojan-activity;sid:81137097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (272221)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/about/lm/5oj0ss1de/"; depth:20; endswith; nocase; http.host; content:"dezcom.com"; depth:10; isdataat:!1,relative; metadata:created_at 2019_12_19; reference:url, urlhaus.abuse.ch/url/272221/; classtype:trojan-activity;sid:81135321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (267913)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/index_soubory/common_sector/external_area/61551354147_t4d0ky73jjywffgy/"; depth:72; endswith; nocase; http.host; content:"oknoplastik.sk"; depth:14; isdataat:!1,relative; metadata:created_at 2019_12_12; reference:url, urlhaus.abuse.ch/url/267913/; classtype:trojan-activity;sid:81131013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (254738)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cvd/dist/fileupload/1571723382710/9.915787746614242.jpg"; depth:56; endswith; nocase; http.host; content:"cdn.xiaoduoai.com"; depth:17; isdataat:!1,relative; metadata:created_at 2019_11_18; reference:url, urlhaus.abuse.ch/url/254738/; classtype:trojan-activity;sid:81117838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (254737)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cvd/dist/fileupload/1571723350789/0.25579108623802416.jpg"; depth:58; endswith; nocase; http.host; content:"cdn.xiaoduoai.com"; depth:17; isdataat:!1,relative; metadata:created_at 2019_11_18; reference:url, urlhaus.abuse.ch/url/254737/; classtype:trojan-activity;sid:81117837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (240568)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"94.244.113.217"; depth:14; isdataat:!1,relative; metadata:created_at 2019_10_07; reference:url, urlhaus.abuse.ch/url/240568/; classtype:trojan-activity;sid:81103668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (240036)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"178.151.143.2"; depth:13; isdataat:!1,relative; metadata:created_at 2019_10_07; reference:url, urlhaus.abuse.ch/url/240036/; classtype:trojan-activity;sid:81103136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (239019)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"36.66.139.36"; depth:12; isdataat:!1,relative; metadata:created_at 2019_10_06; reference:url, urlhaus.abuse.ch/url/239019/; classtype:trojan-activity;sid:81102119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (237890)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/.i"; depth:3; endswith; nocase; http.host; content:"185.12.78.161"; depth:13; isdataat:!1,relative; metadata:created_at 2019_10_05; reference:url, urlhaus.abuse.ch/url/237890/; classtype:trojan-activity;sid:81100990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (222263)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keygen.exe"; depth:11; endswith; nocase; http.host; content:"www.konsor.ru"; depth:13; isdataat:!1,relative; metadata:created_at 2019_08_04; reference:url, urlhaus.abuse.ch/url/222263/; classtype:trojan-activity;sid:81085363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (222259)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/keygen.exe"; depth:11; endswith; nocase; http.host; content:"konsor.ru"; depth:9; isdataat:!1,relative; metadata:created_at 2019_08_04; reference:url, urlhaus.abuse.ch/url/222259/; classtype:trojan-activity;sid:81085359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (222056)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaobeitu/news/v1.0.7.31/news_01.exe"; depth:36; endswith; nocase; http.host; content:"download.kaobeitu.com"; depth:21; isdataat:!1,relative; metadata:created_at 2019_08_04; reference:url, urlhaus.abuse.ch/url/222056/; classtype:trojan-activity;sid:81085156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (222026)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kaobeitu/mini/v1.0.7.16/mini_04.exe"; depth:36; endswith; nocase; http.host; content:"download.kaobeitu.com"; depth:21; isdataat:!1,relative; metadata:created_at 2019_08_03; reference:url, urlhaus.abuse.ch/url/222026/; classtype:trojan-activity;sid:81085126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (221598)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kszip/mini/v1.0.7.31/mini_04.exe"; depth:33; endswith; nocase; http.host; content:"download.pdf00.cn"; depth:17; isdataat:!1,relative; metadata:created_at 2019_08_01; reference:url, urlhaus.abuse.ch/url/221598/; classtype:trojan-activity;sid:81084698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (221595)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kszip/news2/v1.0.7.31/news2_02.exe"; depth:35; endswith; nocase; http.host; content:"download.pdf00.cn"; depth:17; isdataat:!1,relative; metadata:created_at 2019_08_01; reference:url, urlhaus.abuse.ch/url/221595/; classtype:trojan-activity;sid:81084695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (220541)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/25072019_0963.xls"; depth:18; endswith; nocase; http.host; content:"fakers.co.jp"; depth:12; isdataat:!1,relative; metadata:created_at 2019_07_29; reference:url, urlhaus.abuse.ch/url/220541/; classtype:trojan-activity;sid:81083641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (219275)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0996938c001/6e8a2a4f-40ac-464f-9a70-7c67f0a0da19.pdf"; depth:53; endswith; nocase; http.host; content:"files.constantcontact.com"; depth:25; isdataat:!1,relative; metadata:created_at 2019_07_24; reference:url, urlhaus.abuse.ch/url/219275/; classtype:trojan-activity;sid:81082375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (217486)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; depth:36; endswith; nocase; http.host; content:"codeload.github.com"; depth:19; isdataat:!1,relative; metadata:created_at 2019_07_17; reference:url, urlhaus.abuse.ch/url/217486/; classtype:trojan-activity;sid:81080586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (215077)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doumai/news2/v1.0.7.01/news2_01.exe"; depth:36; endswith; nocase; http.host; content:"download.doumaibiji.cn"; depth:22; isdataat:!1,relative; metadata:created_at 2019_07_06; reference:url, urlhaus.abuse.ch/url/215077/; classtype:trojan-activity;sid:81078177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (210525)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/20.06.2019_130.22.doc"; depth:22; endswith; nocase; http.host; content:"fakers.co.jp"; depth:12; isdataat:!1,relative; metadata:created_at 2019_06_20; reference:url, urlhaus.abuse.ch/url/210525/; classtype:trojan-activity;sid:81073625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (208009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/domains/updateagent/application%20files/upagent.exe"; depth:52; endswith; nocase; http.host; content:"old.bullydog.com"; depth:16; isdataat:!1,relative; metadata:created_at 2019_06_12; reference:url, urlhaus.abuse.ch/url/208009/; classtype:trojan-activity;sid:81071109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (203280)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/qt51crk.exe"; depth:21; endswith; nocase; http.host; content:"www.hseda.com"; depth:13; isdataat:!1,relative; metadata:created_at 2019_05_29; reference:url, urlhaus.abuse.ch/url/203280/; classtype:trojan-activity;sid:81066380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (203157)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download/qt51crk.exe"; depth:21; endswith; nocase; http.host; content:"hseda.com"; depth:9; isdataat:!1,relative; metadata:created_at 2019_05_28; reference:url, urlhaus.abuse.ch/url/203157/; classtype:trojan-activity;sid:81066257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (202114)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/screenmate/cute/sm1302.zip"; depth:27; endswith; nocase; http.host; content:"www.starcountry.net"; depth:19; isdataat:!1,relative; metadata:created_at 2019_05_26; reference:url, urlhaus.abuse.ch/url/202114/; classtype:trojan-activity;sid:81065214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (201513)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wj1bsetup.exe"; depth:14; endswith; nocase; http.host; content:"dl.dzqzd.com"; depth:12; isdataat:!1,relative; metadata:created_at 2019_05_24; reference:url, urlhaus.abuse.ch/url/201513/; classtype:trojan-activity;sid:81064613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (200800)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/releases/zorke_release/zorke_asciiverter_v1.00/zke-ascv.exe"; depth:60; endswith; nocase; http.host; content:"nerve.untergrund.net"; depth:20; isdataat:!1,relative; metadata:created_at 2019_05_23; reference:url, urlhaus.abuse.ch/url/200800/; classtype:trojan-activity;sid:81063900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (200798)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/releases/12.2013/nrv-ppwr.zip"; depth:30; endswith; nocase; http.host; content:"nerve.untergrund.net"; depth:20; isdataat:!1,relative; metadata:created_at 2019_05_23; reference:url, urlhaus.abuse.ch/url/200798/; classtype:trojan-activity;sid:81063898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (200771)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; depth:27; endswith; nocase; http.host; content:"chiptune.com"; depth:12; isdataat:!1,relative; metadata:created_at 2019_05_23; reference:url, urlhaus.abuse.ch/url/200771/; classtype:trojan-activity;sid:81063871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (200770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/releases/zorke_release/zorke_nfo_file_viewer_v1.00/zke-nfoview.exe"; depth:67; endswith; nocase; http.host; content:"nerve.untergrund.net"; depth:20; isdataat:!1,relative; metadata:created_at 2019_05_23; reference:url, urlhaus.abuse.ch/url/200770/; classtype:trojan-activity;sid:81063870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (199446)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cd/81/ddq7kprp_o.png"; depth:21; endswith; nocase; http.host; content:"images2.imgbox.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_05_21; reference:url, urlhaus.abuse.ch/url/199446/; classtype:trojan-activity;sid:81062546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (195172)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eypipe/pipefile/adpopup/adpopup_1382523956.exe"; depth:47; endswith; nocase; http.host; content:"goto.stnts.com"; depth:14; isdataat:!1,relative; metadata:created_at 2019_05_13; reference:url, urlhaus.abuse.ch/url/195172/; classtype:trojan-activity;sid:81058272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (193761)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-post-thumbnail/sites/wycqytoskj/"; depth:36; endswith; nocase; http.host; content:"www.springhillmontessori.com"; depth:28; isdataat:!1,relative; metadata:created_at 2019_05_09; reference:url, urlhaus.abuse.ch/url/193761/; classtype:trojan-activity;sid:81056861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (192171)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2d/da/zg72nmjz_o.png"; depth:21; endswith; nocase; http.host; content:"images2.imgbox.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_05_07; reference:url, urlhaus.abuse.ch/url/192171/; classtype:trojan-activity;sid:81055271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (192166)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1b/a6/9pjo30dk_o.png"; depth:21; endswith; nocase; http.host; content:"images2.imgbox.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_05_07; reference:url, urlhaus.abuse.ch/url/192166/; classtype:trojan-activity;sid:81055266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (186282)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pub/1003b/patch/patch_data/patch_0.3300/1003b.exe"; depth:50; endswith; nocase; http.host; content:"dl.1003b.56a.com"; depth:16; isdataat:!1,relative; metadata:created_at 2019_04_27; reference:url, urlhaus.abuse.ch/url/186282/; classtype:trojan-activity;sid:81049382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (185713)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qrtb.exe"; depth:9; endswith; nocase; http.host; content:"xiaoma-10021647.file.myqcloud.com"; depth:33; isdataat:!1,relative; metadata:created_at 2019_04_26; reference:url, urlhaus.abuse.ch/url/185713/; classtype:trojan-activity;sid:81048813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (184801)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tqpjo/scan/uftruaemi2h/"; depth:24; endswith; nocase; http.host; content:"redlk.com"; depth:9; isdataat:!1,relative; metadata:created_at 2019_04_25; reference:url, urlhaus.abuse.ch/url/184801/; classtype:trojan-activity;sid:81047901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (176091)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/templates/theme261/css/msg.jpg"; depth:31; endswith; nocase; http.host; content:"sk-comtel.com"; depth:13; isdataat:!1,relative; metadata:created_at 2019_04_12; reference:url, urlhaus.abuse.ch/url/176091/; classtype:trojan-activity;sid:81039191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (175833)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/templates/theme261/html/com_contact/category/hp.gf"; depth:51; endswith; nocase; http.host; content:"sk-comtel.com"; depth:13; isdataat:!1,relative; metadata:created_at 2019_04_11; reference:url, urlhaus.abuse.ch/url/175833/; classtype:trojan-activity;sid:81038933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (173971)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/support/trust/en/042019/"; depth:30; endswith; nocase; http.host; content:"brightworks.cz"; depth:14; isdataat:!1,relative; metadata:created_at 2019_04_09; reference:url, urlhaus.abuse.ch/url/173971/; classtype:trojan-activity;sid:81037071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (173380)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/programas1/uldqi-i7q4vmdrqzvbbg_qjuhgzkb-vr2/"; depth:46; endswith; nocase; http.host; content:"aftelecom.com.br"; depth:16; isdataat:!1,relative; metadata:created_at 2019_04_08; reference:url, urlhaus.abuse.ch/url/173380/; classtype:trojan-activity;sid:81036480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (165554)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secure.myacc.resourses.com/"; depth:28; endswith; nocase; http.host; content:"flyingmutts.com"; depth:15; isdataat:!1,relative; metadata:created_at 2019_03_25; reference:url, urlhaus.abuse.ch/url/165554/; classtype:trojan-activity;sid:81028654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (165504)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/i203611254b019514581.zip"; depth:25; endswith; nocase; http.host; content:"programandojuntos.us.tempcloudsite.com"; depth:38; isdataat:!1,relative; metadata:created_at 2019_03_25; reference:url, urlhaus.abuse.ch/url/165504/; classtype:trojan-activity;sid:81028604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (164277)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/corporation/new_invoice/1033530/hijmq-jo_uqgwdlyf-8e/"; depth:54; endswith; nocase; http.host; content:"flyingmutts.com"; depth:15; isdataat:!1,relative; metadata:created_at 2019_03_22; reference:url, urlhaus.abuse.ch/url/164277/; classtype:trojan-activity;sid:81027377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (162770)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/artluz/produtos/sendincsec/support/sec/en_en/03-2019/"; depth:54; endswith; nocase; http.host; content:"alarmline.com.br"; depth:16; isdataat:!1,relative; metadata:created_at 2019_03_20; reference:url, urlhaus.abuse.ch/url/162770/; classtype:trojan-activity;sid:81025870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (161757)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tomatoleizhutizy/tomatoleizhutizy.exe"; depth:38; endswith; nocase; http.host; content:"softdl2.360tpcdn.com"; depth:20; isdataat:!1,relative; metadata:created_at 2019_03_19; reference:url, urlhaus.abuse.ch/url/161757/; classtype:trojan-activity;sid:81024857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (157610)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/stats/f06bn-kgh24-ncoviajp/"; depth:28; endswith; nocase; http.host; content:"flyingmutts.com"; depth:15; isdataat:!1,relative; metadata:created_at 2019_03_12; reference:url, urlhaus.abuse.ch/url/157610/; classtype:trojan-activity;sid:81020710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (156866)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/9e/ff/ila2jh9p_o.png"; depth:21; endswith; nocase; http.host; content:"images2.imgbox.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_03_12; reference:url, urlhaus.abuse.ch/url/156866/; classtype:trojan-activity;sid:81019966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (156867)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ce/60/rw99spa3_o.png"; depth:21; endswith; nocase; http.host; content:"images2.imgbox.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_03_12; reference:url, urlhaus.abuse.ch/url/156867/; classtype:trojan-activity;sid:81019967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (155567)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/rawabijob.hta"; depth:14; endswith; nocase; http.host; content:"local-update.com"; depth:16; isdataat:!1,relative; metadata:created_at 2019_03_10; reference:url, urlhaus.abuse.ch/url/155567/; classtype:trojan-activity;sid:81018667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (154627)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/za.ebali"; depth:9; endswith; nocase; http.host; content:"mitreart.com"; depth:12; isdataat:!1,relative; metadata:created_at 2019_03_07; reference:url, urlhaus.abuse.ch/url/154627/; classtype:trojan-activity;sid:81017727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (148872)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86/e2/nuflpuwf_o.png"; depth:21; endswith; nocase; http.host; content:"images2.imgbox.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_27; reference:url, urlhaus.abuse.ch/url/148872/; classtype:trojan-activity;sid:81011972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (148857)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ff/22/6nkpot2i_o.png"; depth:21; endswith; nocase; http.host; content:"images2.imgbox.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_27; reference:url, urlhaus.abuse.ch/url/148857/; classtype:trojan-activity;sid:81011957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (143333)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/css/out-1773725897.hta"; depth:23; endswith; nocase; http.host; content:"globalbank.us"; depth:13; isdataat:!1,relative; metadata:created_at 2019_02_23; reference:url, urlhaus.abuse.ch/url/143333/; classtype:trojan-activity;sid:81006433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (143301)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pistacchietto/win-python-backdoor/raw/master/win.bat"; depth:53; endswith; nocase; http.host; content:"github.com"; depth:10; isdataat:!1,relative; metadata:created_at 2019_02_23; reference:url, urlhaus.abuse.ch/url/143301/; classtype:trojan-activity;sid:81006401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (140156)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1465810408079_502.exe"; depth:22; endswith; nocase; http.host; content:"static.topxgun.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_19; reference:url, urlhaus.abuse.ch/url/140156/; classtype:trojan-activity;sid:81003256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (133387)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/34/60/1zc8bevk_o.png"; depth:21; endswith; nocase; http.host; content:"images2.imgbox.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_18; reference:url, urlhaus.abuse.ch/url/133387/; classtype:trojan-activity;sid:80996487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (122827)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/core/cache/action_map/web/ssj.jpg"; depth:34; endswith; nocase; http.host; content:"sochibeer.ru"; depth:12; isdataat:!1,relative; metadata:created_at 2019_02_12; reference:url, urlhaus.abuse.ch/url/122827/; classtype:trojan-activity;sid:80985927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (122825)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/core/cache/action_map/web/bs.jpg"; depth:33; endswith; nocase; http.host; content:"sochibeer.ru"; depth:12; isdataat:!1,relative; metadata:created_at 2019_02_12; reference:url, urlhaus.abuse.ch/url/122825/; classtype:trojan-activity;sid:80985925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (122732)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/core/cache/action_map/web/sserv.jpg"; depth:36; endswith; nocase; http.host; content:"sochibeer.ru"; depth:12; isdataat:!1,relative; metadata:created_at 2019_02_12; reference:url, urlhaus.abuse.ch/url/122732/; classtype:trojan-activity;sid:80985832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (121029)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/active/pcclear_eng_mini.exe"; depth:28; endswith; nocase; http.host; content:"down.pcclear.com"; depth:16; isdataat:!1,relative; metadata:created_at 2019_02_10; reference:url, urlhaus.abuse.ch/url/121029/; classtype:trojan-activity;sid:80984129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (115233)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/sanghyun-guest.exe"; depth:25; endswith; nocase; http.host; content:"sanghyun.nfile.net"; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_01; reference:url, urlhaus.abuse.ch/url/115233/; classtype:trojan-activity;sid:80978333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (115231)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/sanghyun.exe"; depth:19; endswith; nocase; http.host; content:"sanghyun.nfile.net"; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_01; reference:url, urlhaus.abuse.ch/url/115231/; classtype:trojan-activity;sid:80978331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (112779)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/update.exe"; depth:17; endswith; nocase; http.host; content:"sg123.net"; depth:9; isdataat:!1,relative; metadata:created_at 2019_01_29; reference:url, urlhaus.abuse.ch/url/112779/; classtype:trojan-activity;sid:80975879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (112648)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/install.exe"; depth:18; endswith; nocase; http.host; content:"sg123.net"; depth:9; isdataat:!1,relative; metadata:created_at 2019_01_29; reference:url, urlhaus.abuse.ch/url/112648/; classtype:trojan-activity;sid:80975748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (112647)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/install.exe"; depth:18; endswith; nocase; http.host; content:"igra123.com"; depth:11; isdataat:!1,relative; metadata:created_at 2019_01_29; reference:url, urlhaus.abuse.ch/url/112647/; classtype:trojan-activity;sid:80975747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (112642)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/update.exe"; depth:17; endswith; nocase; http.host; content:"igra123.com"; depth:11; isdataat:!1,relative; metadata:created_at 2019_01_29; reference:url, urlhaus.abuse.ch/url/112642/; classtype:trojan-activity;sid:80975742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (111691)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/haeum.exe"; depth:16; endswith; nocase; http.host; content:"haeum.nfile.net"; depth:15; isdataat:!1,relative; metadata:created_at 2019_01_28; reference:url, urlhaus.abuse.ch/url/111691/; classtype:trojan-activity;sid:80974791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (110142)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/%d3%b2%bc%fe%d0%c5%cf%a2%b2%e9%bf%b4%c6%f7.exe"; depth:47; endswith; nocase; http.host; content:"down.54nb.com"; depth:13; isdataat:!1,relative; metadata:created_at 2019_01_25; reference:url, urlhaus.abuse.ch/url/110142/; classtype:trojan-activity;sid:80973242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (110132)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gcld/updates_tw/gcmgr_tw.exe"; depth:29; endswith; nocase; http.host; content:"static.ilclock.com"; depth:18; isdataat:!1,relative; metadata:created_at 2019_01_25; reference:url, urlhaus.abuse.ch/url/110132/; classtype:trojan-activity;sid:80973232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (109220)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/de_de/tejqsyf3366492/ger/rechnungszahlung/"; depth:43; endswith; nocase; http.host; content:"blogs.sokun.jp"; depth:14; isdataat:!1,relative; metadata:created_at 2019_01_24; reference:url, urlhaus.abuse.ch/url/109220/; classtype:trojan-activity;sid:80972320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (108283)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bigfile/v1/urls/d/4qnwtdd-4xsuuy1xlrmzcibqjfu/ihdzyo55cus7ds4lmmkxpa"; depth:69; endswith; nocase; http.host; content:"attach.mail.daum.net"; depth:20; isdataat:!1,relative; metadata:created_at 2019_01_23; reference:url, urlhaus.abuse.ch/url/108283/; classtype:trojan-activity;sid:80971383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (106006)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qcoin/qcoin128.exe"; depth:19; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/106006/; classtype:trojan-activity;sid:80969106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (106003)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qcoin/qcoin133.exe"; depth:19; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/106003/; classtype:trojan-activity;sid:80969103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (106002)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jd/jd156.exe"; depth:13; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/106002/; classtype:trojan-activity;sid:80969102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (106000)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qcoin/qcoin130.exe"; depth:19; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/106000/; classtype:trojan-activity;sid:80969100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105999)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qcoin/qcoin142.exe"; depth:19; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105999/; classtype:trojan-activity;sid:80969099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105998)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jd/jd124.exe"; depth:13; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105998/; classtype:trojan-activity;sid:80969098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105997)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qcoin/qcoin141.exe"; depth:19; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105997/; classtype:trojan-activity;sid:80969097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105996)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jd/jd127.exe"; depth:13; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105996/; classtype:trojan-activity;sid:80969096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105992)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jd/jd145.exe"; depth:13; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105992/; classtype:trojan-activity;sid:80969092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105991)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qcoin/qcoin140.exe"; depth:19; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105991/; classtype:trojan-activity;sid:80969091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105988)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jd/jd144.exe"; depth:13; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105988/; classtype:trojan-activity;sid:80969088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105985)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jd/jd136.exe"; depth:13; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105985/; classtype:trojan-activity;sid:80969085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105976)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qcoin/qcoin139.exe"; depth:19; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105976/; classtype:trojan-activity;sid:80969076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105975)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jd/jd137.exe"; depth:13; endswith; nocase; http.host; content:"cdn-10049480.file.myqcloud.com"; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105975/; classtype:trojan-activity;sid:80969075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105558)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n/tui/ciqinmishi/6/cqms.exe"; depth:28; endswith; nocase; http.host; content:"bundle.kpzip.com"; depth:16; isdataat:!1,relative; metadata:created_at 2019_01_18; reference:url, urlhaus.abuse.ch/url/105558/; classtype:trojan-activity;sid:80968658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105407)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hkhe3fktc/"; depth:11; endswith; nocase; http.host; content:"atkcgnew.evgeni7e.beget.tech"; depth:28; isdataat:!1,relative; metadata:created_at 2019_01_18; reference:url, urlhaus.abuse.ch/url/105407/; classtype:trojan-activity;sid:80968507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (104016)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/drop/css/obr.hta"; depth:17; endswith; nocase; http.host; content:"www.myvcart.com"; depth:15; isdataat:!1,relative; metadata:created_at 2019_01_16; reference:url, urlhaus.abuse.ch/url/104016/; classtype:trojan-activity;sid:80967116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (102706)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/autoguarder/autoguarder_2.3.7.350.exe"; depth:38; endswith; nocase; http.host; content:"softdl4.360.cn"; depth:14; isdataat:!1,relative; metadata:created_at 2019_01_12; reference:url, urlhaus.abuse.ch/url/102706/; classtype:trojan-activity;sid:80965806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (102548)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doumai/tips/v1.0.1.11/tips_01.exe"; depth:34; endswith; nocase; http.host; content:"download.doumaibiji.cn"; depth:22; isdataat:!1,relative; metadata:created_at 2019_01_11; reference:url, urlhaus.abuse.ch/url/102548/; classtype:trojan-activity;sid:80965648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (102545)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doumai/fmt/v1.0.1.11/fmt_01.exe"; depth:32; endswith; nocase; http.host; content:"download.doumaibiji.cn"; depth:22; isdataat:!1,relative; metadata:created_at 2019_01_11; reference:url, urlhaus.abuse.ch/url/102545/; classtype:trojan-activity;sid:80965645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (98628)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6nqq.js"; depth:8; endswith; nocase; http.host; content:"www.hostingcloud.science"; depth:24; isdataat:!1,relative; metadata:created_at 2018_12_21; reference:url, urlhaus.abuse.ch/url/98628/; classtype:trojan-activity;sid:80961728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (96625)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/iuia-qgkdtq2rfbxd7z_ljiaengvq-4cy/"; depth:35; endswith; nocase; http.host; content:"www.ardguisser.com"; depth:18; isdataat:!1,relative; metadata:created_at 2018_12_17; reference:url, urlhaus.abuse.ch/url/96625/; classtype:trojan-activity;sid:80959725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95728)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/game/download/zip/waigua/shiqi/2003/06/20030620.exe"; depth:52; endswith; nocase; http.host; content:"veryboys.com"; depth:12; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95728/; classtype:trojan-activity;sid:80958828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95727)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/game/download/zip/waigua/mir2/2003/05/200305252.exe"; depth:52; endswith; nocase; http.host; content:"veryboys.com"; depth:12; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95727/; classtype:trojan-activity;sid:80958827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95726)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/game/download/zip/waigua/mu/2003/07/20030721.exe"; depth:49; endswith; nocase; http.host; content:"veryboys.com"; depth:12; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95726/; classtype:trojan-activity;sid:80958826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95550)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/game/download/zip/waigua/mir2/2003/05/20030520.exe"; depth:51; endswith; nocase; http.host; content:"veryboys.com"; depth:12; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95550/; classtype:trojan-activity;sid:80958650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95209)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/us/information/122018/"; depth:23; endswith; nocase; http.host; content:"flyingmutts.com"; depth:15; isdataat:!1,relative; metadata:created_at 2018_12_14; reference:url, urlhaus.abuse.ch/url/95209/; classtype:trojan-activity;sid:80958309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95078)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/us/information/122018"; depth:22; endswith; nocase; http.host; content:"flyingmutts.com"; depth:15; isdataat:!1,relative; metadata:created_at 2018_12_14; reference:url, urlhaus.abuse.ch/url/95078/; classtype:trojan-activity;sid:80958178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (94279)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/upload/20140812/14078161556897.rar"; depth:35; endswith; nocase; http.host; content:"static.3001.net"; depth:15; isdataat:!1,relative; metadata:created_at 2018_12_13; reference:url, urlhaus.abuse.ch/url/94279/; classtype:trojan-activity;sid:80957379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (92354)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/3"; depth:14; endswith; nocase; http.host; content:"itssprout.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_10; reference:url, urlhaus.abuse.ch/url/92354/; classtype:trojan-activity;sid:80955454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (92351)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/2"; depth:14; endswith; nocase; http.host; content:"itssprout.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_10; reference:url, urlhaus.abuse.ch/url/92351/; classtype:trojan-activity;sid:80955451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (92344)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1"; depth:14; endswith; nocase; http.host; content:"itssprout.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_10; reference:url, urlhaus.abuse.ch/url/92344/; classtype:trojan-activity;sid:80955444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (86730)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/076360tad/oamo/business/"; depth:25; endswith; nocase; http.host; content:"flyingmutts.com"; depth:15; isdataat:!1,relative; metadata:created_at 2018_11_29; reference:url, urlhaus.abuse.ch/url/86730/; classtype:trojan-activity;sid:80949830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (86203)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/076360tad/oamo/business"; depth:24; endswith; nocase; http.host; content:"flyingmutts.com"; depth:15; isdataat:!1,relative; metadata:created_at 2018_11_28; reference:url, urlhaus.abuse.ch/url/86203/; classtype:trojan-activity;sid:80949303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85967)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/task/2009-06/29/106045/rc1veeex.rar"; depth:36; endswith; nocase; http.host; content:"p3.zbjimg.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_28; reference:url, urlhaus.abuse.ch/url/85967/; classtype:trojan-activity;sid:80949067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85901)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tekiwanatain/installer.rar"; depth:27; endswith; nocase; http.host; content:"users.atw.hu"; depth:12; isdataat:!1,relative; metadata:created_at 2018_11_28; reference:url, urlhaus.abuse.ch/url/85901/; classtype:trojan-activity;sid:80949001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85881)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/task/2009-06/29/106045/5fg9yjwr.rar"; depth:36; endswith; nocase; http.host; content:"p3.zbjimg.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85881/; classtype:trojan-activity;sid:80948981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85879)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/task/2009-06/29/106045/a9to40e7.rar"; depth:36; endswith; nocase; http.host; content:"p3.zbjimg.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85879/; classtype:trojan-activity;sid:80948979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85878)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/task/2009-06/29/106045/e6i8pdc0.rar"; depth:36; endswith; nocase; http.host; content:"p3.zbjimg.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85878/; classtype:trojan-activity;sid:80948978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85877)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/task/2009-07/28/117228/4wtjdjio.rar"; depth:36; endswith; nocase; http.host; content:"p3.zbjimg.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85877/; classtype:trojan-activity;sid:80948977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85876)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/task/2009-06/29/106045/zwy1q6k0.rar"; depth:36; endswith; nocase; http.host; content:"p3.zbjimg.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85876/; classtype:trojan-activity;sid:80948976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85874)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/task/2009-06/06/98428/07c9mfhe.zip"; depth:35; endswith; nocase; http.host; content:"p3.zbjimg.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85874/; classtype:trojan-activity;sid:80948974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (79342)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bigfile/v1/urls/d/1gpusd8uwnakepjjehixnayfekq/kbdjubux_j-nvjot1z-mdw"; depth:69; endswith; nocase; http.host; content:"attach.mail.daum.net"; depth:20; isdataat:!1,relative; metadata:created_at 2018_11_13; reference:url, urlhaus.abuse.ch/url/79342/; classtype:trojan-activity;sid:80942442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (71185)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nykol16/kepek.exe"; depth:18; endswith; nocase; http.host; content:"users.atw.hu"; depth:12; isdataat:!1,relative; metadata:created_at 2018_10_26; reference:url, urlhaus.abuse.ch/url/71185/; classtype:trojan-activity;sid:80934285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (67517)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbs/attachment/forum/201106/03/153053ki5kbisfbc8316i3.rar"; depth:58; endswith; nocase; http.host; content:"attach.66rpg.com"; depth:16; isdataat:!1,relative; metadata:created_at 2018_10_13; reference:url, urlhaus.abuse.ch/url/67517/; classtype:trojan-activity;sid:80930617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (67516)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbs/attachment/forum/201403/02/104411hqzp4rto4ro94qpz.rar"; depth:58; endswith; nocase; http.host; content:"attach.66rpg.com"; depth:16; isdataat:!1,relative; metadata:created_at 2018_10_13; reference:url, urlhaus.abuse.ch/url/67516/; classtype:trojan-activity;sid:80930616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (67474)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bbs/attachment/forum/201108/22/215335elkpi66piz56eii9.zip"; depth:58; endswith; nocase; http.host; content:"attach.66rpg.com"; depth:16; isdataat:!1,relative; metadata:created_at 2018_10_12; reference:url, urlhaus.abuse.ch/url/67474/; classtype:trojan-activity;sid:80930574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (67439)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zoolatogato/xruhbmzvlaghfnqcerrv.exe"; depth:37; endswith; nocase; http.host; content:"users.atw.hu"; depth:12; isdataat:!1,relative; metadata:created_at 2018_10_12; reference:url, urlhaus.abuse.ch/url/67439/; classtype:trojan-activity;sid:80930539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (66694)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/autoup/client/aqclient.exe"; depth:27; endswith; nocase; http.host; content:"pay.aqiu6.com"; depth:13; isdataat:!1,relative; metadata:created_at 2018_10_11; reference:url, urlhaus.abuse.ch/url/66694/; classtype:trojan-activity;sid:80929794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (66274)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/toneraruhaz/wp-admin/network/installer.rar"; depth:43; endswith; nocase; http.host; content:"users.atw.hu"; depth:12; isdataat:!1,relative; metadata:created_at 2018_10_09; reference:url, urlhaus.abuse.ch/url/66274/; classtype:trojan-activity;sid:80929374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (66164)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fvlmodell/letoltes/files/scalecalc.exe"; depth:39; endswith; nocase; http.host; content:"users.atw.hu"; depth:12; isdataat:!1,relative; metadata:created_at 2018_10_09; reference:url, urlhaus.abuse.ch/url/66164/; classtype:trojan-activity;sid:80929264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (59247)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/vqd0d5/"; depth:8; endswith; nocase; http.host; content:"robertrowe.com"; depth:14; isdataat:!1,relative; metadata:created_at 2018_09_23; reference:url, urlhaus.abuse.ch/url/59247/; classtype:trojan-activity;sid:80922347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (57935)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/factures-09-2018/"; depth:18; endswith; nocase; http.host; content:"hasalltalent.com"; depth:16; isdataat:!1,relative; metadata:created_at 2018_09_19; reference:url, urlhaus.abuse.ch/url/57935/; classtype:trojan-activity;sid:80921035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (57059)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/document/en/need-to-send-the-attachment"; depth:40; endswith; nocase; http.host; content:"vgd.vg"; depth:6; isdataat:!1,relative; metadata:created_at 2018_09_17; reference:url, urlhaus.abuse.ch/url/57059/; classtype:trojan-activity;sid:80920159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (56449)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/7mn5zo8d/"; depth:10; endswith; nocase; http.host; content:"vgd.vg"; depth:6; isdataat:!1,relative; metadata:created_at 2018_09_14; reference:url, urlhaus.abuse.ch/url/56449/; classtype:trojan-activity;sid:80919549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (38013)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/dl/gxfqfem5m813nva/firefox_67.3.39.js"; depth:40; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2018_08_02; reference:url, urlhaus.abuse.ch/url/38013/; classtype:trojan-activity;sid:80901113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (38011)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/dl/dqrsgzlf8jeefw0/firefox_67.3.45.js"; depth:40; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2018_08_02; reference:url, urlhaus.abuse.ch/url/38011/; classtype:trojan-activity;sid:80901111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (38009)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/s/dl/g4is5u674v6l2yy/firefox_67.3.16.js"; depth:40; endswith; nocase; http.host; content:"www.dropbox.com"; depth:15; isdataat:!1,relative; metadata:created_at 2018_08_02; reference:url, urlhaus.abuse.ch/url/38009/; classtype:trojan-activity;sid:80901109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (16630)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/doc/past-due-invoice/"; depth:22; endswith; nocase; http.host; content:"robertrowe.com"; depth:14; isdataat:!1,relative; metadata:created_at 2018_06_07; reference:url, urlhaus.abuse.ch/url/16630/; classtype:trojan-activity;sid:80879730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (15711)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/status/auditor-of-state-notification-of-eft-deposit/"; depth:53; endswith; nocase; http.host; content:"robertrowe.com"; depth:14; isdataat:!1,relative; metadata:created_at 2018_06_05; reference:url, urlhaus.abuse.ch/url/15711/; classtype:trojan-activity;sid:80878811; rev:1;) # Number of entries: 31061